• jpj007@kbin.social
    link
    fedilink
    arrow-up
    0
    ·
    10 months ago

    Assuming the victim does not use 2FA on their Bitwarden account

    A pretty tall assumption given that we’re already talking about someone who knows to turn on 2FA for other things. If someone knows about 2FA and password managers, they’d be insane not to have 2FA set up on the password manager itself.

    • andreluis034@lm.put.tf
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      10 months ago

      That’s a fair point. I just wanted to highlight that there may be cases where a password manager isn’t automatically protected by 2FA by the two factors you mentioned (The password you know and the copy of the vault) since in the case of bitwarden fulfilling one can give you the second. In order to actually achieve 2FA in this case, you would need to enable OTPs.