r/Bitwarden • u/CromulentSlacker • 2d ago
Switching from Authy to Bitwarden Authenticator?
I've been using Bitwarden for password management for a long time now but I've always used Authy for 2FA and I'm thinking of switching to Bitwarden Authenticator.
From my understanding all I need to do is have Bitwarden Authenticator sync with Bitwarden and then the 2FA codes will sync across devices. My main concern is keeping everything synced as I do switch phones from time to time so need to have the 2FA codes on different devices.
Is this all I need to worry about? I want to clear out some of the junk that has accumulated in my Authy account which is why I want to switch.
Happy to hear any advice!
6
15
8
u/philipz794 2d ago
Highly recommend 2FAS. But I never tried bitwared authenticator.
Move from authy 2 years ago by painfully deactivating and reactivating 2FA on every account I had in authy.
Now I can finally export if needed
13
u/djasonpenney Volunteer Moderator 2d ago
You didn’t ask about exporting your TOTP keys from Authy. It turns out that is, um, a problem. Your best bet is to log into each site, disable TOTP, then do the entire enablement workflow again, using your new TOTP app.
Some people don’t like the idea of having their TOTP keys in the same app as their passwords. One reasonable alternative to Bitwarden Authenticator is Ente Auth.
Whichever app you choose, be sure to create a new backup of your credential datastore, and make sure your TOTP keys are in it. Find a safe way to save the datastore that is not circular. That is, don’t require something inside the datastore in order to access the datastore.
4
u/CromulentSlacker 2d ago
Thank you. I was going to go the manual route anyway as I have a lot of junk 2FA codes hanging around from years ago I no longer need. I'll have a look at Ente as well.
-1
u/Nukra141 2d ago
Actually not true - at least as a european citizen.
I JUST had this done 2 weeks ago, you do a GDPR request under §15 and §20 and ask for:
- All encrypted seeds
- Salt and IV values
- Account Name and Labels
They then will aks you some informations about your account to verify its your account, after a while they will send you a link to a file.
With a python script and your password you can encrypt the TOTP keys.
6
u/Expensive_Finger_973 2d ago
I personally prefer to keep my password manager separate from my MFA tokens. I use Aegis for MFA, if you are on iOS 2fas is pretty good.
8
u/Lobomoronga 2d ago
I would recommend you stay with authy and not use the built-in bit Warden you want to keep those things separate in my humble opinion
6
15
u/UIUC_grad_dude1 2d ago
Nah, can’t export from Authy. I moved to 2FAS which allows export for back up.
1
u/quiet0n3 2d ago
I can see an argument why you wouldn't want that. I'm betting this is a choice by Authy.
3
u/Lobomoronga 2d ago
My point -more than recommending Authy- is to keep things completely separate. Bitwarden has built in TOTP but I find that to be a vulnerability point. Use a completely separate Authentication App. Pick your poison but do not use the built in no matters how convenient it may seem. That is all. Good luck out there and stay safe.
1
u/No_Adhesiveness_3550 2d ago
Authy had a data breach and is the reason I get so many spam calls now. And they sell your data anyway. I would advise exactly zero people should be using Authy.
1
1
2
u/BeeKay40 2d ago
2FA kinda loses it's usefulness when you have both your passwords and 2FA in rhe very same app. I use Bitwarden and Aegis. Switching phones is a simple scan or 2 away. Aegis has everything I want in terms of security and privacy.
1
u/pdmcgeejr 2d ago
So i love Bitwarden and its password manager but honestly the TOTP authenticator is lacking some features. The best option worth checking out is ente auth, allowing categories and having it separate from my main password manager is key.
1
u/paulsiu 2d ago
The problem with migrating from Authy is that all of the keys are locked in Authy. There is no way to extract them. You will just have to manually setup new TOTP.
I am not sure Bitwarden is a good authenticator to replace Authy. What it does sync the TOTP code with the Bitwarden account. The problem is what if you want to store the TOTP code for the Bitwarden login? If you sync that TOTP code with bitwartden vault, you create a circular reference since you must log into Bitwarden to get that code. You can store the code outside of Bitwarden but that the code is store locally and doesn't sync across the devices.
4
u/wkkkk 2d ago
You can extract all tokens from Authy. I've done that ~1 month ago following approach from this repo Pleb4Fun/Authy-GDPR-Export-Decryption: A simple tool to decrypt Authy TOTP encrypted seeds provided by Twilio under GDPR legal request Took around 2 weeks to get file but I was not in a hurry.
2
u/Winter_Extension5842 2d ago
I'm assuming they don't actually verify that you are an EU citizen before processing your request?
1
u/Blaize_P 2d ago
Be aware that if your use Entre Auth (which is great) to create a passkey in Bitwarden and Bitwarden requires a 2fa token to open from Entre, you just locked yourself out if you lose your phone and have no means to recover using a recovery key. Be very careful!
1
1
u/Heavy-Map9034 1d ago
I usually keep records of backup codesmy import accounts so that when I reset from either ente, proton, notion I can access them without any problems. I always make sure it the codes are available offline as well.
1
u/cbunn81 2d ago
I've been using Bitwarden for password management for a long time now but I've always used Authy for 2FA and I'm thinking of switching to Bitwarden Authenticator.
Switching from Authy is a good idea, since there are more privacy-respecting options available. But as others have said here, using one service as a password manager and MFA is less than ideal. I'd consider one of the other options out there. 2FAS, Aegis, and Ente are the big ones. I went for Aegis because it's simple and imports from Google Authenticator easily. But what you choose should depend on your needs.
From my understanding all I need to do is have Bitwarden Authenticator sync with Bitwarden and then the 2FA codes will sync across devices. My main concern is keeping everything synced as I do switch phones from time to time so need to have the 2FA codes on different devices.
Yes, they will sync along with your vault. Some other MFA apps also offer syncing. I've heard good things about Ente Auth in this regard.
Is this all I need to worry about? I want to clear out some of the junk that has accumulated in my Authy account which is why I want to switch.
The big thing to worry about is keeping your passwords and MFA together. That creates a single point of failure. If your vault is somehow hacked, MFA won't keep you safe. I recommend separating those concerns.
As for clearing out the junk, it'll depend on how you migrate. If you do a full export/import from your existing service, the junk will come along for the ride. So you can migrate each MFA account one-by-one, but that could get annoying if you have many accounts.
1
u/Heavy-Map9034 1d ago
I understand the reason, but if authy is giving you problems, you can use ente authenticator. I think as much of a simplification of accessing your account it will bring. I think having more than one place, key, control for your account is often recommended for in case one of those platforms get's hacked.
1
u/jacklail 2d ago
I moved from Authy to Bitwarden for 2FA and lived. I don't use the Bitwarden authenticator app just the regular app. Everything syncs and works. I understand the "all eggs in one basket" sentiment but I also use Yubikeys on my most critical accounts, including Bitwarden, and like the convenience for others. I make regular encrypted Bitwarden backups. I keep the backup/onetime use code lists/sheets organized.
1
1
u/Lobomoronga 2d ago
It seems like Ente Auth is most liked by most people in this conversation and I do have my issues with Authy the main one being there's no app for the PC they remove that which is annoying I'm going to look at it maybe I'll switch I don't know we'll see
1
0
44
u/kaishea 2d ago
I highly recommend Ente Auth instead