SMS Based Two Factor using Phone Number (Without Duo App)
This is a feature that can be defeated by SimSwapping, however leaving the free users not being able to add 2FA using SMS leaves us more vulnerable.
SMS Based Two Factor using Phone Number (Without Duo App)
This is a feature that can be defeated by SimSwapping, however leaving the free users not being able to add 2FA using SMS leaves us more vulnerable.
Stale
It would be great to have a phone number option for the coming two step authentication. I’m not fond of using email to do so.
You mean the new device verification?
Or do you mean the 2FA-options for Bitwarden? (currently: email, “passkey”/FIDO2, TOTP/authenticator app, DUO, Yubico OTP)
And by phone number, you mean “SIM” in the end? (i.e. not “push app”)
Thanks.
Not really a tech person, but yes, the 2FA for Bitwarden.
And yes, using the sim. Either sms to number, or some sort of push to device (similar to what some banking apps use).
Apologies for any lack of clarity.
Okay, so you mean “more 2FA options for Bitwarden - either SMS or push app”…
Hm, some first thoughts to that:
PS: I changed the title for now… it was “2 step authentication” before…
Thanks for the clarification and better title.
I appreciate your thoughts and input as my knowledge of this stuff would fill less than a thimble.
Cheers.
As I indicated in the other thread. This is possible if you sign up for DUO.
Right. I didn’t think of that possibility.
Here me out. all the other methods have a lock out possiblity aswell. especially if you are using bitwarden to store the creds.
With sms or phone it removes alot of the hard lock out possiblity. if you get a new phone you can still get access to your account for the creds needed.
Email > if you dont know your password and its in bitwarden.
authenticator app > phone is replaced, broken, or stolen,
Token > broken, lost, stolen, etc
passkey > lost or stolen,
duo >phone is replaced, broken, or stolen,
@gurban2013 Welcome to the forum!
You can already get 2FA codes by SMS or voice calls using DUO:
Hello, i am not asking for this via duo. this request is for native SMS and phone. having to download middle ware is never a good option and now you are at the mercy of a 3rd party. no thank you.
I’ve re-opened an old feature request, merged a few existing topics into the thread, and revised the title to be more general (original title was: “SMS Based Two Factor using Phone Number (Without Duo App)”).