Require Bitwarden account 2FA/MFA to view/copy secrets

Feature name

  • Selectively require an extra MFA/2FA step for viewing and copying secrets from an unlocked password manager.

Feature function

I would like to keep my accounts in a central location with my tokens, but require one of my configured (Duo, Yubikey, ie a TOTP on a separate device/service) MFA/2FA methods to access secrets of an already unlocked password manager.

Using BW to store TOTP codes and passwords is great, obviously, it’s a password manager. However, info stealer malware are focusing on stealing credentials from password manager extensions more and more.

When using a password manager, the convenience of storing username, password, and now more commonly a TOTP code is convenient. However, a security versus convenience shift is happening away from security. Having an unlocked password manager is becoming a risk and using a master password to continually unlock is annoying if not a risk. I’d rather not move all my TOTP tokens to Microsoft Authenticator or Google Auth to mitigate my concerns of losing 2FA/MFA on my stored account secrets.

It would be nice to utilize a master password sparingly and for important changes, then utilize a configured account MFA/2FA regularly for secrets or TOTP tokens before the token can be accessed on the password manager. If these tokens are sniffed they are short lived and not as easily replay-able.

If malware attacks on password managers becomes more common, utilizing a store of TOTP tokens is less and less safe.

Related topics + references

I would like to second this proposal. Especially when accessing a secret in public (eg on my phone while on the subway), having to confirm my password in plain view of cameras or other people is a security risk. Being able to simply tap my Yubikey to my phone as a confirmation option would be a huge improvement.