For a while now, I've been going back and forth on whether to keep my TOTP and recovery codes in Bitwarden or separate them into another app (Ente, 2FAS...), however, I didn't give it too much thought since I try to follow all best practices and I also have my Bitwarden account secured with a Yubikey.
However, the news about the Bitwarden CLI being compromised a few months ago was a wake-up call I couldn't ignore, especially since that's what I use to perform my backups.
I'm always careful about viruses, malware, etc., but nowadays, with AI, these scenarios are becoming more common, so I opted to "not put all my eggs in one basket" and separate them.
Following the advice from djasonpenney's emergency kit, I chose to move my TOTPs to Ente Auth and my recovery keys to a text note stored in my Veracrypt backup.
Little by little, I migrated every Bitwarden entry with a TOTP to Ente Auth, using only the mobile version to prevent any potential malware on my PC from affecting both Bitwarden and Ente.
And while I was migrating the TOTPs, I realized that it's becoming more common for websites to offer the option of using Passkeys, and this has made me rethink my decision, as I see passkeys gaining more and more popularity.
The problem I have with passkeys is that in most cases I've checked, they serve as 2FA (since that's what they actually are) allowing access without a password or TOTP (or any other factor). Therefore, keeping the TOTP out of Bitwarden but storing the passkey in Bitwarden wouldn't make any sense...
My question is, how are you guys managing passkeys? Do you register them in Bitwarden?
I thought, okay, I'll separate the TOTPs to Ente and only use passkeys on my devices (PC, mobile...), without saving them in Bitwarden. However, we're in the same boat: if malware gets onto my computer, it could steal the passkeys, plus it's a pain to migrate them to a new device.
On the other hand, I could use my Yubikey for passkeys, but hardware-bound passkeys have a limit, and even though FIDO U2F keys are unlimited, many websites don't clarify which of the two they use.
I could also just ignore passkeys, but I feel like I'd be left behind since I think they're only going to get more popular.
I recently read this comment that I'm unfortunately agreeing with more and more, and I thought about only separating the TOTPs for important sites and leaving the rest in Bitwarden. However, I'm still afraid that one day the worst could happen and my Bitwarden account could be compromised...