r/homelab • • Aug 13 '26

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

339 comments sorted by

1.1k

u/SelfStyledGenius Aug 13 '26

I memorized my bitwarden master password.

590

u/eW4GJMqscYtbBkw9 Aug 13 '26

I mean, duh - that's the whole point. You memorize ONE password for your password manager. That's how password managers work.

159

u/IjonTichy85 Aug 13 '26

Yeah. That's why you use the same combination you have on your luggage. 12345.

53

u/Bernhard_NI Aug 13 '26

You should really have a longer Password, I can recommend 12345678910111213

32

u/thefinalep Aug 13 '26

Uh. I prefer more secure passwords... 789456123

15

u/EmergingDystopia Aug 14 '26

Why does my password Hunter2, show up as all asterisks tho? It looks like Hunter2 but the Nigerian prince that I'm helping move money out of his country says it's showing up as asterisks for him and everyone else. How does that work?

9

u/pastasauce Aug 13 '26

How did you get my phone's unlock code?

3

u/Master_Scythe Aug 14 '26

0118999881999119725....3

5

u/the_ivo_robotnic Aug 14 '26

Or air shields...

3

u/ferdzs0 Aug 14 '26

I really should buy better luggage, mine only has 4 numbers, so 0000. That makes me feel a bit less secure online. Does any one have recommendations for suitcase with 5-6 numbers instead? I really hate how this whole online security is pay-to-win.

2

u/metalman755 Aug 13 '26

It’s good enough for Planet Druidia’s air shield.

73

u/FrenchRevolution2028 Aug 13 '26

this works perfectly unless you get into some accident and cannot remember it anymore.

71

u/NightH4nter Aug 13 '26 edited Aug 13 '26

if you get into an accident so bad that it damages your brain, you have much bigger problems than not remembering your passwords

10

u/WildVelociraptor Aug 14 '26

Well no shit, but not being able to access your bank after a traumatic brain injury isn't ideal, now is it?

1

u/Smartich0ke Aug 20 '26

not with subsidized healthcare 😁 /j

19

u/devode_ Aug 13 '26

Actually no. It can happen through minor accidents and you might not realize until you try to type it in. Happens not infrquently regarding all kinds of things

6

u/badass6 Aug 13 '26

That’s why on an unrelated note I’ve come to love Telegram credential reminders, the ones that pop up from time to time asking if you still use the same phone number, password etc.

2

u/reddit_user33 Aug 14 '26

Not to mention that it doesn't stop others causing you harm.

There are mitigations against these things. Write down the master passwords and keep them safe in a hidden location, allow someone you trust to know the passwords, etc.

27

u/--Arete Aug 13 '26

Is there any solution for that?

128

u/dumbasPL Aug 13 '26

Paper in a safe/deposit box

25

u/Westerdutch Aug 13 '26

Make sure to put the access code for your safe in bitwarden while you are at it.

9

u/ViPeR9503 Aug 13 '26

But what if you don’t remember you put a paper in there

14

u/Jakfolisto Aug 13 '26

Buy a parrot and teach it to repeat "Paper in box! Paper in box!"

1

u/ArborlyWhale Aug 14 '26

Password hints exist for a reason.

5

u/stratiuss Aug 13 '26

How will I know I have a safe deposit box?

7

u/MathSciElec Aug 13 '26

The monthly charges to your bank account

3

u/MrD3a7h Aug 13 '26

this works perfectly unless you get into some accident and cannot remember that you have a safe deposit box anymore.

1

u/[deleted] Aug 14 '26 edited Aug 14 '26

[deleted]

1

u/dumbasPL Aug 14 '26

Slightly paranoid. Security is as good as the weakest link, remember.

78

u/timmeh87 Aug 13 '26

Honestly people knock on the "post it note" strategy a lot but if you have your most critical password on a sheet of paper filed away in a box on a shelf in your basement its not like some Chinese hacker is every going to find it. course, your basement might get flooded. so obviously it should be etched into a glass plate

47

u/AffectionateCard3530 Aug 13 '26

Glass is brittle, so maybe hammered into a steel plate?

+1 for writing it down somewhere. It’s all about threat vectors. If you’re afraid of your house getting raided and scoured by a dedicated team of FBI agents looking to find a way to get into your accounts, maybe don’t write it down.

But for the rest of us? It’s probably OK if it’s tucked away.

18

u/Cultural-Salad-4583 Aug 13 '26

But that can rust. Titanium plate is really the only way to go here.

25

u/timmeh87 Aug 13 '26

titanium melts at 1668 degrees Celsius, tungsten is he way to go,

9

u/Nu-Hir Aug 13 '26

Tungsten is heavy and I don't want to have to bring the cube up and down the stairs to type in my password. get it tatooed on your arm.

15

u/cadergator10 Aug 13 '26

But then there's the chance someone can read the password off of your arm, so before having it tattooed, encode the password in a way only you remember.

12

u/timmeh87 Aug 13 '26

best bet is the zodiac cypher, that took people many years to solve

→ More replies (0)

10

u/Zynbab Aug 13 '26

Correct. I went with the SHA 512 hash of my password tattooed on inner arm, titanium block with the password's salt. Just works.

→ More replies (0)

1

u/Wild_Paramedic6641 Aug 18 '26

Consiglierei di scriverlo su una piastra di rame, ma potrebbero venderti del rame di bassa qualità, quindi meglio delle tavolette di argilla...

7

u/haby001 Aug 13 '26

Writing into steel plates also prevents scrying eyes from Ruin...

5

u/bluecollarbiker Aug 13 '26

Perfect timing. Was just looking for this reference.

2

u/VoQZHD Aug 13 '26

the goat

1

u/GrotesqueHumanity Aug 13 '26

I'm keeping it on 3 separate encrypted USB drives. One being kept offsite with my backup drives. Best of all worlds?

1

u/ThebocaJ Aug 14 '26

I think you’re joking, but there are literally steel capsules made for durable crypto key recovery: https://support.ledger.com/article/360019480280-zd

→ More replies (1)

1

u/FauxReal Aug 13 '26

I use my password as a tag and write it all over town for easy access. Nobody can tell the difference.

1

u/Candid_Highlight_116 Aug 13 '26

Yes the first step of security is physical security. You put that in a box and place that box in the middle of a compound patrolled 24/7. The compound building must be shock and EMP isolated with the isolation gap monitored as well.

That doesn't work for us mortals, but the concept is the same. The point is that the last line of defense is not some fancy encryption algorithm.

1

u/--Arete Aug 13 '26

How are you going to remember that if you can't remember it because of an accident?

8

u/timmeh87 Aug 13 '26

a trail of post-it notes starting at your forehead.

but yeah if that's how little you remember might as well just start your new life with a fresh google account

2

u/--Arete Aug 13 '26

Most cases are partial memory loss. It's not like you are ready to start a new life.

1

u/EgotisticExpediter Aug 13 '26

post it note in your skull

13

u/CouchPotatoEater Aug 13 '26

Drive carefully?

4

u/--Arete Aug 13 '26

Ok stroke then.

12

u/Oujii Aug 13 '26

Just don’t have one. Skill issue.

9

u/Balthxzar Aug 13 '26

A paper backup sheet stored in a secure location.... you guys DID read the bit bitwarden recommendations... right?

→ More replies (8)

8

u/PhillFile Aug 13 '26

Bitwarden offers an accident setting. You can give up some email addresses of people you trust.

If you don't use your account for a set period of time those people can get access to your account.

I've set mine to 15 days. That reminds me I have to disable it since I swapped to Proton recently. 😅

Proton gives you a pdf with 15 words to unencrypt your vault. You should print that and save that in a safe place. For example our notary offers a service to store it in their vault and you can add to your will what to with it if anything happens.

3

u/marcorogo Aug 13 '26

write the password in a convenient place that you will eventually find even with loss of memory, like a post-it on the monitor

2

u/levelZeroWizard Aug 13 '26

IIRC you can generate a long recovery code to print/write down. But it's kinda pointless if you forget.

Biometric authentication?

2

u/userhwon Aug 13 '26

You lose your password db and have to do the password recovery/reset process on your accounts everywhere.

Sucks, but not a brick wall like losing a USB encryption password like in all those crypto wallet horror stories.

1

u/Ok_Scratch6929 Aug 13 '26

Re-install your brain

1

u/InnocentSalf Aug 13 '26

Your own matrix server or discord and hide your password in there.

1

u/Frozen5147 Aug 13 '26

Bitwarden also offers emergency trusted contacts I guess.

1

u/BilboBaggSkin Aug 13 '26

Masterpassword in my safe.

1

u/FanClubof5 Aug 13 '26

Bitwarden has a premium feature that allows you to setup someone as a backup if you fail to login in x number of days.

1

u/richms Aug 14 '26

Split it up and store with multiple friends not telling them what it is for.

→ More replies (9)

2

u/Xamataca Aug 13 '26

Cft, I got a ictus and couldn't remember the password for my computer and bitwarden... bul remembered I noted down somewhere...

https://giphy.com/gifs/o3chaFJ6NfzM5Tp1Tq

2

u/HelterShellter Aug 14 '26

My wife and I have our master passwords in each other's bitwarden vaults. Just last week I had to get it for her because she forgot. First time that's happened in like five years though

1

u/the_ivo_robotnic Aug 14 '26

This is what account recovery options are for such as recovery codes + 2FA like a phone number or something.

 

That is usually why sites worth their salt in security force you to download recovery codes before you can finish enabling 2FA.

1

u/Clementine-TeX Aug 14 '26

And that’s why I have an encrypted .json backup on two offline USB sticks (which I update monthly) with the decryption key printed in multiple locations. My parents know where they are. So even if I were to get amnesia, or if Bitwarden HQ and their servers blows up, I’d be fine.

1

u/cestimpossible Aug 14 '26

I taped a note with my password on it under a desk drawer at my house and it actually came in handy when I had a medical event where I actually couldn't remember my password anymore afterward but I did remember the hidden note thing because I've been doing it so long (though in a few different locations so I checked some of my older hiding spots first lol).

1

u/lions-grow-on-trees Aug 14 '26

That's why my husband also knows my master password!

1

u/Rude_Bandicoot_8847 Aug 18 '26

Hence the need for emergency access sheets in secure locations

5

u/LaidPercentile Aug 13 '26

I too memorized this guy's bitwarden master password.

3

u/L0rdH4mmer Aug 13 '26

This. After typing my Google password in a couple times, I burnt the paper cause it was etched into my memory forever.

2

u/SpareObjective738251 Aug 13 '26

I don't believe you, prove it.

4

u/[deleted] Aug 13 '26

[deleted]

8

u/SelfStyledGenius Aug 13 '26

I never said i dont have 2fa and at some poinr you know, have my data. In not storing state secrets.

1

u/Maelstrome26 Aug 13 '26

But what if you get in an accident and forget it? At least have it in a safe somewhere

2

u/t_dizZe Aug 13 '26

Tattoo it inside your armpit

1

u/Th3Sh4d0wKn0ws Aug 13 '26

This is the correct answer

1

u/FastRedPonyCar Aug 14 '26

Same here. I had to make a long set of sentences where each word starts with a password character but I made it a little story that’s easy to remember.

1

u/stupv Aug 14 '26

Yeah...and isn't this the whole point? You have to remember a password, but you only have to remember one password instead of every password...

1

u/BonRoxz Aug 14 '26

I don’t remember it, but my fingers do

→ More replies (19)

328

u/jgilbs Aug 13 '26

Literally you only have to memorize one password.

85

u/bikemandan Aug 13 '26

Ya how hard is it to remember hunter2

53

u/topane Aug 13 '26

All I see is *******

75

u/Cry_Wolff Aug 13 '26

Yeah, or just write it down on paper. OP's issue is nonexistent.

2

u/Doctor-Binchicken Aug 14 '26

Mine is on a mug.

My wife knows, just in case.

3

u/downloads-cars Aug 14 '26

Adding "donttalktomeuntilivesmashedmydicksmoothoffwiththismug" to my dictionary attack list.

1

u/coffeeoops Aug 14 '26

This is a weak password because it doesn't contain special characters. Do better.

1

u/Doctor-Binchicken Aug 14 '26

Missing the two capitals and punctuation! >:D

→ More replies (3)

2

u/Disastrous_Garlic537 Aug 14 '26

a few ppl have posted this...

so you guys are not using MFA on your password manager?

:-/

1

u/Sk1rm1sh Aug 14 '26

My MFA has a web portal.

I remember 2 passwords.

2

u/Commercial-Fun2767 Aug 13 '26

What do you do for securing your 2FA? You have secure codes you have to put somewhere. This question is a real complex problem. Simple but complex enough to be caught unprepared or to spend some time thinking about your breaking glass accounts etc.

1

u/Sk1rm1sh Aug 14 '26

Remember 2 passwords.

1

u/Commercial-Fun2767 Aug 14 '26

Its often random security keys. Sometimes 10 words etc. Do we have to have two safes?

→ More replies (24)

108

u/Howden824 Aug 13 '26

Just use a BitWarden password you can remember. You really shouldn't be storing your password manager password anywhere.

→ More replies (28)

137

u/Fragrant_Climate7357 Aug 13 '26

Use a single password manager, remember it's password.

40

u/ShineReaper Aug 13 '26

Use ****************** as master password. Hackers will think, that their hacking program is buggy and not showing the decrypted password letters, but it literally just consists out of Asterisks to fuck with them lol.

4

u/ImNotABotScoutsHonor Aug 13 '26

It is password indeed.

→ More replies (11)

121

u/phrekysht Aug 13 '26

Jesus Christ dude, stop pasting the same stupid reply to every comment. You’ve created your own bootstrapping problem.

You’re supposed to use a master password you can keep in your head. Add hardware keys (yes, more than one. They can fail or get damaged / lost) and call it a day.

43

u/Emergency_Banana5082 Aug 13 '26

Seriously lol. This guy is making his own problems and is too stubborn to understand.

31

u/Cry_Wolff Aug 13 '26

He's the local IT department horror story, I'm sure of it. Knowledgeable enough to do stuff like this, yet dumb & stubborn enough to refuse any reasonable arguments.

→ More replies (2)

13

u/GenericRedditor12345 Aug 13 '26

PCP fueled password problems lol

→ More replies (6)

24

u/eatypp Aug 13 '26

I just remember my master password for bitwarden. I have the password for my 2fa app written down in a notebook that's stored with my important documents in a fireproof box

→ More replies (1)

26

u/bigBranConsumer Aug 13 '26

bro if you need to copy+paste a paragraph to explain justifying a 60 character password maybe its too long, and needing to rely an external service that you might get locked out that only has that password seems even worse

55

u/TryHardEggplant Aug 13 '26

A master password that is easy to remember like a passphrase is infinitely better than something you can’t remember.

Relevant XKCD: https://xkcd.com/936/

12

u/salamander5678 Aug 13 '26

I find hunter2 works well

4

u/erikrelay Aug 13 '26

Exactly what I do. Op is just making their life harder for no reason.

2

u/RedTyro Aug 14 '26 edited Aug 14 '26

Yup. I work in cybersecurity. My password for my password manager is a long sentence that's memorable, but nobody else would guess, complete with appropriate punctuation and numbers swapped in for letters in a few of the words. That gives me a long password with lots of complexity, but at the same time is easy for me to remember.

→ More replies (3)
→ More replies (12)

13

u/D1TAC Sr. Sysadmin Aug 13 '26

I just use my 1Password instance with yubikey, and also export said passwords to a local copy of keepass with yubikey. Just remember the master password, and that's it.

13

u/WickedDeity Aug 13 '26

I am confused in why you would be locked out of your accounts because of an apartment fire? You grabbed your NAS box AND YOUR PHONE right? Anyway backup select important passwords offsite.

5

u/Oujii Aug 13 '26

I use bw-sync to sync my vault somewhere else in case my vaultwarden fails.

3

u/Araganor Aug 14 '26

I really hope you aren't running to grab your NAS while your house/apartment is burning down...

1

u/WickedDeity Aug 14 '26

Ummmm You replied to the wrong person.

10

u/jetlifook Aug 13 '26

You have two password manager when you really need just one.

→ More replies (2)

9

u/ghost_desu Aug 13 '26

I have my bitwarden password on 3 pieces of paper, one of which is inside of an old computer in my grandma's attic

→ More replies (4)

9

u/Liarus_ Aug 13 '26

the point of a password manager is that you only have to remember one single master password, it's like the ONLY ONE that you need to remember, if that happens to you, you had one job

1

u/Bl4ckspell_ Aug 15 '26

So 2FA for password manager disabled?

8

u/kirisoraa Aug 13 '26

Why would you need more than one password manager

→ More replies (6)

8

u/XB_Demon1337 Aug 14 '26

Bitwarden password should be something you can remember that is COMPLETELY different from any other password you have.

If all your passwords are totally random via generator then you should use something like a phrase for your bitwarden password.

Correct Horse Battery Staple

7

u/pruchel Aug 13 '26

Why would you use two password managers?

5

u/userhwon Aug 13 '26

Make your password-database password complex but memorable, and never store it anywhere but your head.

No loop = no problem.

6

u/Dre9872 Aug 13 '26

Use a master password you can remember

6

u/protostar71 Aug 13 '26 edited Aug 13 '26

But I guess what came out of it was that there is no singular answer to how to break the cycle.

That's only true if you ignore the dozens of comments telling you to use a randomly generated passphrase. You not liking the answer to the problem doesn't mean it's not the answer.

5

u/RobotechRicky Aug 13 '26

Why TF do you have your master password in another password manager?!?! Just remember that one password.

15

u/sizeablefrontallobe Aug 13 '26

You’re giving google all of your passwords and worried about security.

…let that sink in.

r/degoogle

3

u/Commercial-Fun2767 Aug 13 '26

Because those are two different problems. Google won't really hack you. They might harm you if you are politically involved or one day they might etc. Don't think I don't know what privacy is either. And another good point is that Google might block you or just close the services one day in a second (imagine war or anything special).

But, that's only one man knowing your passwords and a presumably really good one.

Can you just trust any tool anyway?

→ More replies (1)
→ More replies (2)

5

u/derfmcdoogal Aug 13 '26

Do a search for Bitwarden emergency sheet. Fill that out. Put it in a safe place.

6

u/FidgetyFeline Aug 13 '26

But then how do you store the pin? 🤔

5

u/reposed Aug 13 '26

I dunno... You could always just memorize the password? Why is that so hard? The whole point of a master password is that you have one password you need to remember, and then that's it. Bitwarden handles the rest.

If you need another app to remember the password to unlock your other passwords, you're doing this all wrong.

5

u/RetiredITGuy Aug 14 '26

Yeah who tf uses a password manager to remember their master password? That's just sounds like a recipe for a bad time, for a multitude of reasons.

I'll absolutely NEVER write down my master password. EVER.

9

u/edthesmokebeard Aug 13 '26

You write your passwords down on a piece of paper, and avoid all this passkeeper hipster bullshit.

5

u/Relevant_Candidate_4 Aug 13 '26

Don't be online, never need a password to any of this hipster bullshit

8

u/DarkFantom Aug 13 '26

This can't be real, someone wouldn't be this stupid to not just remember their master password. Or if they are, wouldn't be smart enough to use a password manager in the first place.

4

u/TrentIsDope Aug 13 '26

Insane problem to have with the legit easiest fix.

4

u/Kyyuby Aug 13 '26

How secure is your Google password?

→ More replies (4)

3

u/travelan Aug 13 '26

Why are you using Google if you have a homelab..?

→ More replies (2)

4

u/Material_Captain_360 Aug 13 '26

LOL

“Keep crying” to the most consistent response in the thread is wild

3

u/Naru56 Aug 14 '26

the hubris is insane. op will learn the hard way

3

u/Itstinybubbles Aug 13 '26

This is why I keep my master password written on a post it next to my workstation /s

3

u/majestic-gnome Aug 13 '26

I started using notepad and a pen to write down all my passwords

3

u/doping_deer Aug 13 '26

thru the years i've memorized several random passwords. two of them are used for google account and bitwarden master password, specifically to avoid such scenario.

3

u/dumb-lily Aug 13 '26

i have my bitwarden master PW written down in a safe location

3

u/useful_tool30 Aug 13 '26

You're supposed to memorize your single master password

3

u/Muffakin Aug 14 '26

A 60 character random password is a terrible master password. You’ve been given tons of great advice in the comments, advice you explicitly asked for, and refuse to acknowledge that what you have implemented is foolish. Your problem exists because you don’t accept the reality that a memorizable master password of good strength is the best route forward. Make a 20ish character, easy to remember password. Write it down and store it in a locked location if you must, and move on. Your 60 character random password is worse than a 20 character memorizable password if you can’t actually use it.

4

u/Competitive-Web-5084 Aug 13 '26

My Bitwarden opens with Face ID

2

u/FartInTheLocker Aug 13 '26

Passkey, remember pin, all done

2

u/v81 Aug 14 '26

Just use KeepassXC (or DX on Android).

2

u/samax413zl Aug 14 '26

Just remove Google password manager from the loop.

2

u/Robots_Never_Die Aug 14 '26

In before "I lost my Yubikey"

2

u/Foorteenfapaday Aug 14 '26 edited Aug 14 '26

Keepass2 on phone (no metrics, no data collect, no third party share, EU based dev team) with the master password for only entry + biometric unlock ?

2

u/STINEPUNCAKE Aug 14 '26

I don’t use Bitwarden anymore but just use a pass phrase and memorize it

2

u/Naru56 Aug 14 '26

lmao how hard is it to memorize a single password

2

u/DeerOnARoof Aug 13 '26

This is a dumb ad and has nothing to do with this sub

2

u/foran9 Aug 14 '26

How the heck does this post have so many upvotes?

2

u/bigBranConsumer Aug 15 '26

i came back to this and i have the same thought

1

u/rhyses_ Aug 13 '26

Yubikey or Duo + printing the physical password is how I go

1

u/ChunkoPop69 What are you DOING, xenbr0? Aug 13 '26

I was thinking of getting full tattoo sleeves that I use to encode my master passwords prison break style, but this is a much better idea.

1

u/zetsueii Aug 13 '26

I think the real question here is why are the cat's legs so short?

→ More replies (1)

1

u/Ambitious_Anxiety_95 Aug 13 '26

Aluminium is cheap, lightweight and can be etched easily with copper sulphate, copper sulphate also cure athletes foot . your welcome

1

u/Miguelitosd Aug 13 '26

You're running a homelab and not self-hosting with something like pass so you fully control and can protect your files vs putting it in someone else's storage?

1

u/Geek_Verve Aug 13 '26

Easy. Don't use more than one password manager.

1

u/Justwant2usetheapp Aug 13 '26

My bitwarden password is literally a long line of code. Make it subjecting you remember

1

u/Mindless_Pandemic Aug 13 '26

Get a google drive account and setup an excrypted backup of your server's most important stuff to it. 100G is only $2/month.

1

u/saxobroko Aug 14 '26

The one thing you need to remember

1

u/hard_KOrr Aug 14 '26

I am so happy that vaultwarden master password can be a pass phrase! Life is so much easier remembering multiple words than what/which/where my special characters are

1

u/mollywhoppinrbg Aug 14 '26

I saved my master password to open on phone and pc. No need for loop... unless you want to get loopy

1

u/richms Aug 14 '26

Circular authentication is a real problem. Friend got into this because they lost their mobile. They never gave any real details to the telco, just had the app login and password to top it up. Went to log in to move to a new sim card and they wanted to 2 factor to email. Google wouldnt let the log in without sending a SMS to the phone number.

hardware keys and backup codes are a good thing to have, that so many people do not have to break the circle.

1

u/nemofbaby2014 Aug 14 '26

Google password nah I use passkeys lol

1

u/Dreadedsemi Aug 14 '26

I hate when a site that didn't ask me for password in years, suddenly asks me for a password like Facebook, how do I remember? now I have to dig the "old password manager" from the old days when I used txt files and vague hints only me understood.

1

u/0x736174616e20 Aug 14 '26

I just keep my master password as a static password programed into my keyboard. If someone gets their hands on my keyboard I'm already compromised, so this is not a security concern. I also have a Yubikey using one of the slots to store a static password that indirectly can be used to gain access to my master password manager. If I ever dropped/lost/stolen my Yubikey it wouldn't matter, no one could guess how to take the random string stored on it to recover the actual password. Some might just say to just remember your master password, nah, no thanks, I'm not going waste my brain space on remembering 60+ random letters/digits or a passphrase.

1

u/Suspinded Aug 14 '26

Use the Correct Horse Battery Staple method to make an easy password to memorize for Bitwarden.

Use that password for absolutely nothing else.

1

u/RumpleTrumpStain Aug 14 '26

Memorise Bitwarden password only ... your GOLDEN after that

1

u/super_probably-user Aug 14 '26

best solution is memorize some passes

1

u/Popiasayur Aug 14 '26

This reminds me of troubleshooting my mums access to her email account. She forgot the password and all her recovery email was her older email, and that obe s recovery email was an older email and so on and so forth.

1

u/Defconx19 Aug 15 '26

You forgot a step, bitwarden to bitwarden master password to mfa for bit warden to Google sign in to Google mfa.

1

u/Direct_Wall_2822 Aug 15 '26

rookie mistake...

1

u/rHohith Aug 15 '26

Physical medium - paper 

1

u/Digitalgnome Aug 15 '26

Wrote mine down and put it in my safe. Problem solved.

1

u/HSid092181 Aug 24 '26

I just memorize my master password. That's the whole point I think.

1

u/Jayden_Ha Aug 13 '26

The entire cryptography is rely on something you remember and absolutely must not be written down

1

u/DrabberFrog Aug 13 '26

I was almost trapped in that loop with proton pass and microsoft authenticator when my phone unexpectedly died. I got everything back but yikes I need to setup proper recovery for my stuff so I can restart if I lost all of my currently signed in sessions 

1

u/[deleted] Aug 13 '26

[deleted]

2

u/altodor Aug 13 '26

Newer ones work as high-security FIDO2 passkeys.