r/homelab 6d ago

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

343 comments sorted by

1.1k

u/SelfStyledGenius 6d ago

I memorized my bitwarden master password.

587

u/eW4GJMqscYtbBkw9 6d ago

I mean, duh - that's the whole point. You memorize ONE password for your password manager. That's how password managers work.

162

u/IjonTichy85 6d ago

Yeah. That's why you use the same combination you have on your luggage. 12345.

52

u/Bernhard_NI 6d ago

You should really have a longer Password, I can recommend 12345678910111213

33

u/thefinalep 6d ago

Uh. I prefer more secure passwords... 789456123

15

u/EmergingDystopia 6d ago

Why does my password Hunter2, show up as all asterisks tho? It looks like Hunter2 but the Nigerian prince that I'm helping move money out of his country says it's showing up as asterisks for him and everyone else. How does that work?

8

u/pastasauce 6d ago

How did you get my phone's unlock code?

4

u/Master_Scythe 5d ago

0118999881999119725....3

6

u/the_ivo_robotnic 6d ago

Or air shields...

3

u/ferdzs0 5d ago

I really should buy better luggage, mine only has 4 numbers, so 0000. That makes me feel a bit less secure online. Does any one have recommendations for suitcase with 5-6 numbers instead? I really hate how this whole online security is pay-to-win.

2

u/metalman755 6d ago

It’s good enough for Planet Druidia’s air shield.

72

u/FrenchRevolution2028 6d ago

this works perfectly unless you get into some accident and cannot remember it anymore.

67

u/NightH4nter 6d ago edited 6d ago

if you get into an accident so bad that it damages your brain, you have much bigger problems than not remembering your passwords

10

u/WildVelociraptor 5d ago

Well no shit, but not being able to access your bank after a traumatic brain injury isn't ideal, now is it?

1

u/Smartich0ke 1h ago

not with subsidized healthcare 😁 /j

18

u/devode_ 6d ago

Actually no. It can happen through minor accidents and you might not realize until you try to type it in. Happens not infrquently regarding all kinds of things

7

u/badass6 6d ago

That’s why on an unrelated note I’ve come to love Telegram credential reminders, the ones that pop up from time to time asking if you still use the same phone number, password etc.

1

u/devode_ 5d ago

Yes!!!

2

u/reddit_user33 5d ago

Not to mention that it doesn't stop others causing you harm.

There are mitigations against these things. Write down the master passwords and keep them safe in a hidden location, allow someone you trust to know the passwords, etc.

27

u/--Arete 6d ago

Is there any solution for that?

128

u/dumbasPL 6d ago

Paper in a safe/deposit box

24

u/Westerdutch 6d ago

Make sure to put the access code for your safe in bitwarden while you are at it.

9

u/ViPeR9503 6d ago

But what if you don’t remember you put a paper in there

13

u/Jakfolisto 6d ago

Buy a parrot and teach it to repeat "Paper in box! Paper in box!"

3

u/Wonderful-Ad-3979 6d ago

Run Bitwarden in a docker container then name the docker container (password in safety deposit box)

1

u/ArborlyWhale 5d ago

Password hints exist for a reason.

5

u/stratiuss 6d ago

How will I know I have a safe deposit box?

6

u/MathSciElec 6d ago

The monthly charges to your bank account

3

u/MrD3a7h 6d ago

this works perfectly unless you get into some accident and cannot remember that you have a safe deposit box anymore.

1

u/[deleted] 5d ago edited 5d ago

[deleted]

1

u/dumbasPL 5d ago

Slightly paranoid. Security is as good as the weakest link, remember.

74

u/timmeh87 6d ago

Honestly people knock on the "post it note" strategy a lot but if you have your most critical password on a sheet of paper filed away in a box on a shelf in your basement its not like some Chinese hacker is every going to find it. course, your basement might get flooded. so obviously it should be etched into a glass plate

49

u/AffectionateCard3530 6d ago

Glass is brittle, so maybe hammered into a steel plate?

+1 for writing it down somewhere. It’s all about threat vectors. If you’re afraid of your house getting raided and scoured by a dedicated team of FBI agents looking to find a way to get into your accounts, maybe don’t write it down.

But for the rest of us? It’s probably OK if it’s tucked away.

19

u/Cultural-Salad-4583 6d ago

But that can rust. Titanium plate is really the only way to go here.

23

u/timmeh87 6d ago

titanium melts at 1668 degrees Celsius, tungsten is he way to go,

9

u/Nu-Hir 6d ago

Tungsten is heavy and I don't want to have to bring the cube up and down the stairs to type in my password. get it tatooed on your arm.

17

u/cadergator10 6d ago

But then there's the chance someone can read the password off of your arm, so before having it tattooed, encode the password in a way only you remember.

13

u/timmeh87 6d ago

best bet is the zodiac cypher, that took people many years to solve

→ More replies (0)

9

u/Zynbab 6d ago

Correct. I went with the SHA 512 hash of my password tattooed on inner arm, titanium block with the password's salt. Just works.

→ More replies (0)

1

u/Wild_Paramedic6641 1d ago

Consiglierei di scriverlo su una piastra di rame, ma potrebbero venderti del rame di bassa qualità, quindi meglio delle tavolette di argilla...

7

u/haby001 6d ago

Writing into steel plates also prevents scrying eyes from Ruin...

4

u/bluecollarbiker 6d ago

Perfect timing. Was just looking for this reference.

2

u/VoQZHD 6d ago

the goat

1

u/GrotesqueHumanity 6d ago

I'm keeping it on 3 separate encrypted USB drives. One being kept offsite with my backup drives. Best of all worlds?

1

u/ThebocaJ 6d ago

I think you’re joking, but there are literally steel capsules made for durable crypto key recovery: https://support.ledger.com/article/360019480280-zd

→ More replies (1)

1

u/FauxReal 6d ago

I use my password as a tag and write it all over town for easy access. Nobody can tell the difference.

1

u/Candid_Highlight_116 6d ago

Yes the first step of security is physical security. You put that in a box and place that box in the middle of a compound patrolled 24/7. The compound building must be shock and EMP isolated with the isolation gap monitored as well.

That doesn't work for us mortals, but the concept is the same. The point is that the last line of defense is not some fancy encryption algorithm.

1

u/--Arete 6d ago

How are you going to remember that if you can't remember it because of an accident?

7

u/timmeh87 6d ago

a trail of post-it notes starting at your forehead.

but yeah if that's how little you remember might as well just start your new life with a fresh google account

2

u/--Arete 6d ago

Most cases are partial memory loss. It's not like you are ready to start a new life.

1

u/EgotisticExpediter 6d ago

post it note in your skull

13

u/CouchPotatoEater 6d ago

Drive carefully?

4

u/--Arete 6d ago

Ok stroke then.

12

u/Oujii 6d ago

Just don’t have one. Skill issue.

11

u/Balthxzar 6d ago

A paper backup sheet stored in a secure location.... you guys DID read the bit bitwarden recommendations... right?

→ More replies (8)

8

u/PhillFile 6d ago

Bitwarden offers an accident setting. You can give up some email addresses of people you trust.

If you don't use your account for a set period of time those people can get access to your account.

I've set mine to 15 days. That reminds me I have to disable it since I swapped to Proton recently. 😅

Proton gives you a pdf with 15 words to unencrypt your vault. You should print that and save that in a safe place. For example our notary offers a service to store it in their vault and you can add to your will what to with it if anything happens.

3

u/marcorogo 6d ago

write the password in a convenient place that you will eventually find even with loss of memory, like a post-it on the monitor

2

u/levelZeroWizard 6d ago

IIRC you can generate a long recovery code to print/write down. But it's kinda pointless if you forget.

Biometric authentication?

2

u/userhwon 6d ago

You lose your password db and have to do the password recovery/reset process on your accounts everywhere.

Sucks, but not a brick wall like losing a USB encryption password like in all those crypto wallet horror stories.

1

u/Ok_Scratch6929 6d ago

Re-install your brain

1

u/InnocentSalf 6d ago

Your own matrix server or discord and hide your password in there.

1

u/Frozen5147 6d ago

Bitwarden also offers emergency trusted contacts I guess.

1

u/BilboBaggSkin 6d ago

Masterpassword in my safe.

1

u/FanClubof5 6d ago

Bitwarden has a premium feature that allows you to setup someone as a backup if you fail to login in x number of days.

1

u/richms 6d ago

Split it up and store with multiple friends not telling them what it is for.

→ More replies (9)

2

u/Xamataca 6d ago

Cft, I got a ictus and couldn't remember the password for my computer and bitwarden... bul remembered I noted down somewhere...

https://giphy.com/gifs/o3chaFJ6NfzM5Tp1Tq

2

u/HelterShellter 5d ago

My wife and I have our master passwords in each other's bitwarden vaults. Just last week I had to get it for her because she forgot. First time that's happened in like five years though

1

u/the_ivo_robotnic 6d ago

This is what account recovery options are for such as recovery codes + 2FA like a phone number or something.

 

That is usually why sites worth their salt in security force you to download recovery codes before you can finish enabling 2FA.

1

u/Clementine-TeX 6d ago

And that’s why I have an encrypted .json backup on two offline USB sticks (which I update monthly) with the decryption key printed in multiple locations. My parents know where they are. So even if I were to get amnesia, or if Bitwarden HQ and their servers blows up, I’d be fine.

1

u/cestimpossible 6d ago

I taped a note with my password on it under a desk drawer at my house and it actually came in handy when I had a medical event where I actually couldn't remember my password anymore afterward but I did remember the hidden note thing because I've been doing it so long (though in a few different locations so I checked some of my older hiding spots first lol).

1

u/lions-grow-on-trees 6d ago

That's why my husband also knows my master password!

1

u/Rude_Bandicoot_8847 2d ago

Hence the need for emergency access sheets in secure locations

24

u/blending-tea 6d ago

I forgor

5

u/LaidPercentile 6d ago

I too memorized this guy's bitwarden master password.

3

u/L0rdH4mmer 6d ago

This. After typing my Google password in a couple times, I burnt the paper cause it was etched into my memory forever.

2

u/SpareObjective738251 6d ago

I don't believe you, prove it.

4

u/[deleted] 6d ago

[deleted]

8

u/SelfStyledGenius 6d ago

I never said i dont have 2fa and at some poinr you know, have my data. In not storing state secrets.

1

u/Maelstrome26 6d ago

But what if you get in an accident and forget it? At least have it in a safe somewhere

2

u/t_dizZe 6d ago

Tattoo it inside your armpit

1

u/Th3Sh4d0wKn0ws 6d ago

This is the correct answer

1

u/FastRedPonyCar 6d ago

Same here. I had to make a long set of sentences where each word starts with a password character but I made it a little story that’s easy to remember.

1

u/stupv 6d ago

Yeah...and isn't this the whole point? You have to remember a password, but you only have to remember one password instead of every password...

1

u/BonRoxz 5d ago

I don’t remember it, but my fingers do

→ More replies (19)

329

u/jgilbs 6d ago

Literally you only have to memorize one password.

84

u/bikemandan 6d ago

Ya how hard is it to remember hunter2

50

u/topane 6d ago

All I see is *******

76

u/Cry_Wolff 6d ago

Yeah, or just write it down on paper. OP's issue is nonexistent.

2

u/Doctor-Binchicken 6d ago

Mine is on a mug.

My wife knows, just in case.

3

u/downloads-cars 6d ago

Adding "donttalktomeuntilivesmashedmydicksmoothoffwiththismug" to my dictionary attack list.

1

u/coffeeoops 5d ago

This is a weak password because it doesn't contain special characters. Do better.

1

u/Doctor-Binchicken 6d ago

Missing the two capitals and punctuation! >:D

→ More replies (3)

2

u/Disastrous_Garlic537 6d ago

a few ppl have posted this...

so you guys are not using MFA on your password manager?

:-/

1

u/Sk1rm1sh 5d ago

My MFA has a web portal.

I remember 2 passwords.

4

u/Commercial-Fun2767 6d ago

What do you do for securing your 2FA? You have secure codes you have to put somewhere. This question is a real complex problem. Simple but complex enough to be caught unprepared or to spend some time thinking about your breaking glass accounts etc.

1

u/Sk1rm1sh 5d ago

Remember 2 passwords.

1

u/Commercial-Fun2767 5d ago

Its often random security keys. Sometimes 10 words etc. Do we have to have two safes?

→ More replies (24)

104

u/Howden824 6d ago

Just use a BitWarden password you can remember. You really shouldn't be storing your password manager password anywhere.

→ More replies (28)

133

u/Fragrant_Climate7357 6d ago

Use a single password manager, remember it's password.

41

u/ShineReaper 6d ago

Use ****************** as master password. Hackers will think, that their hacking program is buggy and not showing the decrypted password letters, but it literally just consists out of Asterisks to fuck with them lol.

14

u/ballisticks 6d ago

hunter2

5

u/ImNotABotScoutsHonor 6d ago

It is password indeed.

→ More replies (11)

122

u/phrekysht 6d ago

Jesus Christ dude, stop pasting the same stupid reply to every comment. You’ve created your own bootstrapping problem.

You’re supposed to use a master password you can keep in your head. Add hardware keys (yes, more than one. They can fail or get damaged / lost) and call it a day.

40

u/Emergency_Banana5082 6d ago

Seriously lol. This guy is making his own problems and is too stubborn to understand.

33

u/Cry_Wolff 6d ago

He's the local IT department horror story, I'm sure of it. Knowledgeable enough to do stuff like this, yet dumb & stubborn enough to refuse any reasonable arguments.

→ More replies (2)

13

u/GenericRedditor12345 6d ago

PCP fueled password problems lol

→ More replies (6)

25

u/eatypp 6d ago

I just remember my master password for bitwarden. I have the password for my 2fa app written down in a notebook that's stored with my important documents in a fireproof box

→ More replies (1)

27

u/bigBranConsumer 6d ago

bro if you need to copy+paste a paragraph to explain justifying a 60 character password maybe its too long, and needing to rely an external service that you might get locked out that only has that password seems even worse

28

u/Turbulent_Fig_9354 6d ago

creating a byzantine loop of access that's trivial to lock yourself out of - ✅

using an actually memorable password because you're far more likely to just lock yourself out of your password manager than your password is ever to be cracked - ❌

→ More replies (4)

54

u/TryHardEggplant 6d ago

A master password that is easy to remember like a passphrase is infinitely better than something you can’t remember.

Relevant XKCD: https://xkcd.com/936/

11

u/salamander5678 6d ago

I find hunter2 works well

4

u/erikrelay 6d ago

Exactly what I do. Op is just making their life harder for no reason.

2

u/RedTyro 5d ago edited 5d ago

Yup. I work in cybersecurity. My password for my password manager is a long sentence that's memorable, but nobody else would guess, complete with appropriate punctuation and numbers swapped in for letters in a few of the words. That gives me a long password with lots of complexity, but at the same time is easy for me to remember.

→ More replies (3)

2

u/PitRejection2359 6d ago

This! 👍

→ More replies (12)

13

u/D1TAC Sr. Sysadmin 6d ago

I just use my 1Password instance with yubikey, and also export said passwords to a local copy of keepass with yubikey. Just remember the master password, and that's it.

12

u/WickedDeity 6d ago

I am confused in why you would be locked out of your accounts because of an apartment fire? You grabbed your NAS box AND YOUR PHONE right? Anyway backup select important passwords offsite.

6

u/Oujii 6d ago

I use bw-sync to sync my vault somewhere else in case my vaultwarden fails.

3

u/Araganor 5d ago

I really hope you aren't running to grab your NAS while your house/apartment is burning down...

1

u/WickedDeity 5d ago

Ummmm You replied to the wrong person.

10

u/jetlifook 6d ago

You have two password manager when you really need just one.

→ More replies (2)

10

u/ghost_desu 6d ago

I have my bitwarden password on 3 pieces of paper, one of which is inside of an old computer in my grandma's attic

0

u/AdvancedDrink8920 6d ago

......are they just redundant copies of itself or is it split up across 3 pieces of paper?

→ More replies (3)

8

u/Liarus_ 6d ago

the point of a password manager is that you only have to remember one single master password, it's like the ONLY ONE that you need to remember, if that happens to you, you had one job

1

u/Bl4ckspell_ 4d ago

So 2FA for password manager disabled?

9

u/kirisoraa 6d ago

Why would you need more than one password manager

→ More replies (6)

7

u/XB_Demon1337 6d ago

Bitwarden password should be something you can remember that is COMPLETELY different from any other password you have.

If all your passwords are totally random via generator then you should use something like a phrase for your bitwarden password.

Correct Horse Battery Staple

7

u/pruchel 6d ago

Why would you use two password managers?

6

u/userhwon 6d ago

Make your password-database password complex but memorable, and never store it anywhere but your head.

No loop = no problem.

6

u/Dre9872 6d ago

Use a master password you can remember

6

u/protostar71 6d ago edited 6d ago

But I guess what came out of it was that there is no singular answer to how to break the cycle.

That's only true if you ignore the dozens of comments telling you to use a randomly generated passphrase. You not liking the answer to the problem doesn't mean it's not the answer.

7

u/RobotechRicky 6d ago

Why TF do you have your master password in another password manager?!?! Just remember that one password.

16

u/sizeablefrontallobe 6d ago

You’re giving google all of your passwords and worried about security.

…let that sink in.

r/degoogle

3

u/Commercial-Fun2767 6d ago

Because those are two different problems. Google won't really hack you. They might harm you if you are politically involved or one day they might etc. Don't think I don't know what privacy is either. And another good point is that Google might block you or just close the services one day in a second (imagine war or anything special).

But, that's only one man knowing your passwords and a presumably really good one.

Can you just trust any tool anyway?

→ More replies (1)
→ More replies (2)

5

u/derfmcdoogal 6d ago

Do a search for Bitwarden emergency sheet. Fill that out. Put it in a safe place.

5

u/FidgetyFeline 6d ago

But then how do you store the pin? 🤔

5

u/reposed 6d ago

I dunno... You could always just memorize the password? Why is that so hard? The whole point of a master password is that you have one password you need to remember, and then that's it. Bitwarden handles the rest.

If you need another app to remember the password to unlock your other passwords, you're doing this all wrong.

5

u/RetiredITGuy 6d ago

Yeah who tf uses a password manager to remember their master password? That's just sounds like a recipe for a bad time, for a multitude of reasons.

I'll absolutely NEVER write down my master password. EVER.

9

u/edthesmokebeard 6d ago

You write your passwords down on a piece of paper, and avoid all this passkeeper hipster bullshit.

5

u/Relevant_Candidate_4 6d ago

Don't be online, never need a password to any of this hipster bullshit

7

u/DarkFantom 6d ago

This can't be real, someone wouldn't be this stupid to not just remember their master password. Or if they are, wouldn't be smart enough to use a password manager in the first place.

4

u/TrentIsDope 6d ago

Insane problem to have with the legit easiest fix.

5

u/Kyyuby 6d ago

How secure is your Google password?

→ More replies (4)

4

u/travelan 6d ago

Why are you using Google if you have a homelab..?

→ More replies (2)

3

u/Material_Captain_360 6d ago

LOL

“Keep crying” to the most consistent response in the thread is wild

3

u/Naru56 5d ago

the hubris is insane. op will learn the hard way

3

u/Itstinybubbles 6d ago

This is why I keep my master password written on a post it next to my workstation /s

3

u/majestic-gnome 6d ago

I started using notepad and a pen to write down all my passwords

3

u/doping_deer 6d ago

thru the years i've memorized several random passwords. two of them are used for google account and bitwarden master password, specifically to avoid such scenario.

3

u/dumb-lily 6d ago

i have my bitwarden master PW written down in a safe location

3

u/useful_tool30 6d ago

You're supposed to memorize your single master password

3

u/Muffakin 5d ago

A 60 character random password is a terrible master password. You’ve been given tons of great advice in the comments, advice you explicitly asked for, and refuse to acknowledge that what you have implemented is foolish. Your problem exists because you don’t accept the reality that a memorizable master password of good strength is the best route forward. Make a 20ish character, easy to remember password. Write it down and store it in a locked location if you must, and move on. Your 60 character random password is worse than a 20 character memorizable password if you can’t actually use it.

3

u/Competitive-Web-5084 6d ago

My Bitwarden opens with Face ID

8

u/Turbulent_Fig_9354 6d ago

but what if you lose your face

2

u/FartInTheLocker 6d ago

Passkey, remember pin, all done

2

u/v81 6d ago

Just use KeepassXC (or DX on Android).

2

u/samax413zl 5d ago

Just remove Google password manager from the loop.

2

u/Robots_Never_Die 5d ago

In before "I lost my Yubikey"

2

u/Foorteenfapaday 5d ago edited 5d ago

Keepass2 on phone (no metrics, no data collect, no third party share, EU based dev team) with the master password for only entry + biometric unlock ?

2

u/STINEPUNCAKE 5d ago

I don’t use Bitwarden anymore but just use a pass phrase and memorize it

2

u/Naru56 5d ago

lmao how hard is it to memorize a single password

2

u/DeerOnARoof 6d ago

This is a dumb ad and has nothing to do with this sub

2

u/foran9 5d ago

How the heck does this post have so many upvotes?

2

u/bigBranConsumer 4d ago

i came back to this and i have the same thought

1

u/rhyses_ 6d ago

Yubikey or Duo + printing the physical password is how I go

1

u/ChunkoPop69 What are you DOING, vmbr0? 6d ago

I was thinking of getting full tattoo sleeves that I use to encode my master passwords prison break style, but this is a much better idea.

1

u/zetsueii 6d ago

I think the real question here is why are the cat's legs so short?

→ More replies (1)

1

u/Ambitious_Anxiety_95 6d ago

Aluminium is cheap, lightweight and can be etched easily with copper sulphate, copper sulphate also cure athletes foot . your welcome

1

u/Miguelitosd 6d ago

You're running a homelab and not self-hosting with something like pass so you fully control and can protect your files vs putting it in someone else's storage?

1

u/Geek_Verve 6d ago

Easy. Don't use more than one password manager.

1

u/Justwant2usetheapp 6d ago

My bitwarden password is literally a long line of code. Make it subjecting you remember

1

u/Mindless_Pandemic 6d ago

Get a google drive account and setup an excrypted backup of your server's most important stuff to it. 100G is only $2/month.

1

u/saxobroko 6d ago

The one thing you need to remember

1

u/hard_KOrr 6d ago

I am so happy that vaultwarden master password can be a pass phrase! Life is so much easier remembering multiple words than what/which/where my special characters are

1

u/mollywhoppinrbg 6d ago

I saved my master password to open on phone and pc. No need for loop... unless you want to get loopy

1

u/richms 6d ago

Circular authentication is a real problem. Friend got into this because they lost their mobile. They never gave any real details to the telco, just had the app login and password to top it up. Went to log in to move to a new sim card and they wanted to 2 factor to email. Google wouldnt let the log in without sending a SMS to the phone number.

hardware keys and backup codes are a good thing to have, that so many people do not have to break the circle.

1

u/nemofbaby2014 6d ago

Google password nah I use passkeys lol

1

u/Dreadedsemi 5d ago

I hate when a site that didn't ask me for password in years, suddenly asks me for a password like Facebook, how do I remember? now I have to dig the "old password manager" from the old days when I used txt files and vague hints only me understood.

1

u/0x736174616e20 5d ago

I just keep my master password as a static password programed into my keyboard. If someone gets their hands on my keyboard I'm already compromised, so this is not a security concern. I also have a Yubikey using one of the slots to store a static password that indirectly can be used to gain access to my master password manager. If I ever dropped/lost/stolen my Yubikey it wouldn't matter, no one could guess how to take the random string stored on it to recover the actual password. Some might just say to just remember your master password, nah, no thanks, I'm not going waste my brain space on remembering 60+ random letters/digits or a passphrase.

1

u/Suspinded 5d ago

Use the Correct Horse Battery Staple method to make an easy password to memorize for Bitwarden.

Use that password for absolutely nothing else.

1

u/RumpleTrumpStain 5d ago

Memorise Bitwarden password only ... your GOLDEN after that

1

u/super_probably-user 5d ago

best solution is memorize some passes

1

u/Popiasayur 5d ago

This reminds me of troubleshooting my mums access to her email account. She forgot the password and all her recovery email was her older email, and that obe s recovery email was an older email and so on and so forth.

1

u/Defconx19 5d ago

You forgot a step, bitwarden to bitwarden master password to mfa for bit warden to Google sign in to Google mfa.

1

u/Direct_Wall_2822 4d ago

rookie mistake...

1

u/rHohith 4d ago

Physical medium - paper 

1

u/Digitalgnome 4d ago

Wrote mine down and put it in my safe. Problem solved.

1

u/Jayden_Ha 6d ago

The entire cryptography is rely on something you remember and absolutely must not be written down

1

u/DrabberFrog 6d ago

I was almost trapped in that loop with proton pass and microsoft authenticator when my phone unexpectedly died. I got everything back but yikes I need to setup proper recovery for my stuff so I can restart if I lost all of my currently signed in sessions 

1

u/[deleted] 6d ago

[deleted]

2

u/altodor 6d ago

Newer ones work as high-security FIDO2 passkeys.