Need recommendations on something like Vaultwarden but for 2FA only.

fedonr@lemmy.dbzer0.com to Selfhosted@lemmy.world – 27 points –

So I selfhost Vaultwarden which allows TOTP but I like to keep my 2FA and Password Manager separate, so I'm looking for something like Vaultwarden which can sync up with my server, but for 2FA only. I came across 2FAuth which can do it, but it only has webapp, so if a Alternative Service where there is a client for iOS and Android it would be a lifesaver. Thanks in advance for any suggestions or recommendations.

25

You are viewing a single comment

In my opinion the best 2FA is a yubikey. They have an TOPT app too, but I prefer webauthn.

I wish that cloudflare deal was still available. They are pretty expensive at RRP, although probably worth it on balance.

If yubikeys are too expensive for you, you can use the security keys. Webauthn is supported, but not TOTP. You could use vaultwarden or bitwarden for TOTP and the Security key as 2FA for bitwarden 🤔

I'm actually using KeepassXC etc at the moment and am waiting on them to support hmac-secret so the cheaper security keys work. Although I'm willing to switch to vaultwarden, I'd be more comfortable with both supporting it before I invest in it.

do you have two or more yubikeys? how do you handle sites that only allow registering a single webauthn dongle? how do you handle backup 2fa?

loosing my yubikey is the main reason why i havent used it yet for webauthn. I just use pass and openpgp keys stored on the yubikey as that way it was possible to backup the encryption private key to a seperate usb drive that can be used to restore it later if needed.

I have 2 yubikeys, one for backup in a safe place. If a site only allows one key, like PayPal, I use another method. Yubikeys are for 2FA on my nextcloud and bitwarden mainly. Both have backupkeys in case you lose them. Those keys are printed out and stored in a safe place too.