Oddbean new post about | logout
 nostr:npub1rnq3kmah2jqlewmgsv3w0mus7znmn7teupxctuyqwuaamwc4mmusdx7anc nostr:npub1rv5svmxg5j7p0gw8xz3mymh8sqlhxyjwcrzxm6tdkcuhfx6h8tcscqz2l6 expected this 😁

No I didn’t. Access to Bitwarden requires a TOTP. And my TOTP app is… on my phone. So in practice you need access to my phone in either case.

Losing my phone (which is the only place where I had my TOTP seeds) is a much more likely threat than getting my E2EE Bitwarden vault broken into. Now if I lose my phone I no longer lose my seeds.