mirror of
https://github.com/dani-garcia/vaultwarden.git
synced 2026-02-05 00:29:40 +03:00
Enabling 2fa on bitwarden.com overwrites vaultwarden 2fa key #1655
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @freekvh on GitHub (Aug 2, 2023).
Subject of the issue
Enabling 2fa on bitwarden.com overwrites vaultwarden 2fa key in MS authenticator
Deployment environment
Install method:
Clients used:
Reverse proxy and version:
MySQL/MariaDB or PostgreSQL version:
Other relevant details:
Steps to reproduce
I went to bitwarden.com where I have the same account as in vaultwarden, I enabled 2fa and used MS authenticator to import the key via QR code. There was a warning that it would overwrite or update a key? I didn't think much of it because I may have experimented with bitwarden in the past. But afterwards I found that my vaultwarden key was gone.
Expected behaviour
Making a new TOTP for bitwarden.com leaves my vaultwarden TOTP untouched
Actual behaviour
Bitwarden.com key overwrites vaultwarden TOTP key.
Troubleshooting data
I thought 2fa was at least domain dependent, but apparently some things are exactly the same between vaultwarden and bitwarden.com. Maybe this is obvious to some, but it isn't to me.
@BlackDex commented on GitHub (Aug 2, 2023):
I'm not sure which version you used to create the key, but if that was before we modified the web-vault to display Vaultwarden instead of Bitwarden, then you are probably right, because that still had the Bitwarden key in there.
So, if you would use the latest version with the modified web-vault it should be fine.
Therefor going to close this is already fixed.
@freekvh commented on GitHub (Aug 2, 2023):
Ah ok, yeah the key was created a long time a ago, using the new version it should be fine then, I will try to reset 2fa on vaultwarden now then... I good challenge but I bet doable from the cli. Thanx.
@BlackDex commented on GitHub (Aug 2, 2023):
Via the admin interface you can remove 2fa from your account.
@freekvh commented on GitHub (Aug 2, 2023):
Yes this worked. Thank you.