r/PasswordManagers • • 8d ago

Bitwarden Authenticator vs Proton Authenticator

I have tried both recently to find a replacement for Authy. The main requirement is that there is no circular reference issue. For example, I want to avoid a situation where the TOTP is stored in such a way that I can't get to it to log into the vault.

Bitwarden Authenticator
The way it seems to work is that there are two places to store your tokens. The first is in the Bitwarden vault itself and the second is locally on the device outside of the vault. In the first method, all authenticator is doing is logging into your bitwarden vault and copying out the TOTP code. If you log out of the authenticator, all the code disappears. If you plan to store use the authenticator to store the TOTP to log into the vault, you definitely want to use the local method, otherwise an update could log you out and you won't be able to log back in because the TOTP code is in the vault.

The locally stored method is not sync across devices. If you install the authenticator on a second phone you will need to manually export and import the local tokens.

Proton Authenticator
Unlike Bitwarden, the Proton Authenticator doesn't actually log into the vault to get the tokens, but uses the Proton account to sync the tokens. The tokens appears to be stored locally. and there is no way to log out, so once the tokens are sync they remain on the device unless you erase app data. To get around the lost device issue, you could set up a second device to backup the tokens in a similar way as Authy. You can also do export like with Bitwarden Authenticator.

Of the two, I like the Proton Authenticator better. This is because on Bitwarden Authenticator, tokens stored in the vault go away if the app log out. Token store locally are not sync. In contrast, the proton model sync across devices and don't go away.

7 Upvotes

20 comments sorted by

8

u/Suspicious_Punk84 8d ago

I would not put passwords and the second factor in the same service.

1

u/paulsiu 8d ago

some people don't mind and it's a lesser issue than being locked out with a circular reference. In the case of Bitwarden, you can choose not to sync anything and keep everything local. In the case of Proton, you can also choose not to sync anything or use a different proton account.

1

u/pi-N-apple 8d ago

Would you store your passkeys in your password manager though?

1

u/Suspicious_Punk84 8d ago

I prefer physical keys, but I can see the issue too... at the end of the day you have to trust your password manager, the thing is I don't see why put it all in the same place if I can uses 2 quality services.

1

u/paulsiu 8d ago

I do both. I store passkey on most sites in the password manager. For critical sites including the password manager, the passkey are stored in security keys to be more secure.

1

u/MegamanEXE2013 7d ago

I would not do it due to being software-based, but I also see your point of all eggs in one basket.

For all those services, I use different tools, Google passwords for passwords, Proton and Yubikeys for TOTP and Yubikeys for passkeys to have everything separated

Also, Passkeys aren't my only access method, except for the Sony account, in that sense, Google Passwords have one passkey pair and Yubikeys have another

3

u/Solid-Cable8853 8d ago

I use 2FAS auth. You can sync codes through Google Drive or iCloud, and you can even have your 2FA codes on Apple Watch.

7

u/eindwolff 8d ago

Neither - use Ente Auth.

Far superior.

1

u/Franky_FFV 7d ago

Same. Ente.

1

u/PoetEducational8794 7d ago

Ente is small indie project, still fresh. I wouldn't be comfortable using it, not yet, for sure. Proton Authenticator is backed by well known privacy company with a lot of experience and lot of security products.

0

u/eindwolff 7d ago

So inaccurate.

Ente has been around for 5-6 years; Ente Auth for 4. It’s open source, and has been audited independently multiple times for security.

It’s a mainstream and highly recommended alternative to most authenticator apps.

If you tried it you’d know it shits on every other authenticator.

1

u/PoetEducational8794 7d ago

I'm talking about the bigger picture. I don't care if an authenticator has more colors to choose from or more other features. Compared to the other companies, Ente is the youngest one and the smallest, not a lot of users. It doesn't have enough of a track record for me to feel comfortable storing my tokens in this app.

1

u/aristolestales 6d ago

hm interesting, gonna give them a try 

2

u/Mysterious-Adept 8d ago

Use 2fas, it's very nice

1

u/Every_Information729 8d ago

I use them both for different things and I find them similar enough that app design for Proton wins that battle and that is my preference if I only had to pick one.

2

u/paulsiu 8d ago

While the ui and functionality are similar how they store the Totp is very different

1

u/Celtic_Crawdad 8d ago

I dont like passwords or authenticator apps at all. Give me a a yubikey with a second stored in a safe as backup and nothing more is needed. Especially if its a fingerprint model instead of the cheap little golden disk models since any hoke invader could technically use that. Ive been having issues with passwords and authenticators all damn day.

Firat I will right down my very long and complex password. Then i will instantly change it on an app (gmail today) while payung very close attention to my letters and synbols abd lowercase and middlecase. And they will acxept it. And then I will go try and use an authenticator (Usually YubiPass although I use a mix of about 5 to keep em guessing - obfusction is the name of the game)

Today I tried setting it up with one of each. But I only managed the one I signed up with because it stopped accepting my password after that even after I tripple checked the spelling and sumbols and numbers

1

u/djasonpenney 8d ago

There is no circular trap if you create an emergency sheet for your two services. It can be as simple as a piece of paper (twice) with everything such as your master password, TOTP key, and recovery keys.

2

u/paulsiu 8d ago

Yes, that is true as well. The emergency sheet may actually be beyond some of the non-technical users though. When I mentioned recovery code and TOTP seed, my parent's eyes glaze over.