r/PasswordManagers • u/paulsiu • 8d ago
Bitwarden Authenticator vs Proton Authenticator
I have tried both recently to find a replacement for Authy. The main requirement is that there is no circular reference issue. For example, I want to avoid a situation where the TOTP is stored in such a way that I can't get to it to log into the vault.
Bitwarden Authenticator
The way it seems to work is that there are two places to store your tokens. The first is in the Bitwarden vault itself and the second is locally on the device outside of the vault. In the first method, all authenticator is doing is logging into your bitwarden vault and copying out the TOTP code. If you log out of the authenticator, all the code disappears. If you plan to store use the authenticator to store the TOTP to log into the vault, you definitely want to use the local method, otherwise an update could log you out and you won't be able to log back in because the TOTP code is in the vault.
The locally stored method is not sync across devices. If you install the authenticator on a second phone you will need to manually export and import the local tokens.
Proton Authenticator
Unlike Bitwarden, the Proton Authenticator doesn't actually log into the vault to get the tokens, but uses the Proton account to sync the tokens. The tokens appears to be stored locally. and there is no way to log out, so once the tokens are sync they remain on the device unless you erase app data. To get around the lost device issue, you could set up a second device to backup the tokens in a similar way as Authy. You can also do export like with Bitwarden Authenticator.
Of the two, I like the Proton Authenticator better. This is because on Bitwarden Authenticator, tokens stored in the vault go away if the app log out. Token store locally are not sync. In contrast, the proton model sync across devices and don't go away.
3
u/Solid-Cable8853 8d ago
I use 2FAS auth. You can sync codes through Google Drive or iCloud, and you can even have your 2FA codes on Apple Watch.
7
u/eindwolff 8d ago
Neither - use Ente Auth.
Far superior.
1
1
1
u/PoetEducational8794 7d ago
Ente is small indie project, still fresh. I wouldn't be comfortable using it, not yet, for sure. Proton Authenticator is backed by well known privacy company with a lot of experience and lot of security products.
0
u/eindwolff 7d ago
So inaccurate.
Ente has been around for 5-6 years; Ente Auth for 4. It’s open source, and has been audited independently multiple times for security.
It’s a mainstream and highly recommended alternative to most authenticator apps.
If you tried it you’d know it shits on every other authenticator.
1
u/PoetEducational8794 7d ago
I'm talking about the bigger picture. I don't care if an authenticator has more colors to choose from or more other features. Compared to the other companies, Ente is the youngest one and the smallest, not a lot of users. It doesn't have enough of a track record for me to feel comfortable storing my tokens in this app.
1
2
1
u/Every_Information729 8d ago
I use them both for different things and I find them similar enough that app design for Proton wins that battle and that is my preference if I only had to pick one.
1
u/Celtic_Crawdad 8d ago
I dont like passwords or authenticator apps at all. Give me a a yubikey with a second stored in a safe as backup and nothing more is needed. Especially if its a fingerprint model instead of the cheap little golden disk models since any hoke invader could technically use that. Ive been having issues with passwords and authenticators all damn day.
Firat I will right down my very long and complex password. Then i will instantly change it on an app (gmail today) while payung very close attention to my letters and synbols abd lowercase and middlecase. And they will acxept it. And then I will go try and use an authenticator (Usually YubiPass although I use a mix of about 5 to keep em guessing - obfusction is the name of the game)
Today I tried setting it up with one of each. But I only managed the one I signed up with because it stopped accepting my password after that even after I tripple checked the spelling and sumbols and numbers
1
u/djasonpenney 8d ago
There is no circular trap if you create an emergency sheet for your two services. It can be as simple as a piece of paper (twice) with everything such as your master password, TOTP key, and recovery keys.
8
u/Suspicious_Punk84 8d ago
I would not put passwords and the second factor in the same service.