Enabling 2fa on bitwarden.com overwrites vaultwarden 2fa key #1513

Closed
opened 2026-04-06 01:58:58 +02:00 by MrUnknownDE · 0 comments
Owner

Originally created by @freekvh on 8/2/2023

Subject of the issue

Enabling 2fa on bitwarden.com overwrites vaultwarden 2fa key in MS authenticator

Deployment environment

  • vaultwarden version:
  • Install method:

  • Clients used:

  • Reverse proxy and version:

  • MySQL/MariaDB or PostgreSQL version:

  • Other relevant details:

Steps to reproduce

I went to bitwarden.com where I have the same account as in vaultwarden, I enabled 2fa and used MS authenticator to import the key via QR code. There was a warning that it would overwrite or update a key? I didn't think much of it because I may have experimented with bitwarden in the past. But afterwards I found that my vaultwarden key was gone.

Expected behaviour

Making a new TOTP for bitwarden.com leaves my vaultwarden TOTP untouched

Actual behaviour

Bitwarden.com key overwrites vaultwarden TOTP key.

Troubleshooting data

I thought 2fa was at least domain dependent, but apparently some things are exactly the same between vaultwarden and bitwarden.com. Maybe this is obvious to some, but it isn't to me.

*Originally created by @freekvh on 8/2/2023* <!-- # ### NOTE: Please update to the latest version of vaultwarden before reporting an issue! This saves you and us a lot of time and troubleshooting. See: * https://github.com/dani-garcia/vaultwarden/issues/1180 * https://github.com/dani-garcia/vaultwarden/wiki/Updating-the-vaultwarden-image # ### --> <!-- Please fill out the following template to make solving your problem easier and faster for us. This is only a guideline. If you think that parts are unnecessary for your issue, feel free to remove them. Remember to hide/redact personal or confidential information, such as passwords, IP addresses, and DNS names as appropriate. --> ### Subject of the issue Enabling 2fa on bitwarden.com overwrites vaultwarden 2fa key in MS authenticator ### Deployment environment <!-- ========================================================================================= Preferably, use the `Generate Support String` button on the admin page's Diagnostics tab. That will auto-generate most of the info requested in this section. ========================================================================================= --> <!-- The version number, obtained from the logs (at startup) or the admin diagnostics page --> <!-- This is NOT the version number shown on the web vault, which is versioned separately from vaultwarden --> <!-- Remember to check if your issue exists on the latest version first! --> * vaultwarden version: <!-- How the server was installed: Docker image, OS package, built from source, etc. --> * Install method: * Clients used: <!-- web vault, desktop, Android, iOS, etc. (if applicable) --> * Reverse proxy and version: <!-- if applicable --> * MySQL/MariaDB or PostgreSQL version: <!-- if applicable --> * Other relevant details: ### Steps to reproduce I went to bitwarden.com where I have the same account as in vaultwarden, I enabled 2fa and used MS authenticator to import the key via QR code. There was a warning that it would overwrite or update a key? I didn't think much of it because I may have experimented with bitwarden in the past. But afterwards I found that my vaultwarden key was gone. ### Expected behaviour Making a new TOTP for bitwarden.com leaves my vaultwarden TOTP untouched ### Actual behaviour Bitwarden.com key overwrites vaultwarden TOTP key. ### Troubleshooting data I thought 2fa was at least domain dependent, but apparently some things are exactly the same between vaultwarden and bitwarden.com. Maybe this is obvious to some, but it isn't to me.
Sign in to join this conversation.
No Label
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github/vaultwarden#1513