Currently I use Bitwarden for storing passwords and Aegis for 2fa. Is is okay to store recovery codes in my Bitwarden vault or I should store them in somewhere else like Tresorit, Dropbox with cryptomator.
Currently I use Bitwarden for storing passwords and Aegis for 2fa. Is is okay to store recovery codes in my Bitwarden vault or I should store them in somewhere else like Tresorit, Dropbox with cryptomator.
There are a few options, all with trade offs.
Some combination of these can work very well, just need to decide what your attack surface looks like.
I lost my home to a fire a couple of years back, would’t recommend only paper copies of 2FA codes. Recovery was a lengthy process.
If someone does go this route I suggest following the 3,2,1 rule. The offsite copy specifically would protect from fires and pretty much anything else that can happen to your house. The same should be said if you use a paper emergency sheet. A good offsite place can be like a safety deposit box or a trustee’s bolted down safe