4. 2FA and Biometrics
Now, your Vaultwarden is only as safe as the difficulty of your master password. If you choose an easy password to enter your Vaultwarden account then it is still extremely vulnerable for attacks and getting access to all your credentials. Don't fall for this trap even if it might seem convenient since you cannot remember a randomly generated password.
2FA with Bitwarden Phone App
There are however alternatives, which are secure, such as 2FA by using the Bitwarden app on your phone. Create a random password of let's say 20 characters and write it down on a piece of paper.
Download the Bitwarden app to your phone
Open the Bitwarden app and make sure that you select your Vaultwarder server instance.
To do this click on logging in or: bitwarden.com
Then
select self hosted
Provide the Vaultwarden server URL and hit save
Then go to Settings > Account security
Then select Unlock with Biometrics
Sweet! now you can always unlock your Bitwarden app on your phone by using your fingerprint.
Now, we
would like that you can use this feature as well for logging in on your laptops inside a Web browser.
Well, there is an automatic feature in the Bitwarden add on that allows you to Log Out on a browser restart. Unfortunately the Biometrics log in does not work with being locked only. But this is not a big deal for now
To do this go to Settings > Account Security > and choose the time out action to be Log Out
Now, when you log out there will
be a pop up window for you to allow
to open your web browser account with "Login with device"
Select this and move over to your phone
On your Bitwarden app login with you biometrics
Go to Settings > Account Security > Pening Login Requests > Then select your device and approve the device
Perfect! Now you are logged in with 2FA and you can keep logging in easily with a complicated password.