The most secure practice for any high-value accounts (email etc) is to use WebAuthn with a hardware key like a Yubikey.
TOTP is still vulnerable to phishing (a fake login page can ask for both a password and a TOTP code) so business/corporate environments are moving away from them.
so no more authy? BITWARDEN HAS THAT BUILT IN??? thats AWESOME
So does keepass
Yep, and Vaultwarden too!
Though the most secure practice is to store them separately.
The most secure practice for any high-value accounts (email etc) is to use WebAuthn with a hardware key like a Yubikey.
TOTP is still vulnerable to phishing (a fake login page can ask for both a password and a TOTP code) so business/corporate environments are moving away from them.
Yep, for only $10 per year. But just make sure to keep backups of your vault and/or make an emergency kit.