2FA Disable Button in the Admin Interface #4155
-
Hi everyone, I am currently migrating from KeepassXC to Vaultwarden because of the synchronization and other qol improvements. I noticed that there is the option to remove the 2fa of any vault/account in the admin interface. Is there a way to make 2fa non removable because that creates a security risk. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 3 replies
-
In that situation you have much more serious concerns than the attacker disabling 2FA for login :-) Also the 2FA mechanism is not involved in the encryption of your data; it's a second factor used to authenticate logins, but the vault data is encrypted using only the master password/passphrase. |
Beta Was this translation helpful? Give feedback.
In that situation you have much more serious concerns than the attacker disabling 2FA for login :-)
Also the 2FA mechanism is not involved in the encryption of your data; it's a second factor used to authenticate logins, but the vault data is encrypted using only the master password/passphrase.