all 12 comments

sorted by: hot top controversial new old
[–] 15 points 2 years ago (2 children)

Starting in February, Bitwarden will bolster user account security for those users who are not utilizing two-step login (2FA) for their Bitwarden account. When logging in from an unrecognized device, users will be asked for an emailed verification code to confirm the login attempt and better protect their Bitwarden vaults…

  • source
  • hideshow 2 child comments
  • [–] 5 points 2 years ago (3 children)

    Please make sure we can turn this off. I use my bitwarden a lot and the last thing I want is to have to switch to a third app just to retrieve my password. I want simplification not complication.

  • source
  • hideshow 3 child comments
  • [–] 7 points 2 years ago

    I'm with you- if I'm accessing my vault from an unknown device, it's usually because I don't have my phone. So now I need to log in to my email on an unknown device, as well as my vault...

  • source
  • parent
  • [–] 2 points 2 years ago (4 children)

    If this is something implemented in-client, we should be able simply to block updates. Failing that… well, a spreadsheet and notepad worked well enough before.

  • source
  • hideshow 4 child comments
  • [–] 1 point 2 years ago (3 children)

    Bitwarden will let people opt out

  • source
  • parent
  • hideshow 3 child comments
  • [–] 1 point 2 years ago (2 children)

    Will they? I can’t find any mention of it

  • source
  • parent
  • hideshow 2 child comments
  • [–] 2 points 2 years ago (1 child)

    What it says on the FAQ: If users do not want new device verification, do not want to set up an alternate two-step login method, and do not want any security on their account, there will be an option to turn off new device verification in the Danger Zone settings when the feature goes live. However, we must emphasize that this is strongly not recommended, as it leaves your account vulnerable to various attacks.

  • source
  • parent
  • hideshow 1 child comment