12 ms·
Bitwarden is turning 2FA on by default for new devices
- wiether 2y agoI'm taking this opportunity to Ask HN: what do you think of the new Bitwarden browser extension? Sure it looks more modern and a few things are better. But personaly I HATE the new "copy" button. With the old version there was a button for each field : one to copy the login, one to copy the password, one to copy the TOTP. Now there's just a single button that will display a list of options to choose from depending on what you want to copy. So instead of copying a field with one click, now I need to do one click, go on the right option, and another click. Even worse: if the account contains only one field, the copy button will still display the list of options, with just one option. How could nobody think that when the user want to copy something from a list, and this list contains only one item, the right thing to do is to copy this single thing, not ask them what they want to copy...
- Modified3019 2y agoLooks like some of these changes can be reverted: https://bitwarden.com/blog/bringing-intuitive-workflows-and-visual-updates-to-the-bitwarden-browser/#tips-for-long-time-bitwarden-users https://bitwarden.com/blog/bringing-intuitive-workflows-and-...
- wiether 2y agoThanks! I hate the title "Tips for long-time Bitwarden users" like they are seeing us as dumb but whatever. If I can get my quick buttons back, I'm glad!
- portaouflop 2y agoIdk to me the title is as neutral as it can get - how else could they word it to not offend you?
- egberts1 2y ago"We screwed the powerusers; here's how to get it back while we fix it ... back."
- 542354234235 2y agoThings change. They made sure people could go back to any legacy behavior they personally favored, or not. "Please constantly be trying to improve your product, so change the things I don't like, but don't change anything I do like, even if I still have the option to pick and choose between legacy and updated options". Man, people will bend over backwards to be offended.
- godelski 2y ago> Change the default behavior of clicking a vault item Thank fucking god... I keep opening my files when I'm really just trying to autofill because autofill doesn't work a lot of times.
- bryankaplan 2y agoBut folders are now stuffed into a small dropdown, leaving All Items as an unorganized mess. That change alone is pushing me to switch password managers.
- ajb 2y agoNice one! Have been annoyed at the new tiny 'fill' button.
- AdmiralAsshat 2y agoGo to Settings -> Appearance -> "Show quick copy actions on Vault"
- CurleighBraces 2y agoThank you!!!!!!
- _benj 2y agoThank you!! I also hated the new copy icon!!
- wiether 2y agoThanks! It looks like an afterthought from them because the label is the only one not translated on the extension. Anyway, I'm more than happy to have the quick actions back!
- Fluorescence 2y agoThanks! Also nice to see a width setting and remove animations which improves my experience. Funny how I didn't even think to look for appearance settings.
- Someone1234 2y agoYep. If you look at the feedback thread before this version was released, they legitimately did listen to feedback from power users and made changes. The first beta version had all of these annoying quirks, but then they added a bunch of settings (Compact Mode, Quick Copy Actions, Wide Mode, Disable Animations) that after you change them gives you a solid experience.
- medwards666 2y agoHave to say ... I'm still not a great fan of the new UI, but the QoL settings under the appearance tab do at least make it bearable.
- davrosthedalek 2y ago
- deleted 2y ago[deleted]
- Cieric 2y agoMy personal problem is that I self host and the updated extension just completely fails to connect to my vaultwarden instance. I probably just need to repull the updated docker container, but it's something I would have rather not thought about. But since the extension auto updated I'm forced to think about it.
- erdii 2y agoBe careful about using newer clients with an outdated version of the vaultwarden server. I lost a couple days of new accounts/passwords because this[1] probably happened. [1] https://github.com/dani-garcia/vaultwarden/discussions/4921 https://github.com/dani-garcia/vaultwarden/discussions/4921
- horsawlarway 2y agoInteresting - I'm also running self-hosted and didn't have this problem (I think my last image pull was about a month ago, though - so somewhat recent). If you want, I believe you can override the update url in chrome to stop the auto-update process in the future: https://chromeenterprise.google/policies/?policy=ExtensionSettings https://chromeenterprise.google/policies/?policy=ExtensionSe... Alternatively, at least for chromium browsers - you can download the .crx directly, unzip it (p7zip will do it), and sideload it using the "Developer mode" checkbox on chrome://extensions. Firefox sadly doesn't support this - they'll remove any sideloaded extensions on browser close.
- Macha 2y agoYeah, the problem is with clients from January or newer, and vaultwarden versions from before October. It did lead me to discover my automatic update process wasn't actually rebooting the vaultwarden server.
- infogulch 2y agoYou can enable the new extension UI when you're using vaultwarden by setting the EXPERIMENTAL_CLIENT_FEATURE_FLAGS=extension-refresh env var. I wrote more about it here: https://forum.cloudron.io/topic/13001/bitwarden-extension-ui-refresh https://forum.cloudron.io/topic/13001/bitwarden-extension-ui...
- packetlost 2y agoI didn't like it at first, but once I built up the muscle memory I like it a lot more.
- Someone1234 2y agoI love the fact it remembers what page you were on and leaves it on that page. In the previous version, you'd go Vault -> Search -> [Find Thing] -> Copy Username, but when you de-focused the extension it would return you to the vault home, so yet again you had to do Vault -> Search -> [Find Thing] -> Copy Password. This one, when it loses focus, it stays exactly where you left it.
- horsawlarway 2y agoI want to second this. I don't mind the general visual update. But the change to the copy buttons was a step backwards. To the bitwarden folks... if I'm opening up the extension 99% of the time it's one of these use cases: 1. I'm creating a login for a new site 2. I'm on a site that doesn't support autofill, and I'm manually copying user/pass/code 3. I'm filling credit card info, and want to select a specific card Both #2 and #3 got worse with this change. Put the damn copy buttons in the huge amount of whitespace you have for the entry. Don't hide them in an overflow. Put each of the user/pass/2fa buttons in a fixed space, and don't move them.
- infogulch 2y agoDid you look at the Appearance extension settings? They solve this problem for most people. (See elsewhere itt for details.)
- MrZander 2y agoTo throw in a second viewpoint: 99% of the time I open the extension, it is to trigger auto-fill. I don't like having my credentials auto-fill on page load, I like to be the one to trigger it. That being said, I also hated the change that hid the copy buttons, but they have a setting that brings them back.
- buggy6257 2y agoYou may know this, but they introduced a feautre that lets you use Cmd/Ctrl+Shift+L in order to trigger auto-fill. I have disabled autofill on pageload but LOVE this shortcut key.
- frameset 2y agoI'm the same as you in how I use Bitwarden. I'd also like to add that if you keep repeating that shortcut it will cycle through the different logins you have for the current site.
- 2y ago
- latchkey 2y agoFor me, it is the double scroll bars in the browser extension. One to scroll in the list of passwords and another to get to the bottom of the extension window. This is even in "compact" mode.
- panzi 2y agoInteresting, I don't have that, only one scroll bar. I use on Firefox. Do you force some different font or font size on all websites perhaps?
- doright 2y agoI like how it's faster than before but the modern UI design trends are starting to wear on me. If you could have the old theme with the new features that would be good. The two-click copy button is absolutely the worst new "feature" they added. That setting should be opt-in by default.
- deleted 2y ago[deleted]
- yoavm 2y agoYou probably know this, but I'm just writing it here because it took me a while to figure it out — you can also use the keybinding (Ctrl+Shift+L) to fill in login forms. It works 90% of time, and you don't need to copy anything. It really reduced the number of times I'm interacting with the extension's panel.
- portaouflop 2y agoIt took me a day to get used to the new UI but now I love it - just goes to show that you’ll can only get UX wrong/UX is hard. It’s good to have both options configurable though!
- csomar 2y agoIt’s horrible. They also updated the iOS app and it’s buggy.
- infogulch 2y agoI like it! With the width and quick copy options under appearance settings there are no glaring issues, but there are two big benefits: 1. It's much faster. This alone makes the refresh worth it imo. 2. The edit item / fill item UX is much more consistent than it was. Before, when you search for and click a card it opens the item, but if you click a card because it matches the current domain then it fills the item, to open it instead you have to click the little "open item" button. Even as a long time user I would often misclick because the context changes the behavior of clicking a card and my muscle memory would be the opposite of what I wanted. Now there's a "Fill" button when a card matches the current domain and clicking anywhere else always opens the item. My only critique is that the Fill button could be a bit bigger to so it's easier to click.
- sunaookami 2y agoIt's awful, it's slow, it's hard to use, confusing and they made editing even worse. The old UI also had it's problems but they weren't this bad. I despise these constant UI changes that only make the product worse without any benefits.
- BozeWolf 2y agoIf you insert the password using bitwarden browser extension, then the totp token is under cmd-v. Even better. At least on safari.
- aceazzameen 2y agoIn full agreement the multiple clicks have been annoying. The old UX with multiple contextual buttons was better.
- brightball 2y agoThey are defaults. You can change it under the appearance menu.
- HaZeust 2y agoI hate how small the "Fill" button is, and how clicking on a card that represents saved credentials is no longer assumed as an intent to fill username/password on the page you're on.
- giancarlostoro 2y agoIn some cases, it just falls apart when displaying over a text box and doesn't know what to do with itself, and sometimes breaks the UI for me. I keep the desktop copy around for the cases where I don't want to fiddle with the extension.
- MrZander 2y agoI also hated this change, but there is a setting: Settings -> Autofill -> Click items to autofill in Vault view
- bubblethink 2y agoThe new extension is a lagfest. There's a noticeable 2s latency to every action now. I don't know how something like this makes it to GA. Long ticket: https://github.com/bitwarden/clients/issues/12286 https://github.com/bitwarden/clients/issues/12286
- boneitis 2y agoseems there are reports of different sorts of delays in the comments. w.r.t. a small, split-second one in initial rendering, i'd take it ten times out of ten over what it was for me all these years: immediate ability to key in input, but if you typed at the precisely (im)perfect moment, which was an extremely common occurrence, the extension would bug out and not perform the actual search. so i'm sitting there for about a whole second wasted for having waited out the threshold to realize that it bugged out yet again and didn't perform my search. then, i would have to either backspace or type in the next character in the query in order to trigger the search; this was often an unpleasant added mental overhead when backspacing would repopulate results that you were trying to filter out. i'd rather have the split-second delay for every initial render.
- mvdtnz 2y agoThe teeny tiny "Fill" button is the dumbest thing I have ever seen in a UI overhaul. A total misunderstanding of how their own product is used.
- xxkylexx 2y agoSettings < Autofill < Click items to autofill from Vault
- mvdtnz 2y agoOf course it's not under Settings -> Appearance where the similar "Show quick copy actions on vault" option is. Why should an option that only affects the UI be in "appearance".
- favorited 2y agoBecause it barely changes the appearance at all? The actual effect of that setting is to change the behavior of the button to be autofill. The only visual change is that the small "Fill" button is removed.
- mvdtnz 2y agoIt fundamentally changes the appearance of the UI, what are you talking about?
- favorited 2y agoThese are screenshots from the extension, before and after checking that autofill box. The only visual change is the missing "Fill" button, because now clicking on the item itself preforms the fill action. The rest of the UI looks exactly the same. https://imgur.com/a/ji3EAKw https://imgur.com/a/ji3EAKw
- J_Shelby_J 2y ago100% this is one of those changes that makes me doubtful of Bitwarden being a well maintained service in perpetuity. Like, if this change was an accident and slipped through that is bad. If it was approved, it's even worse because as you said, it shows that the person who is in charge of how we, the users, interact with the product day-to-day doesn't understand the product or doesn't take their role seriously.
- dml2135 2y agoNot a fan — it feels like an update just for its own sake, I struggle to think of anything that actually improved.
- coderintherye 2y agoIt's been much, much slower to load on click for me now. Surprised others haven't experienced that so wondering if it is some extension conflict. Consistently takes 2-3 seconds to load up after click whereas before was instant-ish.
- RockRobotRock 2y agoRelated question: is there any way to keep the Bitwarden window open when I’m unfocusing it without popping it out into a separate window? That workflow makes copying logins painfully slow for me.
- Yeroc 2y agoIt wouldn't be so bad if the window closed but at least remembered the entry. I often have the issue where I had to search up an entry (credit card info for example) and then when I reopen the extension window I have to start the search all over again.
- deleted 2y ago[deleted]
- blackhaj7 2y agoAgreed. I keep clicking copy and thinking it copied when all it did was open the menu
- buro9 2y agoI hated it so much I migrated to ProtonPass, deleted my data, and set my account to expire. Then Proton CEO made some statements I found offensive, so I re-activated my Bitwarden account, migrated back, and am now learning to love the changes. The best I've got for tips are: 1. Settings > Appearance > Quick Copy 2. Settings > Appearance > Compact Mode 3. Settings > Appearance > Extension Width > Wide I still don't love it, but it remains the best of the bunch.
- teekert 2y agoI searched but for the life of me can’t find what “Fash” is, and boy am I curious (as somewhat of a Proton fanboi).
- zoul 2y agofascist
- Xiol32 2y agoFascist. I'm very surprised a search didn't turn this up for you, or you're not asking in good faith.
- deleted 2y ago[deleted]
- teekert 2y agoI use ddg with country set to Netherlands, fash turns up many things, fascist is not among them.
- dude187 2y agoBut he's a Republican. Why would a Google search for "fash" clear that up?
- teekert 2y agoI just ddged for “fash”, I mean labeling the CEO of Proton no less, an org that does so much good, that has such a nice vision, can shield people from their state because they believe in their right to privacy. To label such a person a fascist is just unimaginable to me. I find it shocking that so many people just use this super small thing to judge Andy Yen. I’m really shocked. How dare these people put such opinions online? It’s so “140 chars” to define a person. It’s what’s wrong with the internet these days.
- deleted 2y ago[deleted]
- t0bia_s 2y agoIm not a fan of copy button and design as well. Dark mode has huge contrast with outlines and rounded corners are space inefficient. It's like design for small touch screen, not a desktop addon to browser. Take inspiration at uBlock.
- INTPenis 2y agoI just started using it and my co-workers who have been using the old one say it sucks but I honestly have no opinion. It seems to do the job to me.
- pknomad 2y agoI don't personally like it but I suspect much of it had to do with me getting used to just clicking once and having to unlearn the habit.
- wruza 2y agoThe new desktop browser plugin is disgusting even after I went through settings. Won’t reiterate here, one of the worst UIs I’ve ever seen and if I were to choose today, I would not choose bitwarden only because how ugly and unusable it is. Bitwarden, return the normal UI back!
- gunalx 2y agoSame, new copy button just takes more time than previously. actually pretty anoying.
- moogly 2y agoEvery single change is for the worse. It's kind of insane how they managed to do that, actually.
- adamtulinius 2y agoHate it (using the Firefox one). The look is weird, seems to waste space. New copy button sucks. I spent 10 minutes one day not being able to login with a copied password, bit realising it was because I was lacking the second click. Also the new suggested results (when searching) honestly just gets in the way, since the order of the results are not always the same anymore.
- renewiltord 2y agoThis extension is the only thing on my computer that is slow. I have an M1 Pro and an M1 Max laptop and the new visual refresh has made the extension very slow and a lot less usable. The old one was instant on clicking the shield icon. The new one is slow and flashes a few times before showing me the UI. Also, the entire field used to be selectable to fill fields. Now I have to aim at the tiny Fill icon and it's even harder to get to the time-based 2FA code. I get why they've done it but I have never seen any software this slow in my life. Even just displaying the boxes seems like it needs a progress bar.
- serial_dev 2y agoIt's bad, it is no longer capable of filling out password fields, I need to copy it manually and then paste it.
- Wowfunhappy 2y agoYes, this is my issue too! The new UI is bad, but the bigger issue is it's just much worse at autofill!
- albybisy 2y agoalso 2FA with passkey into bitwarden website don't work with the extension. It can't find the passkey.
- nikanj 2y agoModern design: looks cleaner, is harder to use (more clicks)
- deleted 2y ago[deleted]
- crossroadsguy 2y agoThe day Bitwarden was VCed I knew there will be a time when I will be desperate to find alternatives. I guess that time is coming closer. The thing I despise most among their UI “improvements” is entry click expands the entry now. To fill you have to find that tiny “fill” button and click that.
- move-on-by 2y agoI didn’t realize it was not required. This is a good change. I could see this being one of those no-brainer decisions that requires herculean effort to push through all the product politics. I would love to hear how this change came about and what hurdles needed overcoming from someone in the know.
- Longhanks 2y agoI hate the cumbersomeness of 2FA and am prepared to and take full responsibility for the consequences of not using it. This is not a good change for me. This annoys me. I will not be using or considering Bitwarden going forward.
- AlotOfReading 2y agoThis is pretty far from a no-brainer to me. The FAQ even has the reason why: "what if I store my email password in bitwarden?" One of the main reasons to use bitwarden is as a synchronized backup when the system autofill fails, which tends to happen in the same situations this 2fa check will trigger (new devices). It adds a potential failure mode without meaningfully benefitting my personal security model.
- Macha 2y agoI like how they're like "Oh just use a 2FA app" The password to my 2FA app is also in bitwarden. It's actually much more aggressive about session expiry.
- unavoidable 2y agoAlso my 2FA app _is_ BitWarden...
- wccrawford 2y agoThis is why I'm seriously considering changing. That, and I feel like password-filling on Android is awful. Plus, it pops up in DuoLingo when it isn't wanted, and they're silent on the issue. Seems like it's just time to find some other password manager.
- foxygen 2y agoThis is terrible, honestly. One of the reasons I use Bitwarden is to be able to not know all my passwords besides the Bitwarden one. I don't know my email password, so can't use that for 2FA. Same for using my phone number or an authenticator app, if I lose my phone, I would also be locked out of my account. The risk of someone stealing my phone is much higher than someone stealing my main password where I live. I intentionally decided not to use 2FA, because that is what makes most sense for my context. I'm ready to take full responsibility for not using 2FA, but now I can't.
- nelblu 2y agoI hear you, and I somewhat feel the same. However, a workaround would be to save the TOTP secret safely like a password. I have started treating all my TOTP secrets as my secondary passwords.
- om8 2y agoBitwarden is the place where I store stuff safely ><. This update is just awful
- sesky 2y agoAgreed. There is no way to rely on the simple model of 'my master password is the single point of failure' now. With any form of 2FA, there is now lockout risk in a way that cannot be mitigated fully. Bitwarden itself recommends printing out a recovery code and storing it in a safe, but what happens if you lose access to that safe? Or if you're traveling and need emergency access to your accounts after your phone gets stolen? On the reddit post announcing this, Bitwarden added a response saying they will provide an opt-out option. It's unclear if this opt-out is temporary or not. It would be a huge step back for their product if 2FA becomes mandatory.
- foxygen 2y agoThat actually happened to me a couple years ago. I was in a foreign country, and lost my phone. All I had to do was buy a new cheap phone and login to Bitwarden again. If I had 2FA enabled, I'd be completely screwed.
- anlsh 2y agoIf anyone works at bitwarden can you get your UI people to stop retheming for the upteenth time and instead make the "detailed view" of any entry read-only by default? Every time I need to access my notes on an entry I'm scared that I'll accidentally typo a letter into my password or a 2fa code or something
- stronglikedan 2y agostrange, since mine is read only be default. I always have to click the edit button on the detail view to make any modifications.
- lousken 2y agostill didn't implement showing credential information when searching so that you don't end up with 10 credentials with the same name across folders? shame
- deleted 2y ago[deleted]
- jampekka 2y agoIf you want to be truly secure, use a Bitwarden random password for your email and wipe your device!
- jaden 2y agoI get the desire to make the Bitwarden login more secure, but this is very likely to cause problems for users who don't have their email password memorized. 2FA already carries the burden of needing a backup if you lose your phone. This change means users will need to come up with an alternate way to log in to their email account. I'm not sure it's worth it.
- Canada 2y agoReminder: Dump your password manager database into cleartext backups regularly. Store them on encrypted media (eg. USB stick with FileVault, VeraCrypt, or similar) Then you will not be totally screwed if your password manager does a rug pull against you such what Bitwarden is doing with this change.
- mplewis 2y agoHow is this new policy a rug pull?
- Canada 2y agoIt's a password manager. It must never, under any circumstances, add any additional barriers to getting in that aren't explicitly configured by the user. This is going to lock out many users. They will not realize this new arbitrary requirement to be able to access the email address. They will lose their existing device. They will get a new device, install Bitwarden, and try to login with their master password, only to find that Bitwarden has moved the goal posts. They will be locked out of everything. Even if 99.99999% of users would benefit from this change, Bitwarden shouldn't do it because it'll unfairly lock out 0.00001%. If they really want to do this change, then they should have like 2 years of warnings displayed on existing clients, and also have an option to permanently disable any 2FA requirement.
- stronglikedan 2y agoAnd the "mandatory" part will probably lose them at least one customer (me).
- xxkylexx 2y agoIt's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
- jmholla 2y agoYea. This article needs to be updated if that is the case. There isn't even a hint that this is possible. And there are very valid reasons to not turn it on as these comments have shown.
- codemac 2y agoinstructions on how? I need to walk through family members to do this.
- jillesvangurp 2y agoSame here. I have a 77 year old father who has had a stroke who is not going to be able to wrap his head around the notion of 2FA. It's a bridge too far. Not going to happen. He's just going to get confused and give up when faced with crap he doesn't understand (that's literally how it works with him). I've seem him break into tears because he couldn't figure out some mobile phone UX. Kind of heartbreaking to watch that happen. That's what strokes do to people. Stuff like this doesn't help people like that. I'm thinking the built in browser password manager might be a safer, more usable option for him at this point. It's probably what I'll have to recommend when this inevitably blows up in a few months. 2FA is a hurdle for normal users. I've had to support 2FA for our Google workspace account for some of my non technical colleagues. It's a PITA almost 100% of them needed me to unblock their account at some point. Absolutely terrible UX. Most users aren't compatible with this stuff. That's why all the big companies are pushing for passkeys now. I don't think that actually fixes the problem and just moves it instead. But I get it. Bitwarden wants to appeal to corporate IT managers so they can sell expensive enterprise licenses because IT managers are most of their paying customers. And for that they need to sacrifice UX. Because IT managers like liability even less than service providers (like Bitwarden). They'll make their users jump through hoops one hundred percent of the time if it reduces their exposure to their mistakes. So sacrificing UX for that is a small sacrifice. But it is a sacrifice that buys ass coverage for Bitwarden and IT managers. At the cost of users.
- Cortex5936 2y agoAny good alternatives that do not require 2FA ?
- foxygen 2y agoI'll be moving to Proton Pass.
- gck1 2y agoProton pass is a terrible choice because of Proton's inactivity policy - I expect my passwords to still be there if I'm incapacitated for one reason or another for a year (jail, coma, whatever).
- keybits 2y agoI use and like Enpass: https://www.enpass.io/ https://www.enpass.io/
- godelski 2y agoI like bitwarden, but there are a lot of weird things that make me want to move or find a self-hosted solution. This feature may actually cause me to leave. I actually ended up buying a subscription and then refunding it in less than an hour. So what's going to happen? Are they going to cache my location? Or are they storing a cookie on my side? Neither sounds great. Ever hear of a VPN? That's going to make my life easier.... Some more general complaints: The storage thing is really weird. Did you know it is just stored on their server? So you can't store locally. But the worst part, when you want to retrieve the item then you download it and it just appears in your download folder. This is TERRIBLE and both of these make it absolutely useless. I got to download it when I need it, hope I have internet in that situation, and then delete it after because I'm... storing sensitive information, right? The new design is just terrible and could only be designed by someone who assumes you never open the panel to fill in the website. Yet... that's the *most common* reason I open that. Things like this give me concern that those designing the tool aren't thinking about other things. When it comes to security, all the little things matter a lot. Of course there's frustrating things that I know they have little to no control over, like all the dumb Microsoft logins I'm forced to have and then annotate because I keep logging into the wrong account. But I do like that it integrates with Firefox's relay. The only thing I wish is that it wouldn't name the mask "Generated by Bitwarden." but "the fucking website name" (sure, append "Generated by Bitwarden" but no one cares and this does nothing to help brand recognition, it just makes things confusing).
- zikduruqe 2y ago> that make me want to move or find a self-hosted solution. passwordstore.org and "git init --bare password-store.git" somewhere on your own network.
- slightwinder 2y ago> I like bitwarden, but there are a lot of weird things that make me want to move or find a self-hosted solution. You can selfhost Bitwarden. There is also an alternative server named vaultwarden.
- coldpie 2y ago
- ss64 2y agoThis is why I like generating passwords with a 1 way SHA-256 hash, no need for any storage or encryption and no reliance on some website service being up.
- eterm 2y agoAnd no way to change your password when it's compromised?
- lxgr 2y agoAnd no way at all to protect yourself against any site you use this scheme on to brute-force your master password without you even being aware of it.
- Too 2y agoNow add one special character, mix upper and lower case, max 32 characters. This wouldn’t work on even 1% of all websites out there.
- gpi 2y agoWhy is this news? 2FA is quite basic is it not?
- tredre3 2y agoThe news is that it is now mandatory.
- xxkylexx 2y agoIt's not mandatory, it's a default. I asked the help docs team to update the FAQ to include that there is an opt-out option under account settings.
- self_awareness 2y agoWhere's the option? I don't see it.
- TheFreim 2y agoThe documentation now says "Users who opt-out from their account settings, to which an option will be added, are excluded" so it appears that there isn't an option yet but that they will add it later.
- tonymet 2y agoI encourage everyone to update your email address (user login) by adding some novel characters to your email like youremail+bw1234@gmail.com because there are active attacks against Bitwarden right now. Thankfully Bitwarden warned me about the attempts. For the rest of the customers it's a matter of time before you are a target.
- Lammy 2y agoThis one is not too bad since it's only once per device, assuming they define a device by generating some unique value at first login so I really won't have to go through it again despite any updates, changes in network, etc. In general though I have become incredibly sick of mandatory 2FA for every-goddamn-thing. I do use it very often, but it should be my choice and not forced on me. The usual retort is blah blah blah I might understand the trade-offs but normies don't and so forcing it is a net positive, but I'm me — not them, so that usual response is just to tell me that my feelings don't matter.
- lxgr 2y ago> but it should be my choice and not forced on me Since service providers are often legally and even more often practically required to cover losses resulting from account takeovers, it's really not your choice alone.
- AutistiCoder 2y agoSMS-based two-way login would be a better way to do 2FA. Think of it from the user perspective - now they have to download and use yet another app on their cellphone just to log in. Yes, I am aware of SMS's vulnerabilities - but the weakest link is always the user.
- qzx_pierri 2y ago>Yes, I am aware of SMS's vulnerabilities - but the weakest link is always the user Or the phone provider's call center employee who gets tricked into helping a bad actor perform a sim swap. I pray you're never in charge of my data.
- Enginerrrd 2y agoThey'd still have to have your vault password.
- alkh 2y agoToday, I almost had a heart attack cause I couldn't log in into BW Web. Strangely, both mobile and Desktop versions worked fine with the same password... The issue resolved automatically in a few hours, still no idea what this was. Still, I backed up my passwords as soon as I logged into the mobile app, so like some people here say I highly recommend everyone do periodic backups and not be like me (:. I would have lost everything if something did happen to my vault access
- TheFreim 2y agoI can understand adding some friction to discourage using Bitwarden without 2FA, but requiring it seems very wrongheaded to make it mandatory. I've been using 2FA on Bitwarden for a while and it adds a lot of friction and made me very nervous that if I lost my phone that I'd be locked out of literally every account I have. I mentioned elsewhere (link below) that I have solved this issue for myself, but people shouldn't be required to jump through these hoops and introduce a greater opportunity to lose access to their accounts if they should lose their phone. https://news.ycombinator.com/item?id=42853696 https://news.ycombinator.com/item?id=42853696
- mplewis 2y agoYou don't need your phone. You need access to your email account. This is described in the article.
- TheFreim 2y agoLike numerous others, my email account password and 2FA codes are in Bitwarden.
- notesinthefield 2y agoI dont understand why people do this - those “bedrock” accounts like bank accounts shouldnt be in your password manager in my opinion. At the very least split your providers - no one manager has all my passwords and 2FA codes.
- Wowfunhappy 2y agoBecause for security (!), I use a very strong and difficult to memorize password, with no backstop if I forget it. I only want to memorize one of those.
- bgnn 2y agowhy is this safer than requiring 2 master passwords. at the end an email account is accessible via a password.
- redmajor12 2y agoFor someone who has only used offline, local password vaults, what is the advantage of a cloud-based solution (for personal use, not enterprise)? I'm interested in their self hosted option, but not sure what the advantages would be over keepass and syncthing.
- starkparker 2y agoConvenience and portability for people who don't want to use, or aren't going to learn how to use, anything more complex than an app, browser extension, or website. Accessing a password vault from any arbitrary internet-connected device and browser through the web is also convenient, even if to you or I that serves more as a reminder of how accessible your passwords might become to unauthorized users. Sharing credentials between Bitwarden users is also more convenient. If you self-host, you can provide those service to friends or family members who don't have your technical aptitude. For teams and businesses, it provides an auditable service with directory integration and other optional enterprise features (SSO, fine-grained access). All of these are possible without a SaaS, just less convenient to set up. You and I might consider setting up our own personal password management to be a fun and useful project, or at least a trivial time expense compared to the value. When something like Bitwarden provides all of those features and more for $0 to $10/year, even a small time and maintenance burden might not seem worth it to a less technically savvy user.
- turbojet1321 2y agoThe big thing that got me to move off passwordstore to BW (and self-hosted vaultwarden) was sharing passwords with family. The app and browser extensions are nicer, too.
- bongodongobob 2y agoGreat example here of HNs ignorance of basic security in this thread. Bitches and moans about companies' data breaches. Bitwarden turns on 2FA by default to kill 99.9% of attacks (you all should be smart enough to be using this already) and y'all are crying about it. I hope the companies you work for have security teams to protect the company from your crazy attitudes.
- physicsguy 2y agoThe whole point of a password manager is that you can use it to log into things like email. I have a single password I only use for Bitwarden and nothing else. All of my other passwords are randomly generated. How am I gaining security by enabling MFA? If I lose my phone on holiday now, I’m in a position where I can’t log into anything because I won’t be able to log into my email.
- Lammy 2y agoMy passwords, my choice.
- grougnax 2y agoThis is very bad news
- fungiblecog 2y agowhile we're bitching about the bitwarden UI my pet peeve is that 99% of my accounts use my email as the username but i still have to type it in every time i create a new account. how about having auto-suggest?
- rlpb 2y agoI very carefully added 2FA to my wife’s Bitwarden account a while ago. I got her a Yubikey and added mine as well as my backup keys in case one ever got lost. I discovered much later that they call email “2FA” so her account isn’t actually protected by the hardware keys at all. Like others here, this doesn’t make sense to me since it’s circular. (and separately, the Yubikey seems to often not work on Android anyway)
- crossroadsguy 2y agoX.com is one site where 2FA just doesn’t work for me and had to repeatedly contact them to “unlock” it or so. Finally I had to disable it and if the a/c ever gets taken over I’d let it be.
- self_awareness 2y agoI'm paying for Bitwarden now, but after they enforce 2FA, I'll stop.
- dyml 2y agoWe're enabling it by default, you can opt-out.
- crossroadsguy 2y agoI thought of stopping the subscription after I reported a blocker issue in great detail with multiple emails but they didn’t tell me why it was happening, neither did they share the ticket created or a ticket was created in the first place - in fact they didn’t respond at all, not even to follow ups. UI “improvements” finally did it for me and I stopped paying — also, started taking periodic backups.
- workfromspace 2y agoYet we still don't have any tags / labels for passwords...
- deleted 2y ago[deleted]
- dyml 2y agoI just want to point out that the title is wrong. 2FA is on by default, but not mandatory. Dang, can we change the title?
- dang 2y agoOk, we've done that now. (Submitted title was "Bitwarden introduces mandatory 2FA for new devices".)
- TheFreim 2y agoThe title was correct but they appear to have changed the policy since the post was made, likely as a response to feedback. Notice that in the archive from earlier today the "Who is excluded from this account email-based new device verification?" section did not have the new fifth bullet point about being able to opt-out: https://web.archive.org/web/20250128011007/https://bitwarden.com/help/new-device-verification/ https://web.archive.org/web/20250128011007/https://bitwarden... Thought it was worth pointing this out since I've already seen people reply to old comments thinking people didn't read the article without realizing it was later changed.
- gck1 2y ago2FA on a password manager is a stupid, stupid idea and will surely lock out many people from non-tech-savy pool. Even engineers have trouble noticing or understanding circular dependencies, does Bitwarden, a password manager that tries to cater to this specific target audience really expect them to figure out they're set up to be locked out once they lose their device?