This is pretty far from a no-brainer to me. The FAQ even has the reason why: "what if I store my email password in bitwarden?"
One of the main reasons to use bitwarden is as a synchronized backup when the system autofill fails, which tends to happen in the same situations this 2fa check will trigger (new devices).
It adds a potential failure mode without meaningfully benefitting my personal security model.
I agree, totally no brainer. Security through making things so annoying that even the guy that is supposed to login, just doesn't any longer. In fact I agree so much with you, we should go even farther. I propose a service where you have to sprinkle some drops of blood in you keyboard every 5 minutes. If you fail to do so, all your accounts will be permanently deleted.
Or wait, I got an even better one; We will go to the house of each person on the planet and destroy their computer--there's you absolute security right there. No BrAiNeR.
Yeah it's interesting because on the one hand you're adding one more step to login. You're adding friction. On the other hand, it's pretty obviously a good security practice.
I wonder what the product and stakeholders discussed. Were there metrics on how many users they might lose with this?
I could see this being one of those no-brainer decisions that requires herculean effort to push through all the product politics.
I would love to hear how this change came about and what hurdles needed overcoming from someone in the know.