Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I didn’t realize it was not required. This is a good change.

I could see this being one of those no-brainer decisions that requires herculean effort to push through all the product politics.

I would love to hear how this change came about and what hurdles needed overcoming from someone in the know.



This is pretty far from a no-brainer to me. The FAQ even has the reason why: "what if I store my email password in bitwarden?"

One of the main reasons to use bitwarden is as a synchronized backup when the system autofill fails, which tends to happen in the same situations this 2fa check will trigger (new devices).

It adds a potential failure mode without meaningfully benefitting my personal security model.


I like how they're like "Oh just use a 2FA app"

The password to my 2FA app is also in bitwarden. It's actually much more aggressive about session expiry.


Also my 2FA app _is_ BitWarden...


This is why I'm seriously considering changing.

That, and I feel like password-filling on Android is awful. Plus, it pops up in DuoLingo when it isn't wanted, and they're silent on the issue.

Seems like it's just time to find some other password manager.


I hate the cumbersomeness of 2FA and am prepared to and take full responsibility for the consequences of not using it.

This is not a good change for me. This annoys me. I will not be using or considering Bitwarden going forward.


I agree, totally no brainer. Security through making things so annoying that even the guy that is supposed to login, just doesn't any longer. In fact I agree so much with you, we should go even farther. I propose a service where you have to sprinkle some drops of blood in you keyboard every 5 minutes. If you fail to do so, all your accounts will be permanently deleted.

Or wait, I got an even better one; We will go to the house of each person on the planet and destroy their computer--there's you absolute security right there. No BrAiNeR.


Yeah it's interesting because on the one hand you're adding one more step to login. You're adding friction. On the other hand, it's pretty obviously a good security practice.

I wonder what the product and stakeholders discussed. Were there metrics on how many users they might lose with this?


this is not a good change.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: