I could see this being one of those no-brainer decisions that requires herculean effort to push through all the product politics.
I would love to hear how this change came about and what hurdles needed overcoming from someone in the know.
I could see this being one of those no-brainer decisions that requires herculean effort to push through all the product politics.
I would love to hear how this change came about and what hurdles needed overcoming from someone in the know.
One of the main reasons to use bitwarden is as a synchronized backup when the system autofill fails, which tends to happen in the same situations this 2fa check will trigger (new devices).
It adds a potential failure mode without meaningfully benefitting my personal security model.
The password to my 2FA app is also in bitwarden. It's actually much more aggressive about session expiry.
That, and I feel like password-filling on Android is awful. Plus, it pops up in DuoLingo when it isn't wanted, and they're silent on the issue.
Seems like it's just time to find some other password manager.
This is not a good change for me. This annoys me. I will not be using or considering Bitwarden going forward.
Or wait, I got an even better one; We will go to the house of each person on the planet and destroy their computer--there's you absolute security right there. No BrAiNeR.
I wonder what the product and stakeholders discussed. Were there metrics on how many users they might lose with this?