Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's a password manager. It must never, under any circumstances, add any additional barriers to getting in that aren't explicitly configured by the user.

This is going to lock out many users. They will not realize this new arbitrary requirement to be able to access the email address. They will lose their existing device. They will get a new device, install Bitwarden, and try to login with their master password, only to find that Bitwarden has moved the goal posts. They will be locked out of everything.

Even if 99.99999% of users would benefit from this change, Bitwarden shouldn't do it because it'll unfairly lock out 0.00001%. If they really want to do this change, then they should have like 2 years of warnings displayed on existing clients, and also have an option to permanently disable any 2FA requirement.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: