Hi I was wondering if there were any plans to add email alerts on certain things like:
Failed login attempts,
Logins from unknown devices,
Failed customer service interactions regarding your account
These seem like a good way to keep a pulse on your account especially if you were exposed in some breach you may not even know about and people are trying to access the accounts involved.
It would be really nice if Bitwarden notifies the user (through email) whenever a new login happens, regardless of whether the 2FA was entered or not, as long as the Master Password is correct. This would mean that the 2FA is now the only defense against hackers…
The OS version, time of Log in, and the IP address should be included in the notification. The notification should also specify whether it was a full login (with correct 2FA), or whether its only the Master Password that was correct.
This would give the user a Chance to Change the Compromised Master Password before the Vault gets logged into by the hacker and all the passwords get stolen…
I am very happy that Bitwarden notifies on every new login. However, if an attacker somehow got both the Master Password and the 2FA, it would be too late. All the passwords would be stolen…
It would be best that the user can know that its Master Password was compromised, before the Vault gets logged into by a hacker. Bitwarden should always be one step ahead of hackers!
If Bitwarden’s Cloud gets hacked, the 2FA wouldn’t be of any use, since the Compromised Master Password is the Decryption Key.
Hope to see this security feature implemented soon!
Thanks a lot!
Yes, email, SMS, app notification, any warning helps!!
Anyone trying to hack, the very first failed, we should be notify.
In fact, even the very first success, I want to know too.
For password management software, there is nothing is too careful, don’t you think?
I agree with the fact that we should be warned if someone try to connect but enter the wrong password, but also if the wrong password is used but not the 2FA, meaning the master password has leaked.
It would be nice to have failed login attempts. It doesn’t need to be an email but an option in settings. Even if it’s a premium feature it would be nice to have. It would also be nice to know if someone got my master password correct and the 2FA stopped them.
It would provide extra piece of mind if it were possible to receive failed login notifications by email to warn you that someone tried to gain access to your account.
I’m not sure what I would do if I got one, - but it’s always nice to know.