Additional security email alerts

Would be useful. On a side note, I find this related to my suggestion of having a session management which shows the current logins with devices and IP addresses. You can vote here: Session management

I also think this would be a great feature.

I’m surprised this doesn’t already exist.

3 Likes

Any updates on this? What are the security measures in place to alert an user that their security may be at risk?

hoping for unlock/login failure alerts also (so we know if someone knows our bitwarden acct email, or knows our master password but is just 2fa blocked)

1 Like

Hello guys

I think Notify user by Email and push notification for every new login also show logged in sessions are important options for security.

@noname Here are some feature requests that seem similar to what you are asking.

It seems like pretty elementary security feature stuff but several related feature requests have been around a long while without response.

The “Disable Sessions” vault setting is not an adequate substitute in my opinion.

Great point. Love the better safe than sorry approach. Thank you!!

Just chiming in to say that I would also love to receive an email if somehow someone knows my email and master password and 2FA is the only thing preventing them from authenticating.

Maybe a good premium feature to offset the additional email costs. Although for the vast majority of users—hopefully—these notifications will never be needed and will be few and far between.

This is something I would like to see as well. I want to be notified if someone tries to login with my master password, even if they can’t pass the 2FA.

1 Like

One of the features that I miss in bitwarden is a push notification about a newly logged in device and the ability to view what devices we are logged in on and, if necessary, log out remotely. As is the case with Google, for example.
Thanks to this, if you forget to log out somewhere, you could check it and possibly log out this device. Currently from what I found there is only an option to end all sessions: /

Would it be possible to have an email when someone tries to login?
Currently we get an email when you fully login but in case your password is known by someone else but the 2FA isn’t could an alert be sent stating attempted signin?

This would warn the user to change their password and maybe their registered email.

1 Like

+1 would be awesome, just like in lastpass.

1 Like

Great, hoping to have much more active notifications of every login

Super neccessary

Are they considering this feature? especially number 1? Knowing or notifying you with failed login attempts will surely help you at least to change your password. Even though you have two of something that your bitwarden needs in order to access the account (password, 2FA), cutting them of by changing the password asap would at least give you a peace of mind.

Thank you and I genuinely hope you guys are reconsidering this.

You guys really need to send email about the unsuccessful login attempt where the someone entered the correct masterpassword but failed to pass 2FA authenticators.

It will alert users to the need to update their master password as soon as possible
because someone else probably had their Masterpassword.

3 Likes

As an FYI, if you sign into a Google account with Advanced Protection enabled and you enter the correct password and then don’t tap your security key, you will get either a “Security Alert” or a “Critical Security Alert.”

2 Likes

I believe this is a feature in the business version as it retains login logs. But the personal one, for privacy reasons, doesn’t create any login logs. Having said that, that’s not an excuse not to have this I agree it is quite important.