How to use YubiKey for unlocking - solution

Hi @stevel,

Thank you for joining the Bitwarden community and for sharing your thoughts and workflow with us.

I wanted to reply here in order to emphasize that this setup means that both your Bitwarden master password and 2FA are stored together on the same security key (YubiKey); If a person gains access to your YubiKey, they would have access to your Bitwarden account and vault, which is not the case if your YubiKey was not also storing your master password and only acted as your 2FA. This can be more convenient in some situations, but it’s important that you, and anyone else that is reading this, be aware that this can arguably be significantly less secure than keeping your master password and 2FA separate.

You are more than welcome to use this setup if you see that it fits your threat model, I just wanted to make sure that anyone else that would read this would be aware of this setup’s potential downsides.

All the best,