Security risks of using Bitwarden as authenticator and password manager

Hm, as this get’s a bit off-topic now for this feature request here, I would like to respond only shortly now - and if this discussion should be continued, I suggest opening a separate topic for that.

It seems, you are in conflict with the FIDO Alliance here:

(source: https://www.passkeycentral.org/resources-and-tools/customer-support#web-based-faq-examples – and similar text also here: https://www.passkeycentral.org/introduction-to-passkeys/passkey-security#multi-factor-authentication → “passkeycentral” is a website of the FIDO Alliance)

Unfortunately, Bitwarden indeed has no User Verification mechanism for now. There are some signs, it will be implemented via the OS in the future… if that could be considered as “making Bitwarden-passkeys MFA (again)”, is a good question…

Speaking of factors again… there also some people now - also part of the FIDO Alliance etc. - considering stop counting factors / stop thinking in factors may be the beginning of a new paradigm here… (as one idea of different factors was a reaction to some downsides to passwords, that are now mitigated with passkeys…)

PS: That said, I also value my YubiKeys - and store some passkeys only there…