According to OWASP a work factor of minimum 10 and default 12 seems good
Related topics + references
If this where to be combined with being able to dictate some defaults/restrictions on this topic via organizations and/or self-hosted server settings this would be great
A pepper could be additionally used to increase security (but it might get hard to switch it on compromise?)
A possible alternative would be Argon2id, for which there already is a feature request or scrypt, which would allow to increase memory usage for countering GPU based hashing (used in some cryptocurrencies I think)
just joining this thread to say this is also something I would like to at least see addressed. Is there a reason why Bitwarden is using PBKDF2 instead of these more secure functions? Are there any previous blog posts about it?