You can now unlock your vault with a passkey

@Micah_Edelblut

This would be a huge improvement. Personally, as much as I’d like to, I probably won’t use Unlock with Passkey unless it is possible to disable Login with Passkey (ideally, on a per-key basis).

If your passkey is stolen, then the only thing protecting a vault that has Login with Passkey enabled is the passkey’s UV (e.g., a PIN). In contrast, for Unlock with Passkey, there is additional protection inherent in the fact that to get access to the vault data using a stolen passkey, the attacker would also need to steal or otherwise access a device that has a logged-in Bitwarden client, and that device would need to be unlocked as well (e.g., using an operating system password).

For these reasons, the UV PIN required for Unlock with Passkey can be significantly weaker than the Passkey PIN required for Login with Passkey (see this discussion of YubiKey PIN strength requirements) — i.e., for a passkey used for both login and unlock, the unlock PIN is going to be unnecessarily complex. In other words, until Login with Passkey can be disabled, there is no real benefit of Unlock with Passkey, because the passkey PIN would have to be more complex than a PIN used for Bitwarden’s Unlock with PIN option.

2 Likes