Bitwarden, a widely used password manager, is enhancing security for accounts that do not have two-factor authentication (2FA) enabled. Starting in February 2025, users logging in from unrecognized devices will be required to verify their identity via an emailed verification code. This new measure is designed to prevent unauthorized access to user vaults, particularly for those who have not implemented 2FA. This security step is triggered by logging in from a device the system does not recognize, such as after app reinstallation or browser cookie deletion, and aims to provide better protection against credential theft.
This email verification requirement will not affect users leveraging self-hosted instances or those who have already implemented 2FA, API keys, or single sign-on (SSO) for logins. However, users who do not utilize these measures are strongly encouraged to ensure they have independent access to their associated email accounts so that they can retrieve the verification code. It is also advised to use strong and unique master passwords that cannot be easily compromised. The implementation of email verification is intended to add a layer of protection, especially given that users may store email account credentials within their Bitwarden vaults, which means they would need access to these credentials to get the emailed codes.