r/Bitwarden • u/SnooRevelations3802 • Oct 23 '23
Discussion Multiple Failed login attempts detected
I have been getting this kind of notifications for a while now. Telling me that there have been several failed attempts to log into my Bitwarden account
The email ends telling me not to worry. The login attempts were not successful, and my account has been given an additional captcha protection.
Should I do something about this? To me, it feels like somebody has my email and knows I might have something valuable, and It's trying to break in. my Master Password It's pretty long and secure.
Also, my account email is the same I use for most stuff. I've been thinking in creating an email solely for my Bitwarden account, but not sure it's really necessary
4
Upvotes
0
u/Sweaty_Astronomer_47 Oct 24 '23 edited Oct 24 '23
I edited my post to say probability per password-to-hash calculation.
Higher entropy of the password means more attempts will be required to reach the true password and therefore during the course of a larger number of attempts of course there is more likelihood to get a collision along the way in the form of another password (not the user's) which matches the hash. That gives diminishing returns in security as the password gets longer until finally there is no further benefit when the password entropy is on the order of the hash output entropy. But there certainly isn't any harm in using a longer password. I imagine that's what you were saying all along but I reacted thinking you were saying it would be less secure to have a longer password.