Mi CuentaIniciar sesión & Desbloquear

Understand Log In vs. Unlock

In order to understand why unlocking and logging in are not the same, it's important to remember that Bitwarden never stores unencrypted data on its servers. When your vault is neither unlocked nor logged in, your vault data only exists on the server in its encrypted form.

Logging in

Logging in to Bitwarden retrieves the encrypted vault data and decrypts the vault data locally on your device. In practice, that means two things:

  1. Logging in will always require you to use your master password or login with device to gain access to the account encryption key that will be needed to decrypt vault data.

    This stage is also where any enabled two-step login methods will be required.

  2. Logging in will always require you to be connected to the internet (or, if you are self-hosting, connected to the server) to download the encrypted vault to disk, which will subsequently be decrypted in your device's memory.

Unlocking

Unlocking can only be done when you are already logged in. This means, according to the above section, your device has encrypted vault data stored on disk. In practice, this means two things:

  1. You don't specifically need your master password. While your master password can be used to unlock your vault, so can other methods like PIN codes and biometrics.

    note

    Cuando configuras un PIN o una biométrica, se utiliza una nueva clave de cifrado derivada del PIN o del factor biométrico para cifrar la clave de cifrado de la cuenta, a la que tendrás acceso por el hecho de estar iniciado sesión, y se almacena en el discoª.

    Desbloquear tu caja fuerte hace que el PIN o la clave biométrica descifren la clave de cifrado de la cuenta en memoria. La clave de cifrado de la cuenta descifrada se utiliza entonces para descifrar todos los datos de la caja fuerte en memoria.

    Bloquear tu caja fuerte provoca que todos los datos de la caja fuerte descifrados, incluyendo la clave de cifrado de la cuenta descifrada, sean eliminados.

    ª - Si usas la opción de Bloquear con contraseña maestra al reiniciar, esta clave solo se almacena en memoria en lugar de en el disco.

  2. You don't need to be connected to the internet (or, if you are self-hosting, connected to the server).