I’ve used Bitwarden for years and did not learn about these 6 hidden settings that increase your safety

After organising Bitwarden a number of years in the past, I’ve barely bothered to alter any settings as a result of it simply works. Having tried several password managers, I made a decision to revisit Bitwarden to see if I used to be leaving any actual safety enhancements unused.
I discovered a number of. Some settings have been handing out extra entry than I’d realized, and some have been positioned on menus I’d by no means opened. It took a couple of minutes, however configuring these settings closed a number of small gaps in how I used to be utilizing Bitwarden.
Protect your most essential logins twice
Master password re-prompt provides a second test to particular person gadgets
Your vault has a master password, which is great security. While it is unlocked, somebody at your pc may entry the info inside.
From my Bitwarden browser extension, I configured Master password re-prompt to fence off particular person gadgets. This manner, Bitwarden requires the grasp password once more earlier than it reveals or autofills these things.
Follow these steps to configure it:
- Open the extension and discover the merchandise you wish to safe.
- Click the More icon (three vertical dots) and choose Edit.
- Scroll down, choose the Master password re-prompt checkbox, then Save.
I now have this setting on for my major e mail and my financial institution. This function has limits, although. According to Bitwarden, it is an interface guardrail, not encryption. Hence, if somebody has deeper entry to your system, it does not cease them.
If you do not unlock your vault with a grasp password, this function is not obtainable. This can occur with some SSO configurations.
Your 2FA codes are hitting the clipboard
Bitwarden copies them after autofill except you turn it off
I used to have my authenticator codes in Bitwarden, however I by no means realized the extension may copy my present TOTP code to the clipboard when it autofilled a login. This is a Bitwarden default.
You might discover the toggle chargeable for this below Settings > Autofill. It’s known as Copy TOTP robotically.
This is not essentially a flaw, however it does improve publicity; disabling it reduces that threat. TOTP codes expire rapidly, so the publicity window is proscribed. But the rest with clipboard entry should still be capable to learn the code whereas it is legitimate.
Just under this setting on the Autofill web page is a Clear clipboard choice. The present default is 5 minutes, however it’s price checking this setting in the event you’ve carried your Bitwarden configuration throughout totally different variations.
When Copy TOTP robotically is disabled, you lose the comfort of getting the code prepared to stick instantly after autofilling a login. You must use the inline menu or copy the code your self.
Check whether or not you enabled page-load autofill
It’s off by default, however Bitwarden warns that compromised websites can exploit it
Bitwarden can fill in your credentials robotically when an identical web page opens. This occurs with out you clicking if Autofill on web page load is enabled.
This setting is disabled out of the field, and a warning subsequent to it notes that compromised or untrusted web sites can exploit it. However, it is handy, and in the event you’ve used Bitwarden for years, you’ll have enabled it in some unspecified time in the future. Hence, this particular tip is extra of an audit than a repair.
To test:
- Navigate to Settings > Autofill in your extension.
- Scroll down and uncheck the Autofill on web page load field.
Bitwarden already blocks page-load autofill in untrusted iframes, however I nonetheless desire to set off autofill myself utilizing Ctrl + Shift + L.
Make logins present up in fewer locations
Host matching ties a login to at least one hostname as a substitute of the entire area
By default, Bitwarden matches logins by base area. This is a handy function, but it’s broader than you might think about. This signifies that a login saved for instance.com may also be supplied on its subdomains (e.g., sub.instance.com).
I desire Host matching. Host matching restricts autofill to the desired hostname.
To configure it:
- Navigate to Settings > Autofill in your extension.
- Scroll right down to Default URI match detection and set it to Host.
You may set it to Exact. This manner, you’ll be able to prohibit autofill to HTTPS pages as a result of the URL has to match precisely.
While this setting does not management whether or not a website deserves your belief, you not less than handle the place a login will get supplied.
Tell Bitwarden the place to remain out
Blocked domains stops fills, passkey prompts, and save prompts
You have the Blocked domains choice on the backside of Settings > Autofill, and it does greater than the identify implies. Once you add websites to blocked domains, Bitwarden stops providing passkey prompts and autofill. It additionally stops asking to save lots of or replace logins.
There are already choices for URI matching and excluded domains, however blocked domains does one thing totally different:
|
Setting |
What it controls |
What nonetheless occurs |
|---|---|---|
|
URI matching |
Where a saved login is obtainable |
Other Bitwarden prompts and options can nonetheless seem |
|
Blocked domains |
Autofill and credential prompts |
Bitwarden can nonetheless be used manually within the extension |
|
Excluded domains |
Save/replace and passkey prompts |
Autofill can nonetheless work |
Make an offline assault costlier
Argon2id sits within the internet app’s encryption settings, not the extension
Bitwarden runs your grasp password by a key derivation perform, or KDF, as a substitute of utilizing it straight. This makes particular person password guesses gradual and costly. That price is commonly what prevents an attacker who obtains your vault from rapidly accessing your knowledge.
Bitwarden helps PBKDF2 and Argon2id. Both make password guessing costlier, however Argon2id additionally requires reminiscence for every derivation. That makes large-scale parallel guessing extra expensive.
You can replace this within the internet app by going to Settings > Security > Keys and altering from the default to Argon2id.
The defaults you get with Argon2id are 32 MiB of reminiscence, 6 iterations, and a parallelism worth of 4. You do not should max out these choices, as a result of larger values will make the unlocking course of in your gadgets slower.
However, the default PBKDF2 continues to be the higher choice for FIPS 140-2 compliance, and altering the KDF settings does not take away the necessity for a robust grasp password.
Your vault deserves one correct look
I’ve included six safety configurations, however you do not have to do all six. I prioritize the re-prompt on my e mail login and the Argon2id change. These are adjustments I could make as soon as after which depart alone except my wants or gadgets change.
The different adjustments depend upon the way you browse. Bitwarden’s defaults are wise for broad use, however they do not essentially match how I would like my vault to behave. Taking time to look by these settings made me perceive what my vault really does when I’m not paying consideration.
- OS
-
Cross-platform
- Developer
-
Bitwarden
- Price mannequin
-
Free, Premium obtainable
- Services
-
Password supervisor, password generator, safe file sending, credential administration, and so on.
Bitwarden is a safe, open-source password supervisor that helps you generate, retailer, and autofill robust passwords throughout all of your gadgets. It makes use of end-to-end encryption, that means solely you’ll be able to entry your knowledge—not even Bitwarden itself. With assist for passkeys, safe notes, and cross-platform apps, it’s a privacy-focused various to built-in browser password managers.
