BW free account. Brand new user. When logging in here (community.bitwarden.com) it only suggests the vault user/password. I have to “forget password” each time, and there are no no entries saved in the Vault after. At least the browser caches it, and “remembers me” unless I deliberately log out of these forums.
Chrome browser. Use the pw generator in BW extension to make the new one. I see no options/flags/prompts to save this new login.
What am I not doing correctly?
Hello @sande005!
First I’ll recommend that it’s not best practice to store your master password inside your Bitwarden vault - it’s recommended that your master password is long, strong and most importantly memorable! Have a quick read over this article that highlights the importance of having a memorable master password. If you don’t know your master password, and you get signed out of all your Bitwarden sessions, this is the technical equivalent of locking your keys inside your house - but in the case of Bitwarden, there is no locksmith you can call to help you break in.
Deleting this vault login will help you avoid the confusion around which login to use when signing into community.bitwarden.com, as you should only have a vault item saved for the forum.
Bitwarden can’t always detect a password reset form (compared to a login form) which is why you may not be prompted to save the new password - you’ll have to do this manually.
While you have the forgot password reset form open, you should edit your vault item for community.bitwarden.com, then generate a new password (click the circular icon in the password field while editing) and then save your change within Bitwarden first. Copy and paste the newly generated password into the password reset form (you may even be able to auto-fill, as Bitwarden should detect ‘password’ fields on the page) - this ensures that your new password is saved first inside Bitwarden, and that you are using a randomly generated password.
Let me know if it works, and if there is anything above that I could clarify further for you!
Hello,
Try doing this:
- In your entry for Bitwarden vault’s credential (assuming you have one), change the URL matching for the link to “host”. Otherwise, it would suggest this for any login with “bitwarden.com” domain (default).
- If you don’t have the above, then your browser may be autofilling for you. Have you turned off the browser’s password manager function and autofill? Once you have completely migrated, you will want to delete the credentials in the browser’s password managers also, as this is another way your passwords can get lifted.
- Don’t use the “Ask to add login” and “Ask to update existing login” for BW extension (under Settings → Notifications). As it may be unreliable, you may want to do this to add new account / change existing password (courtesy of @grb ):
Here are more info of how to disable the browser’s password manager function.
If it is in fact Bitwarden that is suggesting the Web Vault credentials, then all you have to do to fix this issue is to edit the entry of vault.bitwarden.com
in the browser extension, find the “URI 1” field (which would have a value similar to https://vault.bitwarden.com/#/login
), click the icon next to the URI field (which will toggle the visibility of a dropdown menu), change the dropdown menu selection from “Default Match Detection” to “Host”, and finally, click Save in the upper right corner.
As far as I know, Bitwarden does not have such a prompt. Are you sure that you are not seeing prompts from your browser’s password manager?
Was there ever an entry in the Bitwarden vault before you did this? It is possible that everything you have described so far is caused by the browser’s password manager, without any involvement of Bitwarden.
This is part of your problem. If you are going to use Bitwarden’s browser extension, you need to disable the Chrome/Google password manager.
If you have enabled “Ask to add login” and “Ask to update existing login” under Settings > Notifications in the Bitwarden browser extension (and if the website is not on your list of Excluded Domains), then you should get a prompt to save the login credentials in your Bitwarden vault. However, it is a known fact that this function does not always work on every website (whether the Community Forum website is one of the problematic sites or not I cannot confirm at this time). Therefore, I usually recommend that you disable the two options “Ask to add login” and “Ask to update existing login”, and instead use the method that @Neuron5569 linked to in the response above, which I reproduce here for your convenience:
Adding a New Login:
The procedure below assumes that you have the website’s account registration form open in your browser, and that your Bitwarden browser extension is currently unlocked:
1.Open the browser extension (click Bitwarden icon at the top of the browser, or press Ctrl+Shift+Y).
2. Click (or the “Add a Login” link).
3. Type the desired username (or generate a random one).
4. Click the icon the in Password field (generate password).
5. Click Select in the upper right corner.
6. Click Save in the upper right corner.
7. You will now see the new vault item listed at the top of the browser extension’s “Tab” page → click on the website name (which will transfer your username and password to the website’s account registration form.
8. In your browser, submit the account registration form to the website server.
Thanks all for the replies.
I think the vault pwd save was Chome’s fault - I went through a couple of iterations of pwd export/import and sometimes used the browser version of Vault - so Chrome saved it. Somewhere in there was also the initial registration for this community - but who was remembering passwords at the time is vague, so not surprised it never got saved. Now that I have cutover completely (only BW, no pwd’s in Chrome at all), I’ll go back and delete the entry from the Vault.
By “forgot password” that was the step for this forum - only the Vault login shown, so entered user email, then clicked on “Forgot Password” which email link took me directly to an “enter new password” box (with no visible user name). I’ll manually add after one more “Forgot password” cycle again.
Too bad to hear about the problematic “Ask to add”/“Ask to update” issues. That may be a big issue in teaching the other user in the house about navigating the new-fangled system…
Too bad to hear about the problematic “Ask to add”/“Ask to update” issues.
The problem with “Ask to add”/“Ask to update” is they don’t work for all websites, but probably work for many major websites (being default config for BW). Also, it’s not as obvious to use the security/privacy enhancing features like username / email / password generations.
For the tech-inclined, I think it’s absolutely worth it to get them to work this way. For others, maybe helping them set up, importing all the existing passwords (and export a backup) and leaving the options as is would be good enough.
3rd party password managers are most likely always going to be harder to use than the browser/platform ones. If my non-tech inclined friends can settle with ChromeOS and mobile platforms only, I wouldn’t even bother with 3rd party. It’s the highly-accessible PWM + permissive OS + infostealer that make things particularly unsafe.
Here is another example of people not being able to handle BW real well (and I don’t think it applies to just “older” users):
To re-iterate what @Neuron5569 said above, the “Ask” prompts do work for the most part, but every now and then there will be a problematic website for which Bitwarden will fail to ask if you want to save the password — and when that does happen, it can be a bit of a chore to recover the account (since you most likely no longer have the password).
However, I would also like to stress that in addition to avoiding such problems (by guaranteeing that no password is ever lost), the method I have described above is actually both simpler and safer than a more conventional way of adding a new login (using the “ask to add” prompt). Simpler because fewer mouse clicks/keyboard inputs are needed; safer because passwords are never copied to the system clipboard (where they are vulnerable to being leaked).
Many Bitwarden users do use the “Ask to add/update” feature (and they are enabled by default), but I would suggest giving the improved technique a try yourself, before deciding whether it is something you feel you can successfully teach other users.