I accidentally entered (per auto fill) my BW credentials in the login field of this forum

Am I in any danger? (If it helps, I haven‘t pressed enter afterwards, I realized my mistake first and then entered my real community forum password.)

Hey @tomtom

From what I could say I do not think there is any issue. Though I would likely change your auto-fill settings for the community forums, perhaps the host option should best suit you for this.

The community here is ran by the official team at Bitwarden so very little concern of anything “nefarious” going on to try and steal passwords here.
Though if you’d prefer you can always change your master password by following the instructions in their help site.

Hope this helps :slightly_smiling_face:

1 Like

Thank you very much for your answer. I panicked for a second :sweat_smile:
And I changed the autofill setting to use the exact URL value so that it won‘t happen again. Thanks again!

@tomtom You should also change the URI match detection rule for the login item that contains your Bitwarden vault credentials.

Personally, I like to make my match detection as restrictive as possible, so I have set the default to Exact, and only modify it on a case-by-case basis (to Starts with or Host) for those logins that don’t reliably autofill with Exact matching.

1 Like

Just done that. Thanks!

1 Like

Hey @cksapp do you know by chance if the community forum hashes the login details already in the browser or only after it has reached the server?

(I assume that BW would never store passwords - even of „unimportant“ stuff like the forum - unhashed)