Is "community.bitwarden.pw" a fake/phishing website?

as far as i can see, it shows the same content as community.bitwarden.com (this website)

Here’s my username for example: https://community.bitwarden.pw/u/TheBestPessimist/summary

I know this post is in the wrong place, but i dont see any good place (category/subcategory) to put it in.

Here’s a post from reddit 3 years ago:

https://www.reddit.com/r/Bitwarden/comments/iqkvok/possible_phishing_attack/

So, maybe a person doing his own stuffs innocuously. I would stay away from it sticking to the official bitwarden.com and bitwarden.eu, though.

I really wish that Bitwarden would:

  1. Refrain from using Namecheap as their registrar for the bitwarden.eu domain, as Namecheap is not very strict about policing malicious users of their services. Notably, the bitwarden.pw domain is also registered via Namecheap.

  2. Refrain from using registrar “privacy” services that hide the registrant identity. Not surprisingly, the bitwarden.pw domain also hides the identity of the domain registrant.

By clearly identifying Bitwarden (or 8bit Solutions LLC) as the owner of a domain, and by using only reputable registrars, it would be a lot easier for users to spot phishing sites.

1 Like

@bw-admin would it be possible for you guys to add a mention of fake bitwarden websites on your documentation page? I think it would be a good idea.