When being prompted for a Master Password Reprompt (for passwords with that setting), allow the user to select a sleep period for future re-prompts of other credentials. This will suppress the ‘reprompt-for-master-password’ feature for this period when using other credentials with the ‘re-prompt’ option selected.
I would suggest periods akin to (5\15\30\60 minutes).
This would allow a user to use multiple ‘reprompt secured’ credentials within that window without being repeatedly prompted for a master password.
This would be useful for someone who has to log into multiple secured sites within a short, defined session, before being re-prompted.
I have merged your topic into an existing Feature Request thread. If you had cast a vote on your own thread, the vote will have been transferred here during the merge. If you didn’t vote yet, you can click the Vote button at the top of the thread to register your support for this request.
I just found and voted on this because I went to a site where I had re-prompt turned on. My vault was locked, so I had to enter my master password twice to fill the field. Fortunately, it wasn’t one of the sites like people mention in the thread where they have separate username and password pages. Three times in a row would have been really annoying
BY FAR my biggest gripe about Bitwarden: If I enter my lengthy, hard-to-type master password to unlock a field in an entry, then a few seconds later try to access another locked field, I have to type the whole thing AGAIN. This makes no sense.
One easy way to address this: an account setting that says, in effect, “Never ask for the master password if it has been successfully entered in the last xx seconds.”
Easy peasy. Please!
A work around for this. Don’t use Master password re-prompt. Instead set your vault to lock (not logout, there is a difference) after xx seconds. Then, set up biometrics (Face-ID, Fingerprint, and/or PIN) to unlock.
Once you need to do little more than “smile for the camera” (or “show the finger”, depending on perspective), you will find that you don’t mind generally keeping the entire vault locked, protecting all your entries, not just the few you deem important.
It is INSANE that I have to re-enter my master password AGAIN when I just entered it a few seconds ago.
I’m close to abandoning Bitwarden over this.
The fix is so simple: Even if the “master password required” box is checked for a given item, DO NOT demand it IF the user has entered it within the last <configurable time interval, such as 3 minutes>. Is that so hard?
To clarify, is the feature request that you want the “master-password re-prompt setting” that you explicitly enabled for any given item, to be overridden by an additional “don’t re-prompt” interval? (Completely decoupled from the vault’s timeout settings?)
I’m not much of a mind-reader, but my best guess as to the desired feature is that its implementation would require two new behaviors:
If the vault was unlocked (or logged into) with a master password, then “master password reprompt” is disabled for all items, for a configurable time interval of X min.
Anytime a “master password reprompt” enabled item is accessed (by typing in the master password), this would trigger “master password reprompt” to be disabled for all items, for a configurable time interval of X min.
In essence, there would be a timeout period for enforcement of “master password reprompt”, which would be separate and (mostly) independent from the vault timeout period — the timeout interval timer for “master password reprompt” enforcement would start anytime that the master password is entered (whether during the unlock/login authentication or while accessing a specific “master password reprompt” item; possibly also when entering the master password for other protected actions, such as creating vault exports). Unlike the vault timeout timer, the timer would not reset in response to user activity prior to expiration of the timeout interval.
If you unlock Bitwarden only to access a login which is protected by master-password-reenter, you have to type the master password two times in a very short time (<20 s). This is annoying and doesn’t increase security.
My request is a cooldown so you don’t have to type the master password in a given amount of time (edit like the auto-lock timer).
Log in to the browser extension using Login with Device. This (temporarily) disables all of your “Master password reprompt” settings, until you log out and log back in to the extension using your master password.
After completing the master password prompt once to open the item in the browser extension, use drag-and-fill to fill in the username, password, and TOTP on the website. If your screen layout allows it, you can optionally also use the “pop-out” button in the upper right corner of the extension to make it a floating window, which you could place side-by-side with your browser window (or, in Firefox, you could open the extension in the sidebar).
I saw the Login with Device bypass after going through, but I’m using SSO, and the restrictions about policies to enable do not allow me to implement this bypass unfortunately.
I must admit I was not aware of the drag and fill, thanks for the tip. So yes, I’ll go for the popup, as it seems to be THE usecase for it, I never tried if it would ask for another master password when opening the popup, tested and approved. Not perfect, but compared to 4 master password for a single login at the start of the day, I’ll take it with no hesitations!
I would really like this feature too, so I voted on it.
I only check this box for credit cards. In my experience, there are different credit card forms on most sites. Therefore, when I populate the form with the Bitwarden Firefox browser extension, it’s normal for Bitwarden to only partially populate the fields. Since I don’t have the credit card information memorized, I have to view the credit card entry (another re-prompt) to manually fill out the rest of the form. The majority of the time, that means I’ll be re-prompted at least two times.
I put a lot of effort into figuring out if there is a way to improve my Bitwarden entry so it fully populates most credit card forms. A lot of the time the CVC field name can’t be predicted in advance. Also, lots of forms contain drop-downs for things like months and days, and I couldn’t find any documentation that thoroughly explained if Bitwarden can populate drop-down values. If there is a way to reduce my re-prompts by improving my credit card entry in Bitwarden, I’d be happy to use that as a work-around.
This is so inconvenient I’m considering unchecking the box, which is a shame, because I would like that extra security for my credit card information.