Never autofill Social Security Number

Feature name

Never autofill Social Security Number

Feature function

Two reasons why the Social Security, Passport, and License numbers should never autofill:

  1. It seems possible for a malicious web form to have a hidden field titled “Social Security Number,” and when the user selects an Identity with the intention of just filling in their name and address into the visible fields, the website could actually trick Bitwarden into leaking their SSN.
  2. It’s extremely rare that any website would need a SSN/Passport/License number. Name, address, phone, and birth date are very common.

To avoid malicious or accidental leaks of those confidential numbers, the name and address fields should auto-fill when the user selects that Identity, but the SSN, Passport, and License numbers should not autofill. Those should need to be manually copy/pasted if they are needed for a web form.

1 Like

Sounds like this request with the addition to not fill out certain item types.

1 Like