Re-prompt by unlock methods (alternative to master password re-prompt for individual item protection)

Ah, that is fantastic, @bw-admin. My apologies for missing your reply. I appreciate this has been given attention for a future update; it’s really quite useful, once people can get used to it.

Thank you so much.

1 Like

Another feature that I wanted, that I found in search. Glad to see it is under investigation. Is there any timeline on this though, since I see that comment was 8 months ago. (lol, not sure how to better word it, to not sound like I’m demanding an ETA)

Hey @Warden1 thanks for checking in, no specific eta at this time, but we will be sure to share information as it becomes available.

2 Likes

Feature name

  • Fingerprint instead of Master Password when “Require Master Password” selected

Feature function

On my phone, I have a couple of entries set up that require the Master Password before allowing access to their data. LastPass’ android app used to allow biometrics as an alternative to typing in the password. It would be nice to have this in BW too

Feature name

Re-prompt but for pin instead of master password.

Feature function

In Settings, a user will be able to check “Re-prompt with pin”, in addition to “Re-prompt with master password”.
In an item window, there will be the general option to “Require re-prompt for access” instead of specifically “Master password re-prompt”.

Then, if re-prompt with pin had been activated, when the user has an item that requires re-prompting, the user will be able to enter their pin instead of their more sophisticated or much longer master password.

This makes the app more secure in the using because it prevents the user from either choosing a short master password to make re-prompting less of a hassle or not using re-prompting at all due to what a hassle it is to input a sophisticated or long passphrase every time.

The master password should only be used for encryption/decryption purposes, and the user should be encouraged to make it a sophisticated or long passphrase.

After decryption has finished, we should be able to use an easy-to-remember and quick-to-enter pin for access to sensitive items.

(There is a related request but it is worded vaguely and is not gaining any votes so I wrote this request in a way that is clear and easy to get behind).

1 Like

Responding that this is still an issue that I’d like solved please!

1 Like

I would like to have the ability to authorize another password to access very sensitive items, such as re-prompting the master password. In the event that the master password has been compromised and there is potential access to my vault, it would be nice to have something like a second level authorization, to prevent a complete leak of the vault.

Bitwarden already offers a Master Password Reprompt feature that will prevent anybody from seeing, copying, or autofilling passwords (and any other hidden fields) in sensitive items for which you have enabled this extra protection:

Protect Individual Items

Doesn’t directly go to fulfill your request, but if you have some items that are critical beyond just trusting them in your password manager you can use alternative methods such as a password pepper to create a “double-blind” password essentially where your password stored in the password vault is not the full actually used password for the site or service.

That way you at least can feel better about not storing “all your eggs in one basket” if you need.

UP… Came from Lastpass and this feature is critical for me. I hope they tackle this soon.

It would be nice to allow Yubikeys or other Phisical Security Keys as well

Any updates regarding this?

Created an account only to upvote this. This feature would be really great to have, being able to re-authenticate or confirm password with fingerprint when trying to access cards or bank details. Definitely needed! Currently the only missing feature for me.
Is this on a roadmap in near future?

1 Like

Wish you’d work on this, please, or let us know why you don’t think it’s a good idea.

I particularly hate not having this for sites/apps that don’t show the username and password in the same screen. That means I have to type my password twice. It’s a real pain on Android, with a complex password and a thumb-keyboard.

It’s the same for copying a username and then a password.

Not having it makes bitwarden less secure because most people will just turn off password re-prompt for the annoying site. There is one that I use every day.

It could be resentment of former Lastpass users who descended on the Bitwarden platform demanding Master Password Reprompt. It was implemented in pretty fast time but those users are still not happy, sparking more resentment. Only a guess.

Just pushing this thread, every vote counts :grin:

1 Like

Please add I also just made an account to vote for this

1 Like

I also signed up just to vote on this.

I honestly can’t believe this isn’t an option. I’ve been looking to switch from LP for over a year now, and have tried Dashlane, 1Pass, NordPass, and of course BW. BW is by far the best candidate, but the fact this particular feature doesn’t exist means I either seriously reduce the level of security for my most important items (mainly banks, etc) or I have to enter my password upwards of like 40x per day. With LP, I just use my fingerprint, so it’s half a second -2 seconds. This is a dealbreaker for me. And I can’t believe none of the other PMs actually provide this feature. So disappointed I was really hoping to switch to BW but I can’t be typing out my master password 30-40x per day. It’s 18chars long. Not doing it. So, please make this happen and you will have a loyal user.

This feature is repeated throughout multiple posts, and therefore doesn’t have the vote weight it should. Adding up all the votes, this easily becomes one of the highest voted features.

ex. Adding Biometric/PIN authentication as an alternative for Master Password Re-Prompt

1 Like

I have been saying this for literally years. I’m nearly done waiting. Hate to admit it, but you’re doing the right thing by not switching to Bitwarden.

1 Like