Start here: https://bitwarden.com/blog/beyond-your-browser/ is it safe There is no certainty in life, but Bitwarden is about as good as you will get. If you are thoughtful about how you use it (good master password, strong 2FA;, good opsec, and only operate on trusted devices), you will be in good shape. Can my passwords be compromised Yes and no. The LP gaff was the exposure of their backups to attackers. That can happen with Bitwarden. What is different is that LP has bad encryption. Couple that with choosing a bad master password and you could have a problem. Answer from djasonpenney on reddit.com
🌐
Reddit
reddit.com › r/bitwarden › is bitwardern safe?
r/Bitwarden on Reddit: Is bitwardern safe?
October 15, 2023 -

I am a new user and want to switch from default Google password manager to bitwardern so that i can use my passwords seamless. But am concerned that if it is safe to use and can my passwords be compromised like LastPass wass hacked?

Top answer
1 of 16
16
Start here: https://bitwarden.com/blog/beyond-your-browser/ is it safe There is no certainty in life, but Bitwarden is about as good as you will get. If you are thoughtful about how you use it (good master password, strong 2FA;, good opsec, and only operate on trusted devices), you will be in good shape. Can my passwords be compromised Yes and no. The LP gaff was the exposure of their backups to attackers. That can happen with Bitwarden. What is different is that LP has bad encryption. Couple that with choosing a bad master password and you could have a problem.
2 of 16
14
In my opinion, it's safer than google in the following ways. The bitwarden account is separate from your google account, so if someone compromises your google account it won't expose your password. The vault is safer on Windows. Any process with that runs as the user can read the password. Bitwarden as a security company and is probably more security conscious than Google, who wants to serve you ads. Your vault is probably readable by Google. Bitwarden vaults are not readable by bitwarden. Ways that Bitwarden is better than Last Pass. They seemed to more security conscious than LastPass. Bitwarden encrypt more of their fields. Bitwarden source code is open so that securitys firm can audit the code for security. The code cannot be stolen like they did with Lastpass. Bitwarden uses existing encryption open source algorithm instead of coming up with their own. The reason coming up with your own is bad is because the algorithm is quick complicated and you should stick with one that's being used and audited by everyone else. You can use u2F as a 2FA. Lastpass seems to be using OTP, which is not phishing-resistent.
🌐
Reddit
reddit.com › r/privacyguides › bitwarden... is it really %100 safe?
r/PrivacyGuides on Reddit: Bitwarden... Is it really 0 safe?
December 8, 2022 -

Compared to like Keepass, which is offline.

Idk but I feel like the risks are higher with Bitwarden since it's online and there is a risk of my data being compromised by whoever has access to where it's stored. Whereas KeePass is essentially a cold storage and the only way to get access to my data starts at getting the .kdbx file from where I store it, locally.

What am I missing?

EDIT: Asking for when on an Android OS.

Top answer
1 of 14
61
No such thing as "%100 safe". But Bitwarden is among the safest options (in my opinion at least). Whereas KeePass is essentially a cold storage and the only way to get access to my data starts at getting the .kdbx file from where I store it, locally. Yes, you can also keep your passwords in encrypted text on a laminated page stored in a bank deposit. That will be a lot safer than storing a KeePass DB file in your computer, as it can be compromised in case a virus is installed on your computer (it can send the database file, and keylog the password to decrypt it). My point is - convenience also matters. There's a point of security where you're already pretty secure, and adding more layers of security give you very little benefit security-wise, but make it a pain in the ass to use. In 2022, where most people usually have more than a single smart device, and a lot of accounts for different services, I feel like KeePass is a lot of a hassle as you have to sync the db file across your devices, and backup the local database file yourself. Bitwarden is open-source and audited, has a good customer service, a transparent business model, and handles backups, syncing, and security for you.
2 of 14
55
No, it isn't, because as others have pointed out - "100% safe" doesn't exist. Deciding whether or not using something like Bitwarden is appropriate for you is a personal decision that should be informed by your individual threat model and specific use case. compromised by whoever has access to where it's stored What am I missing? You may be missing that it's an open source project that encrypts everything client-side, which you can additionally protect further using a hardware security key so that your vault cannot be unlocked without it - even with your master password. And you can optionally self-host if you decide that you trust your capability to do so securely more than theirs. You can also do this without directly exposing your Bitwarden instance to the internet (access from outside only via a VPN). There are lots of options. In the event that there is some sort of data breach on Bitwarden's server, they still can't get your passwords. Bitwarden server administrators can't get your passwords. It might help to elucidate in more depth what specific attack vectors you have in mind that need to be better mitigated.
🌐
Reddit
reddit.com › r/bitwarden › how safe is bitwarden?
r/Bitwarden on Reddit: How safe is Bitwarden?
January 14, 2024 -

In a future unfortunate event when (or if) the Bitwarden servers suffer a malicious attack at the hands of expert hackers, with resulting breach of user data, what would be the options for the regular users?

I mean this could be serious and so I want to understand the security architecture of BW. How do they plan to avoid such mishaps and what would be their mitigation strategy (in case such event does happen), and how us, the users, would cope with it?

I know it’s not just about BW but for all other web-based services. However BW is the place where the most sensitive data are stored. So the concern.

I may be paranoid but I guess there has to be a back door to escape. What am I missing?

Thanks in advance.

EDIT: Thank you everyone for addressing my concerns. Have a great day.

🌐
Reddit
reddit.com › r/bitwarden › would you bet your life on bitwarden's security?
r/Bitwarden on Reddit: Would you bet your life on Bitwarden's security?
March 30, 2022 -

I am a long time user of both Bitwarden and KeePassXC (I love both). Bitwarden in convenient for auto-fills, but somehow I feel more secure with an offline database which KeePass offers (old school). I have ended up saving my high-stakes passwords with KeePass.

Is my apprehension unfounded?

Top answer
1 of 8
20
If you're not paranoid, you're not paying attention. :-) But that having been said, What exactly are you worried about? Nothing is perfect. I gather you're worried about happens if a malefactor gets his hands on a hard disk that has your passwords on it, but why are you worried about that? Of course you should have a long, strong, unique password — the longer the better — but if you do, then it won't matter much whether they get access to Bitwarden's cloud servers or whether a thief or burglar carriers off your laptop. Encrypted is encrypted is encrypted. The Bitwarden servers are a more attractive target I suppose. But they're also surely much better protected than your personal computers, even if you take them to bed with you at night. Everything is a compromise, and in the world of digital security you're always compromising between security and convenience. The more secure we make things, the less convenient they become, and at some point that inconvenience itself becomes a sort of security risk, because it causes us to start taking shortcuts. Bitwarden's solid. So's 1Password, NordPass and many others. I don't know KeePass but it's probably solid, too. Pick the one you like and then use it with appropriate carefulness.
2 of 8
12
If you are happy with what you are doing, you should keep doing it. Everyone has a different threat profile and everyone has different risk tolerances. So where you should be on the security-convenience spectrum is a personal decision that only you can make. Usually it’s less about trust and more about compartmentalization, just in case.
🌐
Reddit
reddit.com › r/bitwarden › do you actually put in all your passwords ?
r/Bitwarden on Reddit: Do you actually put in ALL your passwords ?
June 8, 2023 -

Newbie here, have been in the background just seeing posts here and there. Not really replying but I think I am ready to start using bitwarden BUT I’m not sure if I trust it enough to input my information for financial stuff, 401k login, bank etc.

Is anyone using this for that? I get if you don’t want to answer (I get it OPSEC)..but also when do you know if and when to trust it?

Other programs which have had breaches just makes me so hesitant

Find elsewhere
🌐
Reddit
reddit.com › r/bitwarden › is it safe to use bitwarden on a public computer with extra caution?
r/Bitwarden on Reddit: Is It Safe to Use Bitwarden on a Public Computer with Extra Caution?
March 11, 2025 -

Hello! I’m a new user of Bitwarden and have a couple of questions about security.

Is it safe to log into Bitwarden from a public computer's web browser (not as a plugin, but through the official website in incognito mode)? For extra caution, I plan to log in using my mobile device instead of typing my master password. I also have 2-factor authentication enabled.

🌐
Reddit
reddit.com › r/bitwarden › is it safer to use bitwarden on my web browser or the application? (on linux pc)
r/Bitwarden on Reddit: Is it safer to use Bitwarden on my web browser or the application? (On Linux PC)
October 26, 2022 -

I have a couple concerns with both approaches.

First with the browser: I have a very long randomly generated password for my master password, therefore it’s impossible to remember and a HUGE pain in the ass to type out manually, so on my PC I just end up leaving the password on my clipboard. I of course wanna change this habit as anyone who catches my PC (or laptops) on and unlocked can steal my master password.

So I was thinking of using the desktop application since I know it lets set a PIN rather than having to type out the entire master password every time.

My concern with this though is whether or not the locally saved vault is encrypted or not? Secondly, if it IS encrypted, would the PIN also decrypt my vault as my master password would? I’ve also heard some very bad things about Electron, how the app is built, does it have any inherit vulnerabilities I should be aware of?

If anyone has any recommendations on a potentially alternative approach I could take that is safer and also convenient I’m open to suggestions!

Top answer
1 of 5
25
I have a very long randomly generated password for my master password Let's start there. Switch to using a passphrase . It might end up being longer, but it will be easier to remember and easier to correctly type. Something like Weekday35-RejudgeLoopySaucepan is going to serve you much better than what you have now. leaving the password on my clipboard. It also means you can't use your clipboard? 🙂 set a PIN That can work. I regard a PIN like the privacy lock on a guest bathroom. It is to keep people honest, not to repel intruders. It can be a part of a reasonable security stack, but it shouldn't replace -- for instance -- locking your desktop. Is it safer to use Bitwarden on my web browser or the application? (On Linux PC) Not sure why you make this an either-or. The browser is going to offer superior security recognizing phishing attempts that are invisible to the human eye. The desktop app is still superior for certain things, but you need to find a way to keep using the browser extension. using the desktop application since I know it lets set a PIN This is where I really got lost. The browser extension for Firefox allows you to set a PIN as well. No need to use the desktop app. whether or not the locally saved vault is encrypted or not? Your decrypted vault is never written to persistent storage. AFAIK the entire vault except for attachments is held in volatile memory while the app is running and the vault is either unlocked or locked. Every, including the copy of the encrypted vault on your disk, is discarded when you log out. would the PIN also decrypt my vault as my master password would? The PIN is used by the running app to let you use that decrypted copy in memory. does it have any inherit vulnerabilities I should be aware of? Well's there may be a few minor nits, but there is not much that I know of for you to be concerned about at this level. potentially alternative approach Change your master password to a passphrase. Enable a PIN for both the desktop and the browser extension, if you wish. Use the browser extension when possible. Practice good opsec on your device, including desktop automatically locking, device physically secure, no other user accounts on the box, malware detection, etc.
2 of 5
3
I want to give big thumbs up to everything said in this thread by u/djasonpenney . Me, I use both extension and desktop, for same reasons as Jason Penney but also because I use biometric authentication on all the various computers I work on during the day and in order to log into the browser extension this way, I have to have the desktop app open. And don't forget there is a third form of the app: the website. And that's required for certain things like managing your account.
🌐
Reddit
reddit.com › r/bitwarden › why do you trust bitwarden?
r/Bitwarden on Reddit: Why do you trust Bitwarden?
November 4, 2022 - 23 votes, 49 comments. 97K subscribers in the Bitwarden community. Bitwarden empowers enterprises, developers, and individuals to safely store and share sensitive information. With a trusted, open source approach to password management, secrets ...
🌐
Reddit
reddit.com › r/bitwarden › what prevents bitwarden from being breached like lastpass?
r/Bitwarden on Reddit: What prevents BitWarden from being breached like LastPass?
March 3, 2023 -

Hey, all! Long-time LastPass user. I've been digging through various threads, but I haven't been able to find a good outline for this, so perhaps someone can point me in the right direction. From everything I've gathered, BitWarden's security is top-notch, esp if you use the recommended, but optional, Argon2 encryption. Notably, at least some things that LastPass did (like number of iterations), were not better on BW side (https://palant.info/2023/01/23/bitwarden-design-flaw-server-side-iterations/). It seems like Argon2 bypasses the whole issue altogether.

What I'd like to find out though is how BitWarden's organizational structure and security practices prevent exfiltration of data like LastPass has suffered. Does BW store unencrypted 2FA seeds like LP did, which could be exfiltrated together with their associated vaults? What are their data structure and practices like, and what's encrypted / not encrypted? I see lots of mentions how BW and 1Pass are much better on security, but I have not seen a clear point-by-point break-down of company fundamentals around security and internal workings. I've not seen these contrasted against LP either. "We've never been hacked" isn't a compelling argument, as that could be a combo of luck, or user-base size, or it might be truly due to their superior practices, but it's hard to point out exactly.

🌐
Reddit
reddit.com › r/bitwarden › how insecure is bitwarden?
How insecure is Bitwarden? : r/Bitwarden
January 29, 2022 - Either way, if that's as often ... and tell you where they come from - not self hosted though. ... Bitwarden empowers enterprises, developers, and individuals to safely store and share sensitive data....
🌐
Reddit
reddit.com › r/bitwarden › "if it's free, you are the product". then why do you trust bitwarden?
r/Bitwarden on Reddit: "If it's free, you are the product". Then why do you trust Bitwarden?
June 6, 2022 -

Hello guys,

I joined Bitwarden recently and I would like you to reasure me. As a long time non-user of password manager, I tended to trust my human memory to remember my password, and in my mind, those passwords were quite challenging to guess. But then, I read a comic from XKCD and articles about how password manager are better, etc. And I decided to trust Bitwarden.

Bitwarden is so popular: it's free, open source and seems trustworthy.

The problem is that now, I have some doubt.

"If it's free, you are the product." That saying is common sense here, in the internet. So why are we trusting Bitwarden all our passwords? Because it's open source? Because everyone is parotting that it's good, it's well protected because of "idunnowhatencryptionsorcery" and good policy and ethics? What proof do we have? Some... allegations by people online we don't even know personally? What will keep Bitwarden from going insane and do something like : "You want your passwords? Haha, now pay me 100 bitcoins".

Really, I don't want to shoot at Bitwarden or any other password manager. But reassure me, please.

Thank you in advance.

Edit: thanks for your answers, I am more serene now. I'm thinking about buying a Yubikey too, but it's another problem.

🌐
Reddit
reddit.com › r/bitwarden › how do i properly start securing my accounts using bitwarden
r/Bitwarden on Reddit: How do i properly start securing my accounts using Bitwarden
October 29, 2023 -

Hey guys! So, i’ve actually lost my account yesterday. The one where i use for my games, social media and other stuff that i use it on. All the grind i did on my games, all the friends that i had on my social media went gone. This actually happened twice to me although the first one was an account i just use to whatever i want. Still, it was useful and convenient, had some important stuff on it just before i lost it too. So now i want to keep things serious and secure my remaining accounts properly.

But as you know, Bitwarden isn’t a 100% safe app. None of the password managers are but i guess it’s less risky compare to memorizing your passwords so i want to know how to be more secure while using Bitwarden, keeping my accounts and password inside the app SAFE. Any kind of tips or things i should do that you highly suggest for me to do? Do you guys also use a notebook at home just in-case something happens? I really want to know more about this stuff. I’d really appreciate any help/tips. Thank you 😊

Top answer
1 of 13
45
It is your responsibility to safeguard your vault in the following ways: Set up a unique, confidential, randomly regenerated master password that provides for at least 50 bits of entropy (e.g., a randomly generated passphrase , which should contain four or more words drawn at random from a list of at least 6000 words), and do not allow others to observe you typing your master password. Enable the strongest form of 2FA that you are able to use (FIDO2/Webauthn if possible). Make sure that your devices are secure (e.g., do not allow others to access your devices, practice good internet hygiene, and ensure that you are using up-to-date malware defenses), and do not use Bitwarden on other people's devices. Always lock your Bitwarden vault when not in use (e.g., using the vault time-out function). If you're still nervous about committing your most valuable secrets to your Bitwarden vault, you can use one or both of the following methods to reduce the likelihood that an attacker who has gained access to your vault data will be able to take over your online accounts: Add a password pepper to your most valuable accounts. Set up 2FA for all stored accounts that support it, using a hardware key (if possible) or a TOTP authenticator app installed on a device that is different from the device on which you use Bitwarden. Here is my Guide for Getting Started on the Right Foot in Bitwarden™: Get a piece of paper and write "Emergency Sheet" at the top. The write down the Bitwarden cloud server that you plan to use (bitwarden.com or bitwarden.eu), as well as the email address that you will use for your Bitwarden login. If you're paranoid or like to play secret agent, make sure that you write with the paper placed on a hard surface (not a notepad or magazine), and that you are alone in a closed room with all curtains drawn. Click this link once, and copy down the displayed phrase on your piece of paper. This will be your master password. Unless you have a medical condition, you will be able to memorize it with some practice (you were able to memorize your mailing address, telephone number, names of friends and relatives, and similar information, and memorizing your master password is not much harder — but accept that it will take a bit of practice). Create your Bitwarden account either on the .com server or on the .eu server . Use a fake name if you wish, and leave the Password Hint blank for now. When you first log in upon account registration, there is an option to Verify Email , which you should use. Optionally, upgrade your subscription to Premium if you wish to use Premium features . Go to the "Two-Step Login" section of your Account Settings, and get your 2FA Recovery Code . Accurately transcribe this code onto your "Emergency Sheet" paper. In the "Two-Step Login" section, enable a 2FA method for your Bitwarden account. I recommend purchasing one or more Yubikey Security Keys for the purpose of securing your Bitwraden account. To set this up in Bitwarden, click "Manage" for the WebAuthn provider, and register your Yubikeys there. Personally, I have 3 security keys; I keep one on my person, one at home, and one at work. In the Account Settings, change your KDF algorithm to Argon2id. Keep the default settings unless you use iOS devices, in which case you should decrease the "memory" setting to 48 MB and increase "iterations" to 4. Populate your vault by importing passwords that had been stored elsewhere, or by creating new vault items from scratch. Download and install the Bitwarden client apps that you wish to use, and configure the settings in each. It is recommended to set the vault Timeout Action to "Lock" instead of "Log out", and to use a relatively short Timeout Period. Also enable to option that clears the system clipboard after a short delay. Create your first backup, by logging in the the Web Vault and creating a vault export, being sure to select the encrypted .json format with the "Password Protected" option . Use the same method as before to create a strong password for your backup file, and write down the backup file password on your "Emergency Sheet" paper. In addition, create an entry in your Bitwarden vault to save the backup file password (which will make it easier to use the password when you create future backups). Use your Emergency Sheet as a "cheat sheet" for typing in your master password when logging in or unlocking your vault, until you have acquired to muscle memory to type it by heart (approximately one week, give or take). Seal your Emergency Sheet in a security envelope (which you can purchase or make yourself ), and store it in a secure location. Optionally, make one or more redundant copies of the Emergency Sheet, to store in different locations. Optionally, update your Password Hint to contain a clue about where your Emergency Sheet is hidden. To change your Password Hint, log in to the Web Vault and use the password change form, but type in your existing master password into the new password field (so that the master password is not changed), and do not check the option for rotating your account encryption key. That's it! Update your backup export on a regular basis using the method from Step 11. Don't use your master password or backup password anywhere else, and do not let anyone know what these passwords are. Keep your devices secure, and malware free, and you should be good to go.
2 of 13
30
Use a unique email that you will check for Bitwarden login. Make your main password a 4+ word passphrase using Bitwarden generator: https://bitwarden.com/password-generator/ Change your KDF to Argon2 with default settings: https://bitwarden.com/help/kdf-algorithms/#changing-kdf-algorithm Enable 2fa on your Bitwarden account. Use totp or security key, no email: https://bitwarden.com/help/setup-two-step-login/ Create an emergency kit with your main password and 2fa recovery phrase at minimum: https://bitwarden.com/help/two-step-recovery-code/ // https://passwordbits.com/password-manager-emergency-sheet/ When creating passwords for websites, use Bitwarden generator for each website with 16+ character password. Include all options (upper/lower, special, number). Consider using aliases or plussed addresses for your logins. Use 2fa on all accounts where applicable. No sms or email, totp or security key only unless it's a bank that only supports sms. Store the backup codes in your vault or on your emergency sheet. Once this is all done, backup your vault using password protected export: https://bitwarden.com/help/export-your-data/#export-an-individual-vault don't use unencrypted unless you know how to manage it. Add the password for your export to your emergency sheet Use Bitwarden to autofill your credentials through the browser extension. Keep the default timeout timer and action unless you want it more strict.