SecuFocus
PasswordsGetting started & analysis

Bitwarden: organise your passwords without locking yourself out

Bitwarden password manager: generator, Argon2id, recovery and exports. The vault, its settings and the limits of its protection.

Before you get started

What to expect

Bitwarden stores your credentials and generates a different password for each account. Before moving everything into it, choose a strong master password, set up a second factor and keep recovery information somewhere other than your everyday device.

The problem often starts with a convenient password

One password for shops, a variation for social media, another for important accounts: this can seem reasonable until a service loses its credential database. Reuse then connects accounts that had no reason to fail together.

A password manager changes the job. You no longer need to invent a memorable formula for every website. You generate and store distinct secrets, then protect access to the vault carefully. This is the practical appeal of Bitwarden: making that discipline usable across the devices you actually use.

Generate a secret instead of inventing a formula

The built-in generator offers random passwords and passphrases. For an automatically filled login, our starting point is 20 random characters if the site accepts them. For something you must remember or type often, six independently drawn words from a large list are more manageable. These are editorial guidelines, not thresholds imposed by Bitwarden.

Do not choose six words that tell your life story, or reuse an example from an article. Random selection is the generator’s job. Yours is to verify saving and sign-in. If a site rejects particular characters, adjust only what is necessary and retain as much length as possible.

What protects a stolen copy of the vault

Bitwarden documents local encryption of vault contents before storage, using AES-256-CBC with HMAC-SHA-256. Key derivation turns the master password into cryptographic material while making each guess more expensive. This matters when an attacker holds an encrypted copy and can try candidates offline.

The values below come from documentation checked on 2 October 2026. They describe defaults for the offered algorithms, not necessarily your account’s current settings. Changing the KDF does not rotate the vault’s symmetric key.

AlgorithmDocumented settings
PBKDF2-HMAC-SHA-256600,000 client-side iterations by default.
Argon2id32 MiB memory, 6 iterations, parallelism 4.

Encryption does not secure an already compromised device

Distinguish two situations. Someone who obtains only an encrypted vault still has to overcome its cryptographic protection. Malware on a device where you open that vault may try to intercept what you type or display. The same word, security, covers two different problems.

Two-factor authentication protects online access to the service. It does not make a weak master password unpredictable in an offline attack. Sensible automatic locking, an updated system and carefully chosen extensions remain necessary. A password manager is not insurance against every program installed on the computer.

Finally, “zero knowledge” describes protection of encrypted contents from the service. It should not be read as an absence of all administrative, billing or connection data. Assess the provider’s policy and your subscription separately for those questions.

Migrate three accounts to start

Choose your main email account, an important storage service and a shopping account. This small selection lets you learn without turning the whole week into a migration project. Keep existing sessions available until you have checked the new sign-ins.

  1. Create the vault with a long, unique passphrase used nowhere else. Arrange a protected way to recover it without opening the vault.
  2. Install the official extension. Check the publisher and start from Bitwarden’s website rather than a search advert.
  3. For each selected account, open its official website yourself, change the password and save the new credentials.
  4. Check a fresh sign-in before moving to the next account. Seeing an entry in the vault does not prove that the website accepted the change.
  5. Enable a second factor for the vault and keep its recovery code somewhere other than the only device providing that factor.

Autofill also gives you a clue

Bitwarden matches credentials to website addresses, using the base domain by default. Stricter rules are available. If an expected credential is not offered, inspect the address before searching for the password and pasting it manually.

A missing suggestion does not prove fraud: a new sign-in address may be legitimate. It does deserve a pause. For an important account, check the domain through a known bookmark or the service’s documentation. Advanced users can examine Host or Exact matching when several applications share a domain.

Master password, second factor and recovery

Bitwarden’s two-step recovery code does not replace the master password. The recovery procedure also requires the account email and that password. Bitwarden cannot simply send back a forgotten master secret; recovery options depend on what was arranged beforehand.

Write full names on your recovery document. A sheet labelled “Bitwarden code” becomes ambiguous when you need to distinguish a password, a second factor and an export.

The secretIts role and the mistake to avoid
Master passwordOpens the vault. Do not store its only fallback inside that same vault.
2FA recovery codeDisables the second factor when supplied with the email address and master password. It does not replace the master password.
Export passwordDecrypts that particular backup. It may differ from the account password.

Choose an export you can import again

Bitwarden distinguishes account-restricted encrypted exports from password-protected exports. The latter can be imported into another compatible account. Account-restricted exports remain tied to their original account and may stop working after an account encryption-key rotation.

For independent recovery, examine the format before exporting. Store the encrypted copy and its password so you can retrieve them without the original service. An export is a snapshot: date it and renew it after important changes.

An import check can create duplicates. Learn the procedure in a separate test environment with fictional credentials. Avoid leaving plaintext exports in Downloads or copying them into an email.

Arrange help without handing everything over today

Emergency Access can provide viewing or takeover access after approval or a waiting period, depending on its configuration. It must be arranged in advance; the person granting access needs the required plan, currently Premium.

This calls for an actual conversation: who can request access, under which circumstances and with what consequences? It is not a box to tick casually. For some people, a carefully stored personal recovery procedure will be more appropriate.

Continue the migration or compare alternatives

Once you can save, retrieve and replace a login, move the remaining accounts in small groups. Remove duplicates, identify abandoned accounts and correct outdated sign-in addresses as you go.

If you are still unsure how to unlock or recover the vault, practise with an unimportant account before continuing. You need to be able to regain access even if your usual phone is unavailable.

When comparing Bitwarden with 1Password, examine sharing and recovery, then the protection model: Bitwarden provides key-derivation settings; 1Password adds a Secret Key to the account password. The cited documentation explains what those choices mean. SecuFocus has not run a comparative test on its own devices.

From the provider

Bitwarden

Downloads, compatibility and current terms.

Official website

Frequently asked questions

Practical questions

Can Bitwarden simply send me my master password?

No. Prepare recovery before you forget it. A two-step login recovery code does not replace the master password. Other options depend on your account and what you configured in advance.

Read more: Master password, second factor and recovery #Link to this answer

Why does a vault export need protection?

Depending on the format, an export may contain readable credentials. Check its encryption and what you need to import it again. Avoid leaving a plaintext copy in Downloads or a synced folder.

Read more: Choose an export you can import again #Link to this answer

Check and explore

Sources for this article

Numbers connect each reference to the passages that use it. Dates show when the documentation was consulted.

This article draws on the sources above. The exercises are for you to try on your devices; SecuFocus does not present them as tests carried out by its editorial team. Interfaces and features can change. Method and corrections.

Cite this article

Keep this reference with the article when you save or share it.