A laptop and phone display password manager interfaces beside keys and a shield, illustrating digital security.
Most of us set up a password manager once, then leave it alone for years. MakeUseOf writer Afam Onyimadu recently went back into Bitwarden's settings after years of leaving them untouched. He found six options worth a second look. Three are about limiting where Bitwarden acts. Two are about limiting what lingers on your machine. One is about making an offline attack on a stolen vault more expensive.

This guide covers what each setting does, where to find it, and where it stops helping. One caveat first: the author's account of his own habits is a personal report. The behavior of the settings is checked against Bitwarden's own help documentation wherever I could confirm it.

1. Master password re-prompt: a second lock on your best items​

Your vault has a master password, but once it's unlocked, anyone at your keyboard can browse it. Master password re-prompt lets you mark individual items so Bitwarden asks for the master password again before showing or autofilling them.

To turn it on in the browser extension:

  1. Open the extension and find the item.
  2. Select the three-dot More icon, then Edit.
  3. Scroll down, tick the Master password re-prompt box, and Save.

Onyimadu uses it on his primary email and bank logins. Email is a sensible pick because it often serves as the reset route for everything else.

What it does not do:

  • Bitwarden describes it as an interface guardrail, not extra encryption. Someone with deeper access to your device isn't stopped by it.
  • It isn't available if you don't unlock with a master password. Some SSO configurations work this way.
  • Bitwarden's documentation says behavior differs on mobile. There, the prompt applies when you view hidden fields or edit the item.
  • Trusted emergency contacts aren't required to re-enter a master password to view a protected item.

In short, this is friction against casual access. It doesn't replace locking your vault or your PC.

2. Copy TOTP automatically: your 2FA code on the clipboard​

If you store authenticator codes in Bitwarden, the extension copies the current code to the clipboard when you autofill that login. That's the default. The toggle is under Settings > Autofill, labelled Copy TOTP automatically.

This isn't a vulnerability. It's a trade-off. Codes expire quickly, so the window is short. But anything else that can read your clipboard could grab the code while it's still valid. Turning the option off means you'll fetch the code yourself, either through the inline autofill menu or by copying it manually.

Right below it is the Clear clipboard setting. Bitwarden documents five minutes as the default. If your configuration has carried over across many versions, check what yours is set to.

3. Autofill on page load: audit it, don't assume​

Autofill on page load fills your credentials as soon as a matching page opens, with no click. It's off by default, and Bitwarden puts a warning beside it that compromised or untrusted sites could exploit it.

The point of the tip is an audit. If you've used Bitwarden for years, you may have switched this on once and forgotten. Check it under Settings > Autofill and uncheck the box if you'd rather not have it.

Some safeguards already exist, per Bitwarden's documentation:

  • Page-load autofill isn't performed in untrusted iframes.
  • Bitwarden warns before filling on an HTTP page when the saved URI implies HTTPS.
  • Page-load autofill doesn't fill TOTP codes.
  • You can override the setting per login item.

The author prefers to trigger autofill manually with Ctrl + Shift + L. Bitwarden documents that shortcut (Cmd on Mac) as filling the last-used login on a matching page, and pressing it again cycles through matches.

4. URI match detection: narrow where logins appear​

By default, new logins use Base domain matching. A login saved for example.com can therefore be offered on sub.example.com too. That's convenient, but it's wider than many people expect.

Under Settings > Autofill, set Default URI match detection to something tighter:

MethodBehavior
Base domain (default)Matches the second-level and top-level domain, including subdomains
HostMatches the specific hostname (and port, if given)
ExactRequires the whole URI to match, including scheme and path

Exact has a side benefit. If the saved URI is HTTPS, a plain HTTP page won't match. Bitwarden also lists Starts with, Regular expression and Never. It warns that Starts with and regex can be dangerous if configured incorrectly, so skip them unless you know why you need them.

Two limits matter here:

  • Matching says nothing about whether a site is trustworthy. It only controls where a login is offered.
  • Platform quirks apply. Bitwarden documents that Android's autofill APIs can't currently match by port or path. iOS keyboard suggestions always use base-domain matching.

You can also override the method for a single URI on an item. That's handy when one site needs to be strict and the rest can stay on the default. If your organization sets a default, that may override your account default.

5. Blocked domains: tell Bitwarden to stay out​

At the bottom of Settings > Autofill, Blocked domains does more than its name suggests. For a listed site, Bitwarden stops autofill, passkey prompts, and prompts to save or update logins. You can still open the extension and use an item by hand.

Don't confuse it with its neighbors. The table below uses the distinctions from the article and Bitwarden's documentation.

SettingWhat it controlsWhat still happens
URI matchingWhere a saved login is offeredOther Bitwarden prompts can still appear
Blocked domainsAutofill and credential promptsManual use in the extension still works
Excluded domainsSave/update and passkey promptsAutofill can still work

Blocking suits sites where you never want Bitwarden offering to fill or save anything, such as internal tools or sites with odd login forms.

6. KDF: make offline guessing more expensive​

Bitwarden doesn't use your master password directly. It runs it through a key derivation function (KDF) that makes each guess slow. If an attacker gets a copy of your encrypted vault, that cost is what slows brute-forcing.

Bitwarden supports two options:

  • PBKDF2 SHA-256. Bitwarden's documentation says it iterates 600,000 times by default, as recommended by OWASP for HMAC-SHA-256. The same page says the implementation is FIPS-140 compliant as long as the value isn't set lower.
  • Argon2id. This one is memory-hard: each derivation needs memory as well as compute. That makes large-scale parallel guessing costlier.

The article's path to change it is the web app, not the extension: Settings > Security > Keys. Choosing Argon2id means you'll be logged out and need to sign in again. A third-party walkthrough from Dave's Computer Tips describes the same path and the logout warning, though its older screenshots show different default values.

The numbers, with a date stamp​

Bitwarden's documentation lists the Argon2id defaults as 6 iterations and parallelism of 4. The documentation reviewed also lists 32 MiB of memory. Treat these as a snapshot. Older guides, including a GRC forum thread and the Dave's Computer Tips walkthrough, cite earlier defaults of 64 MB memory and 3 iterations. A tech-insider.org guide says the current documented defaults, last revised in late August 2026, are 32 MiB, 6 iterations and 4 threads. In other words, defaults have moved before and may move again.

Bitwarden also made a related change. In the 2026.2.1 release, it raised the minimum PBKDF2 iteration count to the 600,000 default. If your account was set lower, expect a prompt to update.

Don't max everything​

Higher settings make unlocking slower, especially on weaker hardware. A Bitwarden community thread notes that even 64 MiB has proven difficult in some contexts, such as iOS autofill. Bitwarden's documentation also warns on iOS when memory is set above 64 MiB. If you change the KDF, test on your slowest device first.

Argon2id isn't automatically the right answer either. If your organization needs FIPS-140 compliance, PBKDF2 at or above the threshold is the documented choice. And no KDF setting replaces a long, unique master password.

What to do first​

You don't need to change all six. Onyimadu's own priorities are re-prompt on his email login and the Argon2id switch, because he can set both once and leave them. A reasonable order:

  1. Turn on re-prompt for email, banking and any admin or recovery accounts.
  2. Check whether Autofill on page load is on. If it is, decide whether you really want it.
  3. Consider disabling Copy TOTP automatically if you use Bitwarden as your authenticator.
  4. Switch Default URI match detection to Host or Exact, then override individual items that break.
  5. Add Blocked domains for sites where Bitwarden should stay out.
  6. Review your KDF. Change it only if you've tested your devices and have no FIPS requirement.

The article is a first-person account from a single writer, and it's more audit checklist than discovery. These settings are documented, not secret. Still, the useful lesson stands: a password manager's defaults suit a broad audience, and "it just works" isn't the same as "it's set up the way I'd choose."

 

References

  1. I've used Bitwarden for years and didn't know about these 6 hidden settings that boost your security MakeUseOf 2026-10-06T19:30:14+00:00
  2. Set Argon2id as default KDF - Password Manager - Bitwarden Community Forums community.bitwarden.com
  3. Encryption Key Derivation bitwarden.com