scruffles360

scruffles360 t1_j1gymq9 wrote

That may be similar. When you go to a login page and LastPass tells you you have 4 accounts on that site.. it gets that information using the unencrypted URLs. It doesn’t log you into your vault unless you try to use one of them. (There are settings to leave you logged in, but they discourage that).

I’m going to have to do some research and see what’s out there.

1

scruffles360 t1_j1gs5fw wrote

I presume bitwarden doesn’t have any browser integration until the user logs in and asks for credentials?

I ask because that’s likely why LastPass doesn’t encrypt urls. When you go to a site, it knows it has a password and can prompt you to fill it. It’s a compromise in security for the convenience of browser integration. Whether or not it’s a good compromise is debatable but a lot of people are making it sound like laziness or a flaw. It’s most likely a usability choice.

3