⚡️ Quickstart: Fix your password habit with Bitwarden on desktop

A pile of keys, more than can be counted at a glance.
Photo by olieman.eth / Unsplash

As you follow this Instruction, you can also use the Table of Contents in the hamburger menu from the top right to navigate quickly.

To successfully complete this Instruction you'll need

  • A laptop, running either macOS (10.10 and above) or Windows 64-bit (7, 8, 8.1 and 10), and
  • A modern and updated browser running on that laptop.
Icon of checked box in brand blue.

By the end of this Instruction

You'll have set up a Bitwarden account on the free tier, and be ready to use a password manager to safely log in to all your services.

Icon of speech bubble with bleeped out swearing.

Helpful words

When we use words in a way that is unfamiliar, come back here then click through to an explainer in the Glossary.


Let's get started

Signup icon in brand blue.

A. Signup through the Bitwarden registration page

You'll need an account with Bitwarden to create, save, and recall passwords using the Bitwarden app.

  1. Open up your browser and go to https://bitwarden.com/.
  2. Click on the Get Started button, which will take you to https://vault.bitwarden.com/#/register.
Email notification icon.

B. Use the email you want to use for account notifications

You'll need to register an email address. Make sure it's for an email inbox you see regularly. When anyone (yourself included), logs into your Bitwarden password manager account from a new (read: unrecognized) client, you get an email notification. This is a useful security feature.

Icon of a vault.

C. Create a strong passphrase to use as your master password

With a password manager, you need to remember only one strong password. The password manager takes care of remembering the other long, unique passwords to all your logins for you.

📣 The CRA hacks happened because people reuse passwords. Here’s why, and how, to stop reusing passwords.
Many of us are not only using the same lock and key everywhere, it’s a lock and key we bought at the dollar store.

We'll use a passphrase as our master "password". Creating an Ideal passphrase is a Instruction by itself. We'll use a shortcut that will give you a good enough main password to start with.

  1. Look around and list 5 things you see.
  2. Drop the commas and spaces, then string them all together-you've probably got at least a 32 character password!
  3. Write the password down, as a backup.
  4. Use your newly created passphrase in the sign up process.

For example, you could right now be sitting outside a café facing a dog park. Looking around thoughfully, you might end up with the following words: labrador, steamer, tightrope, arabica, bench.

Your passphrase should be at least five words and at least 32 characters. That may sound long af, but your password manager needs to use a strong password. Ideally, the words are more random than what one could think of sitting outside café. To do that, we could create a master password using diceware, but that's outside the scope of a Minimum Grade.

It will take a few days to remember your master passphrase. Stash your backup copy of the passphrase somewhere safe, and slightly inconvenient to access. The irritation with having to get up and retrieve the note will eventually encourage you to memorize it. You won't even notice it happen :-)
Icon of verified email.

D. Log into your new web vault, and send yourself the verification email

Until you set up two-step login, be extra careful anytime you login to your web vault through your browser. Ensure that you're logging into the correct web vault.

Check the URL in the browser address bar to make sure the domain is correct. In https://vault.bitwarden.com the domain is bitwarden.com.

We once found a possible phishing website at https://bitswarden.com/. It's easy to miss the "s" after "bit".

Prompt Bitwarden to send you a verification email by selecting the Verify Email button located at near the top right Web Vault. Verify your new account using the email you receive.

Icon of arrow pointing downwards from a cloud.

E. Get the Bitwarden app for desktop, then login

The desktop app will let you access your passwords even without internet. You need the internet to synchronize passwords between desktop, web, and mobile apps.

Go to https://bitwarden.com/download/ and download the app made for your operating system.

Install it, then log in using your registered account.

Until you have memorized your master passphrase, make the app prompt you for the password twice or thrice a day. You can do this through the menu: Bitwarden -> Preferences -> Vault Timeout and set it to 4 hours.

Icon of software updating. Yes, I know that's not specific. Please use the tipline to give me better ideas.

F. Keep Bitwarden updated

Keep Bitwarden updated. Updates make Bitwarden safer against new threats, like vaccines do (but not the same way).

This is the easiest step. Bitwarden will automatically download updates. We just need to restart, to let it install, like we should be doing with browsers! Don't worry about keeping track, Bitwarden will tell you when an update is ready to be installed.

Icon of prize ribbon with star.

Now that you're set up with a password manager, you're ready to transfer some logins!

⚡️ Switch to a password manager: the easy way
Switch to a password manager, but do it gradually. Improving your operational security doesn’t have to be a huge chore.

Meta

Tools used

🛠 Bitwarden cheatsheet
Anyone can use Bitwarden. The password manager is particularly good for helping you remember good passwords and protecting you from password thieves.

Sources

  1. https://bitwarden.com/help/article/create-bitwarden-account/
  2. https://cyber.gc.ca/en/guidance/best-practices-passphrases-and-passwords-itsap30032
  3. https://www.getcybersafe.gc.ca/en/blogs/how-strong-your-password-five-ways-evaluate
  4. https://bitwarden.com/help/article/getting-started-webvault/
  5. https://bitwarden.com/help/article/getting-started-desktop