Resource icon

Base domain versus Host versus Exact autofill matching

What it means​

Bitwarden's Base domain option matches a registered domain across subdomains; Host narrows to a hostname and optional port; Exact checks the full saved URI more strictly. The chosen rule can be set by item rather than applied to every login. This controls when a suggestion appears, not whether a website is trustworthy.

A real-world example​

A bank has a login at accounts.example-bank.test and a separate help site at help.example-bank.test. Host matching for the login avoids offering the credential on the help host, while Exact might be too restrictive if the login path changes.

What to do​

Save only verified login URIs, pick the narrowest rule that still works and test both the correct and an unintended host without entering a password on the latter.

The distinction that matters​

A legitimate site migration may break a narrow rule, and a compromised legitimate host can still look like a match. The browser address, transport and destination must be evaluated separately. An absent autofill suggestion is a warning to investigate, not a reason to paste the password manually into a page from an email. If an organization uses multiple legitimate login hosts, list them separately in the item after verifying each one rather than making the matching rule unnecessarily broad. Recheck the rule when the provider moves its sign-in page. Bitwarden URI match detection
Posted by
Jack
Views
2
First release
Last update

Ratings

0.00 star(s) 0 ratings

More resources from Jack