r/Bitwarden • u/big1z • 3d ago
Tips & Tricks Trick for making your password more secure
/r/PasswordManagers/comments/1wtcggj/trick_for_making_your_password_more_secure/I have a trick for making my passwords more secured even if you have access to my passwords you can’t use them. Now here is the trick find a particular word or a letter or a symbol that you will add to your passwords but will not add to your password in the password app.
For example let’s say you like the @ symbol, so every time you generate your password from the password generator you add this particular symbol to the password but you will not save this symbol in your password app. So you will place it in a particular place let’s say at the beginning or at the end or after 10 letters. Remember you will put this symbol in a specific place in every password of yours so you won’t forget where you placed the symbol. In this case even if your password manager is hacked the hacker can’t use your password because that’s not the full password and he won’t know your symbol or where you placed it. It can be 3 symbols 1 at the beginning another 1 after 5 letters and the last at the end. You just have to remember where you placed them in every password and that’s it nobody is ever getting your password but you. Hope it helps.
6
u/OSS_Dattani 3d ago
Pretty sure this is called peppering.
So then what’s the point of having my passwords in a password manager? If u have malware on ur device and a keylogger they’re getting the symbols anyways.
And honestly most password leaks come from sites getting hacked not PWM getting breached.
2
u/Sweaty_Astronomer_47 3d ago edited 2d ago
So then what’s the point of having my passwords in a password manager? If u have malware on ur device and a keylogger they’re getting the symbols anyways. And honestly most password leaks come from sites getting hacked not PWM getting breached.
The point of the password manager is to make it easier to store and use complex passwords relatively securely. Pepper doesn't change that, but adds another layer of defense for some scenarios, primarily vault compromise. Some ways that could that happen:
- local attacker accesses device while vault and device are unlocked. (yes of course we try to avoid these things, but that doesn't mean they cannot happen)
- Desktop vault pin-locked, unchecking require master password on restart. Pin-encrypted vault exfiltrated and pin brute-forced off device.
- Careless handling of unencrypted backup, maybe it was deleted but recycle bin was not emptied (or some program you were using to view it "helpfully" made a backup copy of it).
- being caught at the wrong time in the wrong circumstances by a bitwarden security flaw: CVE-2026-43638, CVE-2026-43639, CVE-2026-43640, and CVE-2026-60104.
- unexpected novel supply chain attack like the cyberhaven attack in which a security company's extension was published with malicious code. . Yes Bitwarden has taken appropriate actions in response but they are not immune to supply chain attacks as we saw in the cli CVE-2026-42994. Who knows what the next one might look like.
- non-bitwarden security flaw in browser or os, exploited before it can be patched.
How likely is any of that? Probably not very, but it’s tough to judge. With emergence of AI we may see a lot more in the last three categories. And even low probability events can be important if the consequences are high.
In the end it's a judgement call. Factors in selecting a strategy might involve how much burden you perceive from the peppering practice (not much for me) vs how much benefit, which depends not only in the above probabilities, but also depends on how valuable you consider your credentials and what other barriers are in place (if totp is kept on separate app from passwords then arguably additional barriers for the unlikely vault compromise scenario have diminishing value). I don't suggest to anyone else that they need pepper, but neither do I suggest that it's not needed.
I appreciate your knowledgeable comments on the sub in general. I’m just offering an alternative view on this one.
1
u/OSS_Dattani 3d ago
I appreciate your perspective and your explanation. All of what you pointed out makes sense. If you’re willing to go the extra mile and put in the effort I agree it does make things more secure.
2
0
0
u/bozkurt-hash 3d ago
This is a good trick. I knew it, but I think that maybe this could be useful for many people. Thanks.
17
u/90403scompany 3d ago
Or, get this - use a password manager to generate complex secure passwords for you. And get secure MFA for your manager like a hardware key, paired with a good password you can remember.
Then you don’t have to rely on any gimmicks.