Passwords and Bitwarden — The Rules, and How to Actually Use Them
Password rules feel arbitrary until you know what they’re defending against. This article covers both halves: why the rules are what they are, and how to use Bitwarden so following them costs you nothing.
The rules
Long beats complicated. Length is what makes a password hard to crack. Four unrelated words are stronger than one word with symbols substituted in — and far easier to type on a headset call.
Never reuse a password across systems. This is the one that matters most. When any website is breached, the stolen email-and-password pairs get tried against everything else. A password you reused on a shopping site three years ago is a live key to your work account today.
Never share a password. Not with a colleague covering your break, not with a team leader in a hurry, not with anyone who phones claiming to be IT. Shared credentials destroy the audit trail, and anything done under your login is attributed to you.
Never write one down. Not on paper, not in a phone note, not in a file. This is what Bitwarden replaces.
Don’t let the browser save work passwords. Browser password stores are weakly protected and travel with the profile. Bitwarden is the approved place.
MFA everywhere it’s offered. A password on its own is one thing an attacker needs. MFA means stealing the password isn’t enough.
Why we don’t force monthly changes any more
Frequent forced changes made things worse, not better. People responded predictably — Harare2024! became Harare2025!, which is no harder to guess, and more people wrote passwords down because they couldn’t keep up.
Current guidance is long, unique passwords, changed when there’s a reason to. Reasons include: you think it may have been exposed, you shared it in a moment of pressure, or IT tells you to.
Bitwarden: what it’s for
Bitwarden is a vault. You remember one master password; it remembers everything else and fills them in for you.
That’s the point. Once you’re using it, “long and unique for every system” stops being a burden — you never type those passwords anyway.
Getting set up
- Open the Bitwarden browser extension.
- Sign in with your Invarium account.
- Set your master password. Make it long — a phrase you’ll remember, not a word with symbols. Nobody can recover it for you, including IT. If you forget it, the vault is gone and everything has to be reset.
- Enable MFA on the vault itself.
Day to day
Saving a login. The first time you sign in to something, Bitwarden offers to save it. Say yes.
Filling a login. Click the extension icon on the login page and choose the entry, or use the keyboard shortcut. Don’t retype passwords by hand — autofill also protects you against lookalike sites, because Bitwarden won’t offer a saved login on a domain that doesn’t match. If it doesn’t offer to fill on a page you expected, treat that as a warning rather than an inconvenience.
Generating a password. Use the generator in the extension rather than inventing one. Take whatever it produces; you’ll never type it.
Sharing a credential legitimately. Some team or system accounts genuinely need to be used by more than one person. Those go in a Bitwarden collection managed by IT, so access can be granted and removed without anyone knowing the actual password. If you’re sending a credential over WhatsApp or email, stop — log a ticket and we’ll set up a collection.
When something goes wrong
Locked out. Wait fifteen minutes before retrying; most lockouts release automatically and retrying restarts the clock. While you wait, check whether an old saved password in the browser is retrying in the background — that’s the usual culprit.
New phone, or lost phone. Log a ticket for MFA re-enrolment before you wipe or hand over the old device if you still can.
MFA prompts you didn’t trigger. Don’t approve them. That means someone has your password and is at the login screen right now. Deny it, then phone IT immediately.
You think you gave a password away. Report it before changing it. We need to know which credential and when. We’ll reset it within minutes.
The rule that covers the phone calls
Nobody from IT, from a bank, or from any legitimate service will ever phone and ask for your password or an MFA code. Not once, not under any circumstances, however urgent it sounds.
If someone does, hang up and report it.
Read next: How to Spot a Phishing Email, and Reporting a Security Incident.
Watch: Bitwarden 101 — the vendor’s own walkthrough of saving and filling credentials. Then what MFA is, which runs about a minute.

