thomasorlita.com  ›  posts

Overriding Bitwarden's Chrome autofill integration to enable Google Pay

Use case:

For a long time, I thought this was not possible if you use Bitwarden. Until I looked at the source code.[2]

When you open the browser's setting page for autofill, the toggles for controlling the autofill options for passwords, credit cards, and addresses are all disabled with a message "Bitwarden Password Manager is controlling this setting".

Bitwarden has an "Make Bitwarden your default password manager" option in settings. But turning it on/off flips all of these settings simultaneously.

To disable the browser's password manager, but keep the Google Pay and addresses autofill enabled, I opened the Bitwarden extension popup, opened DevTools, and directly updated these settings:

chrome.privacy.services.autofillAddressEnabled.set({ value: true });
chrome.privacy.services.autofillCreditCardEnabled.set({ value: true });
chrome.privacy.services.passwordSavingEnabled.set({ value: false });

  1. Why don't I use Bitwarden's credit card and address autofill? I tried, it's almost unusable. In 99% of cases, the credit card autofill doesn't fill all three number fields. And enabling integration to render the autofill directly into the website's DOM will inherently always be super insecure. The browser autofill, on the other hand, is not part of the website's DOM, but a security-hardened browser UI surface. (I actually did a talk about this, showing ways to bypass these protections! But still, browser on-screen autofill overlays are much more secure in comparison just by the nature of it being a browser-rendered surface, not an element on a website.) ↩︎

  2. Looking it up again now, there is a post showing a different way to do this: by uninstalling the extension, enabling the options you want in the browser's autofill settings, then installing Bitwarden, but making sure to never click the "make default password manager" option. ↩︎