Privacy when using Website Icons

Category: Security
On this page:

    PassageWay does not collect any information when you download icons for website logins stored in your PassageWay vault.

    Using Website Icons

    When PassageWay displays a login item associated with a website in your Vault (determined by the URI field), it attempts to accompany it with a graphical “website icon”.

    Website icons help you to easily identify particular logins in your Vault by recognizable iconography, usually represented by a logo or brand image of that website. The PassageWay icons server provides the delivery endpoint for these website icons.

    If you are using website icons on a device, PassageWay will issue requests to icons.bitwarden.net for each item of type “Login” in your Vault that has a URI that resembles a website (ex. google.com or https://google.com, but not google or http://localhost).

    Privacy Concerns

    Because a request for an icon image contains the hostname of the website stored in your vault, it is important to understand that this feature will “leak” otherwise cryptographically protected information to PassageWay servers and/or CDN endpoints. An example of a icon request looks like the following:

    https://icons.bitwarden.net/google.com/icon.png

    The icon server endpoints do not log or collect any information regarding icon image requests. However, this is something you would have to take our word for since we have no way to demonstrate this publicly other than reviewing our open source codebase.

    Disabling Website Icons

    We understand that certain privacy-minded users may not want to use website icons. We provide the option to disable website icons on all Bitwarden client applications:

    • Web vault: Settings → Options → Disable Website Icons
    • Browser extension: Settings → Options → Disable Website Icons
    • Mobile app: Settings → Options → Disable Website Icons
    • Desktop app: Settings → Options → Disable Website Icons

    When website icons are disabled, PassageWay will opt to display a generic, locally accessed icon instead () for all login items stored in your vault.