Fer cryin’ out loud.
When will we be able to mask our email from showing just because we opened the app?
What if I begged ‘pretty please’?
Fer cryin’ out loud.
When will we be able to mask our email from showing just because we opened the app?
What if I begged ‘pretty please’?
I think this is a real issue, since someone with our account email could erase completely all of our data.
At least it’s what is said on bitwarden help pages for someone who have forgotten the masterpass and wants to delete all data. The only field required for account elimination it’s the account’s email.
So if this is true, it’s very dangerous to have our account’s email exposed.
I think 2 solutions should be implemented and the user could choose what better fits his needs:
#1
having the email hidden between " * " and that the user could program in which letters the * is placed. Example: for me could be better: [email protected] for another person could be better:
[email protected] , for a third person could be better: e****@provider.com , in order for the better way one could remember his email login
#2
the user/alias methood already proposed by the bitwarden team
I think booth solutions should be availabe suiting different needs
But they would also require access to your email account to receive and respond to the account deletion confirmation message before your BW vault contents were destroyed. Simply knowing your email address would not be enough to delete your account.
Has this topic been abandoned? It’s been a year since @tgreer announced we will have the option to show/hide our email but the issue hasn’t been solved yet.
Hey @mcast thanks for following up, looks like this one was based on a community pr, I’ll dig around and see if I can find the community PR referenced above.
@bw-admin this is what I mean
Thanks! I read that earlier, just seeing if I can track down the actual community pull request on GitHub that was mentioned to see what state the work was in.
Please, please, please, can you commit the code PR that has been mentioned to allow this? Pretty please? With a cherry on top!
We will love you forever! We will name our unborn children after you!
On a slightly more serious note, I thought one of the most important security mantras nowadays was “zero trust”. Surely an option to hide your email address should be one of the most fundamental options of a security focussed password manager. What if I unfortunately must sign in to bitwarden from a work environment, a shared computer? Many people are in that boat. I don’t trust other people who (do) login to my work computer. I don’t want my work mates to know that there is even a possibility that my passwords could be accessed by any means on a shared computer. I don’t want the IT guys who backup my work computer to know that it was me who logged in to a password manager. I want the option to be fully and completely anonymous, even if they are watching my session via some sort of remote monitoring tech, which they can.
Thank you for any help you can offer in this area.
I agree with using user-configurable account nicknames X for the “Logged in as X on Y” messages as an effective solution to privacy vs. ability to tell which account is logged in. The default value of X can be the email address, but security-conscious users could set X to a nickname. Especially for self-hosted users, it may also be nice to have the ability to display a nickname for the server domain (Y = ‘bitwarden.com’).
I think that together with the already available option to uncheck “Remember email” on the login screen, this should take care of all concerns about exposing the email address. The only other reasonable enhancement to accommodate the super-paranoid would be to provide a show/hide option for the Email Address filed on the login screen.
Anything beyond that would not really be reasonable, since the email address is stored in plaintext in the .json file.
Hi All,
Please add an option to disable “Logged in as XXXX on bitwarden.com” message in all Bitwarden apps (web, mobile, desktop).
This is for privacy reasons: if someone will use the same device for whatever reason, then they can easily see which email is linked to our Bitwarden account.
Why should someone know this? - we already know our email address and it should not be visible for anyone else as it can potentially create a weak point, especially, if 2FA is not enabled, etc.
It is a good privacy practice to keep a separate email for each sensitive category (banking, password managers, etc) so we should have an ability to disable that message altogether so that no one will see the email which is linked to our account.
Corporate users or other users who need this message can still enable it from within settings so it should be optional.
Thanks!
On the Windows Desktop client, the registered email address appears in the upper right corner.
I would like to see an option in the settings to not display it.
bitwarden is awesome.
kinda sad that lately, all of a sudden, the email of the signed out user still appears in the addon (firefox in my case) and even when clearing all the history.
maybe i missed the option or maybe the feature for hiding/forgetting the email is not released.
can someone please clarify whether there is an option to forget/hide/remove the signed out user email address?
thanks
Hey @c5b007bf96b2 are you using a personal or public machine? It is worth noting that if you have Chrome or Firefox profile if a user taps those fields in your browser UI, it will show your account email as well.
I’d sure like to be able to clear the email address of the last logged in Bitwarden user from the login screen on both the web cleint and the mobile clients. No one except me needs to know what email address I use to get into Bitwarden. Can someone give a convincing argument otherwise?
Hey @MtnRanch with the latest update, when you log out, there is a checkbox ‘remember email’ that you can clear/select before logging back in
Thank you, it works on the browser extensions but the Android mobile app doesn’t want to forget me.
On the browser extention, even with the “remember email off”, the browser’s autocomplete remembers previous entries in that username field which makes it trivial to discover names that have been used for login. Is there any way to overcome this without turning it off for all browser functions?
Thanks, this will be coming to mobile in a future update
Does this include browser extensions and desktop?
The Chrome extension still displays the following message while locked, even when ‘remember email’ is disabled:
Your vault is locked. Verify your identity to continue.
Logged in as [my email address] on bitwarden.com
Is there an new option to obfuscate or remove my email address from being displayed that I’m overlooking?
I believe that displaying the account’s mail in the browser extension is not safe, you need to give it the opportunity to replace it with another name in the extension settings or the account itself.