I have used Bitwarden for years, and recently one issue has been bothering me: the email address visible on the unlock screen.
This may seem trivial and even obvious. Of course the email must be visible — how would you know which account you are signing into?
In recent weeks a stranger asked me for directions on the street, and to help I opened my phone while standing next to them. When I opened it, the Bitwarden mobile app was on screen and, fortunately, it had been locked automatically, so my passwords were not revealed, which is excellent — but the email I use to log into the app was visible. I do not believe that person would do anything with my email, but it still bothered me. You could say it was my fault for opening my phone near a stranger, and you would be completely right. Still, I personally think the app could offer a way to prevent accidents like this.
More recently, in a public place, I was about to open my vault using the browser extension when I noticed a camera pointed at me. Realizing this, I did not unlock the vault, but my email remained visible. Again, I should have been more careful, but I think a simple implementation would help inattentive people like me.
Personally, I have no reason to be excessively paranoid and, if this feature is not implemented, it would not harm me greatly. I know I am not someone anyone would want to spy on via security cameras to discover my private email, but I also know there are people who could be harmed by revealing a “simple email.”
My suggestion is to add, on the app unlock screen and in the browser extension, an option to hide the email which the user can click to reveal when desired.
Another suggestion is to partially mask the email on that unlock screen, for example:
original email: example.example@example.com
partially masked email: exa************le@**le.com
If the user wishes, they could also unmask it by clicking an icon to reveal the full email.
If this is a bad idea, please comment. Thank you for your time.