Restricted access to Secure Notes (when phone is handed over to others)

Please consider adding a feature to the app, so if the phone gets handed over to authorities, and possibly retained for longer time (airports, border crossing, cops, etc.) or even to overly curious family members, or friends, the people having temporary possession of the phone would be limited in accessing only the information & attachments within the selected Secure Note, to which access was given through the suggested feature.

To be noted that most (all) Android phones already come with a feature called “App pinning”, which allows access only to a user’s selected app (referred to as pinned app). The suggested feature would only complement this Android feature to ensure that, when enabled, access would be limited ONLY to:

  • The Bitwarden app (through App Pinning) and
  • The selected folder/space within the app.

Note: this feature may be in high demand in the near future, as more and more official physical documents are being replaced by their digital versions.

A very good example would be a digital driver’s license and insurance pink slip. If presented in a digital form, the cops would likely take your phone and walk away with it to their car.

One thing to note is that IF the authorities would seize your phone and disappear with it you can log into your account on another device and revoke/close ALL active open sessions. Of course this means BW on the seized phone is logged out and the Master Password is the only way back in.

In the speeding ticket example you gave you could download a copy of those documents from BW vault to your “downloads folder” and then logout of the BW app. This way LE can see your driver’s stuff and when they give your phone back you can wipe the documents folder. Just a thought.

For family members you simply “lock” BW so a PIN would be needed for them to access BW and then hand them the phone. BW is always locked on my Android and entering a PIN is quick and easy.

Strictly speaking as a security freak I would rather carry a paper driver’s stuff and NEVER hand my phone to LE unless it is in BFU status ---- > before first unlock!

1 Like

None of the comments really address the suggested feature. I’m talking practical applications where all you want is to hand over the phone, with the required document on the screen, while also making sure that no other areas/folders/apps of your phone can be accessed by that person.

In the 1st example you’re talking about locking your BW account from another device - totally impractical in such situations. Moreover, my concern is not only BW, but the entire phone.

In the 2nd comment, what would be preventing anyone from searching your phone outside the Downloads folder? Besides, Android’s pinning app feature work with a specified app. In order to allow access to the Downloads folder you would have to pin either a Gallery type app, or a File Explorer app and the problem remains the same. Nothing would stop the person from browsing your entire gallery, or files.

Same with the 3rd comment.

So, to reiterate, the feature would complement App Pinning and it would have to be some sort of “pinning” within BW itself.

… one general question/thought to this:

You can’t open any attachments in the mobile app. Only download an attachment.

So, if you would restrict access to a Secure Note… one couldn’t look into any of those attachments, regardless of the file type (PDFs, images, …).

Yeah, but as I wrote before - then you would have pinned the Bitwarden mobile app (and that “restricted to a secure note”) - but no attachments could be opened then.

So, I’m not sure you would get what you want with this feature…

PS: Nevertheless, I changed this from “Ask the Community” into a “Feature Request” for now.

In general, yes. But that only works, when the app can receive that command, i.e. when the phone is still connected to the internet.

That’s a very good point and, in fact, I was afraid that would be the case.