When I use Bitwarden onAndroid, is there a security risk that someone can "see" my master password as I enter it?

Hello, I am very much a noobie. Just recently began to figure out some things when using the Bitwarden Microsoft Edge extension and also the Bitwarden web page.

I have loaded the Bitwarden app onto my Android cellphone and am concerned that my master password is vulnerable for bad actors to see. As I enter the master pw in the Android app, is there a danger for someone to see it?

All comments and suggestions are welcome. Thank you.

As I enter the master pw in the Android app, is there a danger for someone to see it?

I don’t think so unless somebody is looking over your shoulder. :slightly_smiling_face:

Most of us Android users enter the master password once in the app and then we enable biometrics so we don’t have to enter it again.

RogerDodger: you replied “I don’t think so unless somebody is looking over your shoulder.”

Kindly help me understand. Suppose I am at my doctor’s office and I need to connect to my Walgreens phone app to order something. I would be using the doctor’s WiFi to connect. So, if I type in my master password, will it not be exposed to someone malicious on the doctor’s WiFi?
Are you suggesting that I connect to Bitwarden from the safety of my home WiFI and enter the master password there? And then use biometrics or a PIN number to reestablish the connection to Bitwarden?

No, because of two reasons:

  1. Your password gets processed locally and never gets sent over a network.
  2. Even if your password would be sent to BW‘s servers, it wouldn‘t be really useful to attackers because all traffic is encrypted via TLS.

Basically, yes, but not so much because of a security issue (as @tomtom pointed out), but because it is much more convenient to just Lock Bitwarden and use Biometrics to Unlock. You can also set the Vault Timeout to a short time (5 minutes or less) to improve security, since it is easy to Unlock again with Biometrics.

You should also definitely turn on 2FA to improve security if you have not already done so.

1 Like

good info…I’ll read about 2FA in Bitwarden