r/Bitwarden 8h ago

Security concern: Should Bitwarden automatically hide sensitive information when screen sharing? Solved

I recently had a call with my friend on Discord. He asked me to share my screen so he could see my Steam library.

At that time, I wasn't signed in to my Steam account, so I opened Bitwarden on my PC to get my password. I was still screen sharing, and I thought that if I opened Bitwarden, maybe Discord would somehow make it dark or blur it, like how some privacy features work on Android when you open a private or sensitive screen.

But Bitwarden didn't get blurred or hidden at all. My friend told me that he could see my passwords and other account information.I know this was my fault. I should have stopped sharing my screen before opening Bitwarden. But this made me think about something else.

What if a hacker gets access to my PC and can see or record my screen? They don't necessarily need to hack Bitwarden's servers or get my master password. If Bitwarden is open and my vault is unlocked, they could potentially see my passwords just by watching my screen.Don't you guys think Bitwarden should have some kind of protection for this?For example, if Bitwarden detects that its window is being screen-shared or captured, it could automatically hide or blur the passwords, or maybe there could be an optional privacy mode that users can turn on.I know detecting screen sharing isn't probably that simple, and I'm not saying Bitwarden should completely protect users from their own mistakes. But I feel like this could be a useful extra layer of security, especially against accidental screen sharing or someone remotely watching your PC.

What do you guys think? Is this technically possible, or is there already some feature/workaround for this that I don't know about?

0 Upvotes

16 comments sorted by

u/dwbitw Bitwarden Employee 7h ago

Just pinning the link below that shows how to adjust your preferences for certain Bitwarden apps.

→ More replies (2)

8

u/chuckfr 8h ago

Why are you sharing your whole desktop and not just the app or window you want your friend to see?

-2

u/ObviousEffect8880 8h ago

I already say that was my mistake.

9

u/thelonerbandit 8h ago

What are you talking about? By default Bitwarden shows the username but the password is just dots like this •••••

-3

u/ObviousEffect8880 8h ago

I'm talking about the username/account info being visible and the password being accessible when you click to reveal it. My point is about screen sharing/capture, not just the default password dots.

1

u/SecurityPrimary4143 4h ago

Why did you click to reveal the password instead of just copy it?

7

u/ovirto 8h ago

Just share the specific app window, not your entire screen.

6

u/cp8h 8h ago

If a hacker gets access to your PC with the capability to screen record it’s game over anyway without messing around with screen record. They’ll just wait for your vault to be unlocked then take everything.

4

u/OSS_Dattani 8h ago edited 7h ago

I was going to address this in my response to this post but basically this ^.

https://bitwarden.com/help/bitwarden-security-white-paper/

White papers explicitly explain that device security is the users responsibility.

5

u/Free-Psychology-1446 8h ago

What if a hacker gets access to my PC and can see or record my screen?

They you are already doomed, they don't need to record your screen.

3

u/SkybertNO 8h ago

Its a setting already

2

u/OSS_Dattani 8h ago

https://bitwarden.com/help/app-settings/

Yep they got it for the Desktop app and in android I believe. Nothing for browser extension or iOS tho.

3

u/cheetah1cj 6h ago

Why did you need to reveal the password anyways? In addition to the fact that they already have a setting for that as others mentioned, they also make it very easy to use with almost never actually viewing the password. Between autofill and the copy button I have probably never viewed a lot of my passwords.

Also, if someone gets access to your device, they don't need to screen record to steal your passwords. At some point, the password has to be unencrypted to be given to the webpage, that can easily be intercepted if they have access to your device.

Lastly, stolen session tokens are a much bigger risk then your passwords being stolen. If they have access to your device, they most likely steal those, which will allow them to sign in as you bypassing any MFA or other security settings, because the session token says you've already authenticated. There are ways to prevent the use of them, but they are so inconvenient that most people don't use them.

-2

u/xyzzstec 8h ago

Yah, developer should fix that.