When copying sensitive data (e.g. passwords) from password managers, it’s shown in the clipboard content field, which makes masked password fields kinda useless.
If we have option to mask or completely disable this field, someone might decide to permanently turn this on for security reasons.
Although the ability to see the contents of the clipboard can sometimes be convenient.
ownKeepass does this. Well, it erases password entries from the clipboard after X seconds (configurable).
It’s in Chum.
That is not exactly what this request about. When you paste password from ownkeepass you still see it in the clipboard window
Do you mean that clipboard-text that is displayed at the top left of the display-keyboard?
But how should the poor clipboard know it’s keeping a password and not some innocent other text?
That is exactly it. It disappears after first paste action, but using this as a workaround to paste password doesn’t seems to be a good UX
Well, we might come up with some wild ideas here, but it’ll be much easier to have an option to completely disable this field altogether.
By adding some kind of metadata to it.
In this case it’ll be on app to set it, which will require update on the apps’ side. And it probably won’t work for android password managers.
Android does it already, I assume it could be bridged.
Great! Then metadata is indeed the best way to approach this
Don’t show it to anybody for 30s.
This is the salient question, and it has been discussed ad nauseam ever since clipboards & managers were a thing.
There is no good solution for this. Hm, apparently Android found one. I stand corrected but remain skeptical.
Not a great plan.
I believe it’s ClipDescription.EXTRA_IS_SENSITIVE flag?
Please consider that it is only out of sight but still on the clipboard. You can paste it more than one time. And if you swipe to the right on the clipboard icon the stored text will appear again.
It never trully disappears. It just slides left out of view, but you can slide it right back into view.
Nevermind… Someone else already mentioned this.
OK so what exactly is your threat scenario here?
Simply working with sensitive data in public places. Especially when surveillance cameras are becoming a new norm in some countries.
How insanely good did surveillance cameras became, if they can spot a password on a phone’s keyboard ![]()
So, do you think that showing passwords in a phone’s screen is not a security threat and all these masking efforts are for nothing? ![]()
Well if that’s the case why do we mask passwords in password fields at all?
Yes cameras can do this. There are places where a camera might be as close as a few metres from you (in the train I take for my commute for example), and there certainly are security cameras with very high resolutions, though you probably don’t see these as often cause they’re expensive.
Also, besides cameras, someone could just be looking over your shoulder.