From 9afaffdbf0b1bf0870840f25d706363220b955e0 Mon Sep 17 00:00:00 2001 From: Kyle Spearrin Date: Wed, 24 Mar 2021 03:00:36 -0400 Subject: [PATCH] Lock with master password on restart disclosure (#511) --- _articles/account/unlock-with-pin.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/_articles/account/unlock-with-pin.md b/_articles/account/unlock-with-pin.md index fe877525..78f329df 100644 --- a/_articles/account/unlock-with-pin.md +++ b/_articles/account/unlock-with-pin.md @@ -57,7 +57,7 @@ To enable Unlock with PIN for your Desktop app: 2. Scroll down to the Security section and check the **Unlock with PIN** checkbox. 3. Enter the desired PIN code in the input box. Your PIN can be any combination of characters (a-z, 0-9, $, #, etc.). - {% callout success %}The pre-checked option **Lock with master password on restart** will require you to enter your Master Password instea of the PIN when the app restarts. If you want the ability to unlock with a PIN when the app restarts, uncheck this option.{% endcallout %} + {% callout success %}The pre-checked option **Lock with master password on restart** will require you to enter your Master Password instead of the PIN when the app restarts. If you want the ability to unlock with a PIN when the app restarts, uncheck this option.{% endcallout %} Your Unlock with PIN settings will persist **until you log out**. When you log out of your Desktop App, you'll need to re-enable Unlock with PIN. {% endcapture %} @@ -82,6 +82,10 @@ Your Unlock with PIN settings will persist **until you log out**. When you log o +{% callout info %} +When using the **Lock with master password on restart** PIN option, the Bitwarden application may not fully purge sensitive data from application memory when entering a locked state. If you are concerned about your device's local memory being compromised, you should not use this option. +{% endcallout %} + ## Understanding Unlock vs. Log In In order to understand why unlocking and logging in aren't the same, it's important to remember that Bitwarden [never stores unencrypted data]({% link _articles/security/vault-data.md %}) on its servers. **When your Vault is neither unlocked nor logged in**, your Vault data only exists on the server in its [encrypted form]({% link _articles/security/what-encryption-is-used.md %}).