Quantcast
Channel: keepass2android Issue Tracker Rss Feed
Viewing all articles
Browse latest Browse all 955

Commented Unassigned: Database unlocking through fingerprint scan [229]

$
0
0
I own a Samsung Galaxy S5 and I would be very glad if it would be possible to unlock the database using the fingerprint scanner. In this way one could associate the database password to his fingerprint to unlock the database without any typing.

Comments: The way I understand it... 1) No Fingerprints and with QuickUnlock enabled: K2A stores the database fully unencrypted in memory, and remembers the last N characters as you typed it, also in memory. While the database is opened but locked it isn't encrypted by your Keepass password, but protected in memory by K2A using the last N characters to keep the database away from unauthorized users/apps. No part of the password is stored on disk. Just the last N in memory 2) Fingerprints Full FPUnlock: K2A uses Android's Credential store to keep the full database password. Not the app's datastore, and not in memory. Do you trust Google's devs to protect this store? If QuickUnlock is enabled, K2A still records the last N characters to store in memory. --Question: Does K2A have the database unencrypted in memory when in this state and not being used (screen locked, app timed out)? Or does it flush memory and behave more like starting over? 3) Fingerprint for QuickUnlock: The database is still fully unencrypted in memory... so the first part of the password is safely non-persistent. The second part of the password must be in memory for K2A to use it without a fingerprint. But also exists in the Android credential store. So only the last N characters are stored in both memory and in the Android credential store. ---------------------------- "I assume you experienced this in the QuickUnlock screen, right? In the Password Screen, this should not happen." This happens for both QuickUnlock and with the full password screen. I notice I have to lock the screen twice to make it lockout the reader.

Viewing all articles
Browse latest Browse all 955

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>