Optional PINs per volume, to protect volume passwords a little more#79
Open
marfl wants to merge 6 commits into
Open
Optional PINs per volume, to protect volume passwords a little more#79marfl wants to merge 6 commits into
marfl wants to merge 6 commits into
Conversation
added 6 commits
February 8, 2015 22:14
Work in progress... Done so far: once a volume's key is cached for the first time, the user can set a PIN. During unlocking, the cached key is used only if the correct PIN has been supplied. Needs a database update, so all existing volumes must be deleted and re-added manually (I think).
Also delete cached key on three failed attempts
The PIN and PINATTEMPTS columns should now be created on upgrade from older versions.
PINs were not deleted alongside passwords when password caching is disabled in the settings.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull requests implements the following feature:
With this, users can use secure (and thus hard to remember and type) passwords for their EncFS containers without breaking usability. Still, if someone snatches their device, they cannot simply look at all volumes. At the same time, some volumes that are accessed very often, like volumes with notes, can still be accessed quickly.
This is the same idea I outlined in the discussion for #13. However, I now believe that PINs per volume are a somewhat different feature than a PIN for the whole app and that both features could also coexist.
Last note: PINs and passwords are saved unencrypted in the database, so this is not a security measure against sophisticated adversaries.