0xbb / otp-authenticator

A two-factor authentication App for Android
MIT License
160 stars 54 forks source link

Usage of credential storage is problematic #12

Open haarp opened 8 years ago

haarp commented 8 years ago

It seems this app uses credential storage. However, this has some (unintended?) results.

If a entry is added to the authenticator, it prevents the device from disabling the lockscreen (the option states "Disabled by administrator, encyption policy, or credential storage")

One can use "Clear credentials" under the Security settings to clear these, but that also clears all entries added to the authenticator.

This is quite unfortunate.

0xbb commented 8 years ago

Thanks for bringing this issue to my attention! My phone is encrypted/always had a lockscreen and therefore I never came across this thing.

So far having a lockscreen works for me and I don't want to promise a solution for this in the near future.

mueller-ma commented 7 years ago

This repo seems to be unmaintained, but there is a active fork, which is also in F-Droid: https://github.com/kckrinke/onetimepad