SpiderOak / Encryptr

Encryptr is a zero-knowledge cloud-based password manager / e-wallet powered by Crypton
GNU General Public License v3.0
1.58k stars 138 forks source link

Feature request: Option to set login timeouts #246

Open revjim opened 8 years ago

revjim commented 8 years ago

I'm a new user to Encryptr (Linux desktop + Android mobile). So far I have found it very frustrating that every time I need a password, I click on my (open) Encrptr app only to find out my login has timed out.

I chose a very long, very secure password for my Encryptr account, so it's quite a hassle to type it in every time I need a password for a website. It makes it painful to log in to everything (especially on mobile).

I am coming from Passwordbox. The mobile app has an option "Use device security". When checked, you only need to login once and then never again. Since the phone is encrypted and locked down that is good enough for me. But if I had to type in my password again after each phone reboot that would be fine also.

I would like to request an option to use local device security and login only once. This should be "off" by default and only users comfortable with this setting should enable it. Alternatively there could be a variable timeout setting (with a zero option for never automatically logging out).

devgeeks commented 8 years ago

:+1:

I want to add this as well as touchID for iOS.

As long as the user is aware of what they are doing.

likethesky commented 8 years ago

👍 for touchID, as long as the UI affordance makes it clear to the user what they're doing, giving up, etc.; it'd be nice to have an option for the device security to expire too, ideally after a period of non-use, rather than a fixed period, like "Will expire after 24 hours of non-use" or something similar (where 24 is settable).