dkunzler / masterpassword

https://play.google.com/store/apps/details?id=de.devland.masterpassword
GNU General Public License v3.0
54 stars 11 forks source link

Anti Brute-Force identicon #28

Open dkunzler opened 6 years ago

dkunzler commented 6 years ago

Quote

The verification emoticon can actually be used for a brute-force attack if someone's recording your phone screen (guessing one character at a time is extremely easy compared to brute-forcing the entire password). Then again, it'd be a problem on mobile anyway because of the last character showing up as plaintext for a while, but a fix would nevertheless be welcome in the desktop versions. Maybe show a random emoticon for a while before switching to the legit one? That's what another, similar app does.