Open AlexanderWorking opened 6 years ago
Hello there!
We've actually a #define for that: https://github.com/limpkin/mooltipass/blob/master/source_code/src/defines.h#L207 but it hasn't been integrated in the main firmware yet mainly due to the fact that it takes rather a long time to input credentials this way.
We're however reconsidering this decision for the next gen mini!
@AlexanderWorking Would it be sufficient to have an Mooltipass app (Android/iOS) handle credential maintenance instead of on the device itself? My use case is using kiosk PCs such as in a hotel or trade fair.
<------------------------ FEATURE REQUEST ------------------------------------
Missing feature
It would be great it Mooltipass could be used without the supporting browser plugin and app.
This would require some added functionality in the Mooltipass firmware that allows the addition of new credentials. Name of website and username should be entered by the user using the scroll wheel. The password should be generated by Mooltipass. Once the credentials are added, the existing functionality would be sufficient to use these credentials.
The functionality could remain very limited as the preferred method of use would remain one where one would be able to install the plugin and app.
Justification
Increase market for Mooltipass Reason for this is that in many corporate environments it is virtually impossible to get this software installed. Corporations often take an "one size fits all" approach. To get software installed one would need to convince the IT department that they should roll this out to all users. As a user one does not have the required security permissions to install the plugin or app. Currently there is no good way of using Mooltipass in such corporate environment. If the suggested functionality would be added this could increase the sales of Mooltipass to the corporate market.
Increase security Another (secondary) reason for not using the plugin and app is that this eliminates risk of potential vulnerabilities present in the plugin and app. For me, this would be a serious consideration.
Workarounds
I haven't implemented this work around. But one could manage credentials on a different computer where the plugin and software could be installed. However the friction of this work around is to high. Also some (admin) sites I only want to access using the corporate computer, as using a different one would increase the attack surface.
Additional info
I've recently purchased 3 Mooltipass-mini's with the objective of evaluating the usability for our organization. If this request would be honored I would advocate we purchase some additional units.
<------------------------ END FEATURE REQUEST --------------------------------