marius-wieschollek / passwords-webextension

The official browser extension for the Passwords app for Nextcloud.
GNU General Public License v3.0
103 stars 31 forks source link

Feature Request: Optional Pin/Biometric Lock after initial password sign-in #268

Open Saijin-Naib opened 8 months ago

Saijin-Naib commented 8 months ago

Current Status Currently, one has to put in the password every time the extension locks, or the browser is closed/re-opened.

With a randomly-generated password of 128 characters (Upper/lower case letters, numbers, symbols) this is incredibly tedious to type, and storing it anywhere else accessible is a huge safety/integrity risk.

Feature Description The BitWarden extension, for instance, supported optionally adding a device-local PIN (and/or Biometric) lock after initial setup, so that unlocking the extension wasn't as difficult, and security could be maintained.

Additional context This would align with BitWarden UX, and to an extent Mozilla FireFox.

marius-wieschollek commented 8 months ago

This sounds similar to this: https://github.com/marius-wieschollek/passwords/issues/353 . Are you referring to Passkeys/USB sticks/Windows Hello etc.?

Saijin-Naib commented 8 months ago

As an additional option, yes, as well as an option to be able to use a 4-character or longer numeric PIN.

Ark74 commented 6 months ago

Indeed a simple PIN quick unlock would be enough to secure the addon after some small time.