mooltipass / minible

Github repository containing the firmwares running on the Mooltipass Mini BLE
GNU General Public License v3.0
94 stars 20 forks source link

Automatically lock on bluetooth disconnection #408

Closed hoijnet closed 8 months ago

hoijnet commented 9 months ago

Missing feature

Add an option to automatically lock the device upon bluetooth disconnection (if the device is connected to a device).

Justification

I tend to have my Mooltipass connected to my computer by USB and it's not unreasonable to expect that users sometimes forget to bring the device or the smart with them when they lock their screen.

It would be amazing to use the bluetooth connectivity to automatically lock the device when disconnected due to out of range.

This would be a safety measure as a last resort, but to ensure the device is not left logged in by mistake, or when the USB disconnection does not trigger locking which happens sometimes.

Workarounds

Bring the smartcard with me.

CGuy-1 commented 8 months ago

There is another option you can use: image The wake time on the Mooltipass is fairly short, so this could be an option.

Bringing the smartcard with you is the most secure, they really shouldn't be left together unattended. If nothing else your card could be killed by someone playing with the dial and entering multiple bad PIN numbers.

hoijnet commented 8 months ago

Smart! Of course, even better. And I agree the smartcard should not be left with the device unattended, for many reasons.

As the pin is displayed on screen, it should be noted as a risk that is can be seen by others. The real security is is in the smartcard that should be carried!!

As this solves the issue, I'll close this one!

CGuy-1 commented 8 months ago

Yes viewing the PIN is a known security risk which is why you might want to enable Random Starting PIN. This will prevent a user from counting the wheel turns to deduce the PIN number. It is necessary to shield the display from prying eyes as you enter it.