nextcloud / passman-android

:key: Android app for Passman.
https://passman.cc
GNU General Public License v3.0
92 stars 30 forks source link

feature request : Add biometric identification #171

Open grrosminet opened 2 days ago

grrosminet commented 2 days ago

Hi,

You should add biometric identification to make the app more comfortable to use. It's possible to store the vault password (!!!!) but it's a big security failure !

Thanks

binsky08 commented 2 days ago

Hmm, what exactly would you like to protect by biometric identification? You can already enable the android authentification ( which can be biometric - fingerprint or pin on my device) as app access restriction.

Since you can choose whether to store the vault password or not (disabled by default), it's not such a big security failure. The feature is also described in the faq here: https://github.com/nextcloud/passman-android/blob/master/FAQ.md#how-far-can-i-trust-the-local-storage-encryption-is-it-save-to-store-my-vault-password-on-the-device

grrosminet commented 2 days ago

Without biometric identification, you have the choice between :

With biometric identification , you don't have to worry about that

3 juil. 2024 12:45:30 Timo Triebensky @.***>:

Hmm, what exactly would you like to protect by biometric identification? You can already enable the android authentification ( which can be biometric - fingerprint or pin on my device) as app access restriction.

Since you can choose whether to store the vault password or not (disabled by default), it's not such a big security failure. The feature is also described in the faq here: https://github.com/nextcloud/passman-android/blob/master/FAQ.md#how-far-can-i-trust-the-local-storage-encryption-is-it-save-to-store-my-vault-password-on-the-device

— Reply to this email directly, view it on GitHub[https://github.com/nextcloud/passman-android/issues/171#issuecomment-2205769208], or unsubscribe[https://github.com/notifications/unsubscribe-auth/AAXQUK5STERFYLPKSWRIFI3ZKPI4NAVCNFSM6AAAAABKJFXGBOVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHMZDEMBVG43DSMRQHA]. You are receiving this because you authored the thread. [Image de pistage][https://github.com/notifications/beacon/AAXQUK45WUCIGFOSYE3FOPDZKPI4NA5CNFSM6AAAAABKJFXGBOWGG33NNVSW45C7OR4XAZNMJFZXG5LFINXW23LFNZ2KUY3PNVWWK3TUL5UWJTUDPFO7Q.gif]