sirAndros / KeePassWinHello

Quick unlock KeePass 2 database using biometrics with Windows Hello
MIT License
311 stars 21 forks source link

Add ability to verify origin of WinHello prompt #106

Open sirAndros opened 5 months ago

sirAndros commented 5 months ago

Currently any process on user machine can initiate WinHello prompt to decrypt stealed masterkey data.

Proposal: Add an entity to opened DB with user text and show this text when unlocking in WinHello windows caption. User then can verify if it his secret text and decide to trust or not to such prompt.