trustcrypto / OnlyKey-Firmware

The OnlyKey Firmware runs on the OnlyKey itself and provides the core functionality of OnlyKey.
https://docs.crp.to/firmware.html
212 stars 40 forks source link

Feature Request- Random temporary password #166

Open rrottmann opened 10 months ago

rrottmann commented 10 months ago

Feature Request

I suggest adding a feature to the system where a dedicated button is available to generate a random static password. A short press of the button would automatically type the password, while a long press would generate a new one. The LED should show that it is a random password slot and another color or blink code that the key has been rolled.

Why?

Sometimes a password change ceremony has to happen where you generate a new password, manually insert it to a system and you want to guarantee that you have no knowledge of it. With this feature a second person could verify that a new password was entered and rolled on the Onlykey without revealing it to a human.

Also a user sometimes wants to have a short-lived password that gets frequently changed e.g. at the end of a session, the next business day etc. Having an option to do this on the key would save the user time and effort in generating and keeping track of the temporary password.