flipperzero-firmware icon indicating copy to clipboard operation
flipperzero-firmware copied to clipboard

Flipper should auto lock (when enabled) on turn on, and on use of 2FA key.

Open robot-penguin34 opened this issue 1 year ago • 1 comments

Describe the enhancement you're suggesting.

The flipper zero currently does not seem to lock after a power on, nor does it ask for a passcode when using 2FA keys.

Why is this important: The flipper is meant to be a device you bring everywhere with you, and as such malicious actors may be able to access your 2FA key, and using almost any other information about you (see oosint videos), log into whatever account you signed in with. Making this highly useful feature almost useless, maybe even a security risk.

Please consider this great enhancement

Anything else?

Please also consider a feature to wipe the device after X failed passcode attempts.

For the devs who are constantly giving their time to work on this project: I am trying to learn C so I can contribute to requests, rather than add to the load. Thank you for your constant work.

robot-penguin34 avatar May 28 '24 06:05 robot-penguin34

Devs, again thank you for your constant work.

robot-penguin34 avatar May 28 '24 06:05 robot-penguin34

doesn't the flipper zero already natively support a pin code with the option to factory reset

Tohkie avatar May 29 '24 17:05 Tohkie

@Tohkie in response to your question:

On inspection going to settings > desktop (where you configure you pin, and other related content) there does not seem to be an option to reset the device with failed attempts. It does however mention that you will need to manually reset it if you forget your code. Unless there is a piece of code that puts your device in a secure state after enough attempts (like iOS), the pin is negligible.

(Thanks for your engagement in this topic)

robot-penguin34 avatar May 30 '24 12:05 robot-penguin34

To be honest Flipper is not a replacement for security keys and never will be.

Wiping device doesn't make much sense without full disk encryption for SD card. There is a prototype of full disk encryption that I've made, but it will require sacrifices of performance and usability.

skotopes avatar Jun 02 '24 16:06 skotopes

No worries. Honestly, it would be considerably hard to figure out the account the key is paired with. Again, thanks for your work.

robot-penguin34 avatar Jun 03 '24 04:06 robot-penguin34