enpass-cli icon indicating copy to clipboard operation
enpass-cli copied to clipboard

PIN length should be 4 characters

Open rdiezsj opened this issue 3 years ago • 1 comments

A minimum PIN length of 4 characters is set in the Enpass app itself. cli access should keep the same length

rdiezsj avatar Sep 06 '22 14:09 rdiezsj

The PIN works differently in the GUI app, there the vault is kept open in memory. enpass-cli instead writes the encrypted derived database key to (ram)disk (see #110 for more information). An attacker getting access to this file would find it trivial to brute-force a 4 character PIN.

msladek avatar Mar 01 '23 11:03 msladek