Skip to content

deal with the distinction between CredRandomWithUv and CredRandomWithoutUv to avoid losing access to vaults when authenticator PIN is added #6

@glyph

Description

@glyph

Per this comment:

keepassxreboot/keepassxc#9506 (reply in thread)

The user's hmac-secret key may change if the user adds or removes a PIN from the device. I think that tokenring currently does not take this into account, which could hypothetically result in a user creating a token vault, adding a PIN to their authenticator, then losing irreversibly losing access to that vault.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions