Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Warning banner for individual 2FA entry exports #1069

Open
jonod8698 opened this issue Dec 24, 2022 · 2 comments
Open

Warning banner for individual 2FA entry exports #1069

jonod8698 opened this issue Dec 24, 2022 · 2 comments
Labels
proposal A proposal for a new feature

Comments

@jonod8698
Copy link

When the "Transfer Entries" feature is used, it would be useful it a persistent warning banner shows for a few days, similar to #132 which triggers on full exports in plaintext.

It's unavoidable to sometimes provide access to your phone (customs, police etc). In those cases you'd want to know if individual 2FA codes were exported.

I realise the Aegis app requires authentication to access it and locks with the phone. This feature would account for scenarios where users might not opt into encrypting the vault.

@jonod8698 jonod8698 added the proposal A proposal for a new feature label Dec 24, 2022
@alexbakker
Copy link
Member

Thanks for the suggestion. Google Authenticator has something similar. It's an interesting idea, but perhaps we can think of something a bit broader to cover all bases, not just the usage of "Transfer entries".

For example: We could also keep an audit log of every time the app was opened/unlocked. The reason being: If you give your unlocked phone to a someone else, then get it back and see a new entry in the audit log, you'll probably want to go ahead and reset all of your 2FA anyway, regardless of whether any entries were exported.

@jonod8698
Copy link
Author

I agree, an audit log could cover more scenarios:

  • transfer entries
  • reveal individual 2FA code (too verbose?)
  • export vault (encrypted/plaintext)
  • app open, success/failed authentication

A warning banner for "Transfer entries" is useful to warn users who aren't checking their audit log regularly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
proposal A proposal for a new feature
Projects
None yet
Development

No branches or pull requests

2 participants