5 ms·
Hi oefra! Thanks for the feedback. We wanted to provide the same security pattern that iPhone's provide - 4 digit, 6 digit and alphanumeric. This gives the user
by daniel_sushil 6y ago
Hi oefra! Thanks for the feedback. We wanted to provide the same security pattern that iPhone's provide - 4 digit, 6 digit and alphanumeric. This gives the user the power to determine their own security depending on the type of information they are planning to store. Also, based on the overwhelming feedback here on security details, I think we will publish a white paper soon to make it more clear :)
- nicoburns 6y agoSo it's not military grade? It's average clueless user grade? Isn't the value of product like this to provide good security without the user having to be an expert?
- fastball 6y agoTo be fair, military personnel can use bad passwords too.
- GordonS 6y agoSure, but any internal systems they use will (should) prevent really bad passwords from being created in the first place.
- oefrha 6y agoAES256+PBKDF2 does qualify as "military grade" in the security marketing space, AFAICT. Which is pretty meaningless. You can have the best cipher, and the best KDF, but nothing would save you if your key is derived from "1234".
- oefrha 6y agoThere's nothing wrong with allowing a 4-bit passcode. The problem is that you're claiming "no one, not even SecureAppy can unlock or see your data" which is just not true when the user uses a 4-bit/6-bit passcode. Apple doesn't claim that. Not only should you not make a misleading security claim, I think the risk should be clearly communicated when users choose those options. The encryption may very well be sound, but it's only as strong as the passcode.
- Zitrax 6y ago4 digit maybe, 4 bit would just be 16 different combinations.
- gruez 6y ago>Hi oefra! Thanks for the feedback. We wanted to provide the same security pattern that iPhone's provide - 4 digit, 6 digit and alphanumeric. iPhone 4/6 digit passwords are secure because they require physical access to device, and they have anti-bruteforce mechanisms enforced by the security chip (eg. exponentially increasing timeouts after successive incorrect entries, "wipe device after 10 failed attempts"). Your SaaS solution provides none of that.
- daniel_sushil 6y agoHi gruez - we only store your passwords (encrypted) on your device. We don't store it on our servers. So anyone trying to hack should have physical access to your device to tamper with it. So basically they should be able to go through your iPhone passcode first even before they try to hack the app.