Hacker News new | ask | show | jobs
by e12e 1187 days ago
With a secure enclave of some kind, there could conceivably be a three attempt limit before the temporary key associated with the pin is deleted, and full pass phrase is required. In such a setup pin might make sense.

As it is - I'm not sure if pin makes sense even if there's user demand? Then again I do use biometric unlock - and that's not really great either.

At least the bitwarden installs are behind fde (macOS) - and possibly (?) file based encryption (Android 13+).

1 comments

If the user setup the PIN and uses it every time the chances that they know the master password is about 50/50.
50/50 chance the pass phrase is secure against keylogger!