• 0xD@infosec.pub
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    2
    ·
    1 day ago

    That doesn’t really do anything. Attackers need local access to the device to get the database itself. Chances are, they’ll get the key right with it.

      • 0xD@infosec.pub
        link
        fedilink
        English
        arrow-up
        1
        ·
        1 day ago

        The passphrase or the unencrypted database are still open in memory. Though that is, of course, a more complicated attack but they could simply read it through the app itself.

        • HappyTimeHarry@lemm.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 day ago

          You can set it to wipe them from memory on different conditions, including instantly if youre that paranoid, sure its still possible. Its an optional feature most people wont use, but its pretty well thought out.