The panel fetched the PIN blob and decrypted it itself, then reported its own failures. The lockout therefore counted only what a well-behaved panel chose to report, a 15-minute timer handed out five more guesses forever, and anything able to run in the panel could take the blob and search the million PINs offline in minutes. The blob now never leaves index.js: pinSet builds it after checking the master password against the vault, pinUnwrap counts each guess before trying it, and five wrong guesses switch the PIN off until the master password is entered. The panel keeps its PIN pads and only sends digits. A blob from an older build (200k iterations) is re-made at 600k under a fresh salt on the next correct PIN. Only the topmost PIN pad listens to typed digits, so two stacked pads cannot both take one entry. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||