A 6-digit PIN behind PBKDF2 + DPAPI falls in minutes to anything that can open DPAPI (malware running as the user, a disk image plus the Windows password). The PIN is now also the authorization value of a TPM key from the Microsoft Platform Crypto Provider; the key releases a secret mixed with PBKDF2(pin), so the stored blob alone opens nothing and the chip's own lockout (32 failures, then one per 10 minutes) limits guesses however the blob was obtained. Reached through Windows PowerShell's CNG classes with the PIN on stdin, so no native module. Machines without a TPM keep the software PIN, and Settings now says plainly what that protects against. A PIN is no longer stored when there is no real OS keystore (including Linux's basic_text backend, whose key is a constant); a pre-0.31 plain blob is sealed or deleted and remembered, so the panel can tell the user to change the master password if the profile was ever copied. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||