Remember-me sealed the master password with whatever safeStorage offered, which on Linux without a keyring is a constant key, i.e. the password in the clear in the add-on store; and it stored any string without checking it. It now uses the same keystore test as the PIN, verifies the password with the vault first, and drops a blob sealed under no real keystore. Settings says that remember-me leaves the master password readable to anything running as the user, which the PIN's TPM protection does not change. |
||
|---|---|---|
| .. | ||
| aegis | ||
| blocker | ||
| consent | ||
| docx-editor | ||
| notepad | ||
| pdf-editor | ||
| pithos | ||
| screenshot | ||
| translate | ||
| vpn | ||