[QUESTION] Using fingerprint forces "QuickUnlock" which means someone has just to enter the last 3 characters if they don't have fingerprint access
question
Why when you enable biometric unlock with your fingerprint it asks for only the last 3 characters of your password? If someone stole your phone while you are unlocked (but hopefully not whith Keepass unlocked) then they could go to Keepass2android and just press cancel when asked to enter your fingerprint and just try to bruteforce the last 3 characters. I have tried disabling QuickUnlock but it still allows you to enter the 3 characters as an alternative to not using your fingerprint. Just allow us to use fingerprint without QuickUnlock so you have to enter the full password if you cannot provide a fingerprint otherwise this is a security downgrade there.
**What version of Keepass2Android are you using?**
1.14.-r0
关闭于 2026-04-27 3 条评论