Skip to content
View in the app

A better way to browse. Learn more.

Enpass Discussion Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Fingerprint & PIN

Featured Replies

I really like enpass so much!

But there is a fundamental security problem with the biometric unlock.  face-id and fingerprint are not safe. you can hold someone's device in front of his face.  or you press his finger on the device.  We also leave fingerprints everywhere.  They are even stored in many ID cards.  

this is a fundamental problem to unlock smartphones in this way and not a probem of enpass itself. 

but enpass should be more secure. its a pitty, that you need only seconds to overcoming the biometric unlock and all passwords are open!

Enpass could become much safer with two very simple changes:

1. PIN & Biometric unlock at the same time.  Please change the Enpass app so that the PIN and the biometric unlock are possible at the same time.  Then a very short PIN could provide much more security.  I would use a three-digit PIN and set the number of failed attempts to 1.  After a single wrong entry, the master password must be entered.  An attacker who overcomes the biometric unlock would thus only have a 1: 1000 chance.  At the same time, the use of enpass remains very comfortable.

 2. We urgently need a time-out for the biometric unlock.  As in the desktop version, after a certain time (1 day) or when the device was restarted, the master password should always be queried.  So it does 1Password - why not Enpass?  It prevents attackers, who has captured the device from having all the time in the world to overcome the biometric unlock. 

Please implement this very simple features. You can set it by default to „only biometric unlock“ (without a pin at the same time) and set the biometric unlock timeout to „never“. So there will be no less comfort for people, that dont need higher security.

kind regards

Fabian

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.