Skip to content
View in the app

A better way to browse. Learn more.

Enpass Discussion Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Is it Windows Hello safe?

Featured Replies

I am a happy owner of Enpas, but I have a question about unlocking with windows hello.

Is it safe to unlock with fingerprint windows hello?
When I unlock the database with my fingerprint, can same keyloggers detect the master password and the key file?

Thank you

  • 1 month later...

I would like to add a warning about windows hello setup. The link you proviced mentioned that Window Hello uses TPM to securely store key values. On older devices without tpm, that is not the case. When you enable windows hello, you are required to create a pin. If you have a Windows computer without TPM, the PIN value are stored in a secure location. The problem is that many of these machine probably also do not have disk encryption. You can buy an utility to bruteforce your pin.

https://blog.elcomsoft.com/2022/08/windows-hello-no-tpm-no-security/

I believe Enpass smartly forces you to enter the master password on startup if you don't have a TPM, so fortunately hacking the PIN will not allow them into the vault, but it would allow them to acquire the PIN to login.

There are two things you can do to mitigate.

1. Encrypt your drive, which should prevent access to the secure element.

2. Make a really long pin simialar to a good password using letter, numbers, and special characters. Most people don't know that you can use keys other than numbers. If you are using fingerprint, you would not need to enter the pin often.

Create an account or sign in to comment

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.