Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Master Password clear after > 20 seconds v2.7.8 #10695

Closed
K4UwgcIIuChWSIgrWKFITFUDuJeY1i opened this issue May 7, 2024 · 12 comments · May be fixed by #10708
Closed

Master Password clear after > 20 seconds v2.7.8 #10695

K4UwgcIIuChWSIgrWKFITFUDuJeY1i opened this issue May 7, 2024 · 12 comments · May be fixed by #10708

Comments

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i

Please review the video capture for detail.

Master.Password.clear.after.30.seconds.v2.7.8.mp4
@phoerious
Copy link
Member

Not sure what exactly you are trying to show. The password is cleared after 30 seconds for security reasons. That is intended.

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i K4UwgcIIuChWSIgrWKFITFUDuJeY1i changed the title Master Password clear after 30 seconds v2.7.8 Master Password clear after > 20 seconds v2.7.8 May 7, 2024
@droidmonkey droidmonkey closed this as not planned Won't fix, can't repro, duplicate, stale May 7, 2024
@K4UwgcIIuChWSIgrWKFITFUDuJeY1i
Copy link
Author

Not sure what exactly you are trying to show. The password is cleared after 30 seconds for security reasons. That is intended.

This does not happen to v2.7.7 which is the version I have to come back. I couldn't find what you mentioned in the change log.

@phoerious
Copy link
Member

This was implemented a long time ago. We didn't change anything about it in 2.7.7 or 2.7.8.

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i
Copy link
Author

This was implemented a long time ago. We didn't change anything about it in 2.7.7 or 2.7.8.

I assert to you this does not happen to version 2.7.7 & a few versions before.

Please see the screen capture video. I can leave longer but will affect the video size.

v2.7.7.mp4

@droidmonkey
Copy link
Member

droidmonkey commented May 7, 2024

This feature was actually broken in 2.7.7 and I fixed it for 2.7.8. It's been working for all versions prior to 2.7.7. It's a security feature.

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i
Copy link
Author

This feature was actually broken in 2.7.7 and I fixed it for 2.7.8. It's been working for all versions prior to 2.7.7. It's a security feature.

Thank you for your response. It's good to know it's been fixed.

However, it appears that feature does not work in versions 2.7.5 and 2.7.6 on my end. You can watch the video I sent.

For those of us who use the Diceware approach, 30 seconds is insufficient to enter the master password. Although KeePassXC's character input speed has been quite helpful, I still need to choose at least ten entries to enter the master password.

It would be ideal if there was an option to change the time it takes to clear the master password.

Hope you can assist. Thank you.

v2.7.6_v2.7.5.mp4

@phoerious
Copy link
Member

Why do you need more than 30 seconds to type your password? Even with slow typing speeds it shouldn't take that long to type 7-10 words.

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i
Copy link
Author

I utilize KeePassXC's auto-type speed to enter the master password. I, like you, use ten words to remember my master password, however my real master password is somewhat weird.

  1. 66635 zebra
  2. 66636 zen
  3. 66641 zeppelin
  4. 66642 zero
  5. 66643 zestfully
  6. 66644 zesty
  7. 66645 zigzagged
  8. 66646 zipfile
  9. 66651 zipping
  10. 66652 zippy

My master password comprises of the above ten words.

  1. Locate entry 66635 and use auto-type to enter its password into the master password.
  2. Next is entry title 66636, and so on till 66652.

As you can see, I had to switch between the two KeePassXC programs to enter the master password. So I only had 3 seconds to find and enter the proper entry number (out of 7776 entries). But I failed to mention that I also utilize key file. It takes considerably longer to identify the correct location containing the key file.

@phoerious
Copy link
Member

phoerious commented May 8, 2024

That sounds incredibly over-engineered. I suggest you just use a normal 10-word passphrase and remember it, write it down somewhere safe, or store it in your other password database. You don't have to torture yourself with this theatre. It doesn't do anything except wasting your time.

@droidmonkey
Copy link
Member

Or use auto open feature since you are going from one database to another anyway

https://keepassxc.org/docs/KeePassXC_UserGuide#_automatic_database_opening

@K4UwgcIIuChWSIgrWKFITFUDuJeY1i
Copy link
Author

That sounds incredibly over-engineered. I suggest you just use a normal 10-word passphrase and remember it, write it down somewhere safe, or store it in your other password database. You don't have to torture yourself with this theatre. It doesn't do anything except wasting your time.

I will consider this. Thanks.

Or use auto open feature since you are going from one database to another anyway

https://keepassxc.org/docs/KeePassXC_UserGuide#_automatic_database_opening

Thank you for the instructions. My Master DB uses this feature to open other necessary DBs.

I and many others are grateful to your team for creating a great product. Wishing everyone good health and success.

@droidmonkey
Copy link
Member

Btw, thank you for reporting this you did find an actual bug, fix is in the linked PR.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants