[Bug] Unlimited Pin / Fingerprint Unlock Tries #177

Closed
opened 2025-11-07 08:30:00 -06:00 by GiteaMirror · 1 comment
Owner

Originally created by @edsimpsons83 on GitHub (Jan 18, 2018).

I am classifying this as a bug since Apple and Google do (e.g. Apple CVE-2014-4451 - Unlimited incorrect pin attempts on iOS). Currently, if a pin unlock or fingerprint unlock is set on the mobile app, a user or attacker is allowed unlimited attempts to try and unlock the Bitwarden vault instead of being capped at a reasonable amount e.g. 5 before reprompting for the master password.

Originally created by @edsimpsons83 on GitHub (Jan 18, 2018). I am classifying this as a bug since Apple and Google do (e.g. Apple CVE-2014-4451 - Unlimited incorrect pin attempts on iOS). Currently, if a pin unlock or fingerprint unlock is set on the mobile app, a user or attacker is allowed unlimited attempts to try and unlock the Bitwarden vault instead of being capped at a reasonable amount e.g. 5 before reprompting for the master password.
Author
Owner

@kspearrin commented on GitHub (Jan 18, 2018):

Thanks. We already have this slated as a fix in next version with a limit of 10 attempts.

@kspearrin commented on GitHub (Jan 18, 2018): Thanks. We already have this slated as a fix in next version with a limit of 10 attempts.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/android#177