Tutanota: Add PIN/fingerprint unlock option to increase security

Created on 22 Aug 2018  路  11Comments  路  Source: tutao/tutanota

On the new Android/iOS apps can the option be added to allow a PIN/Fingerprint login to access the app once you save your main login on the device?

This just gives an extra layer of security without requiring full login/2FA authentication every time.

Lots of other apps support this including ProtonMail.

android ios new feature

Most helpful comment

Any news on this feature? I am currently using protonmail but I intend to switch over to Tutanota. This is the second TOP feature in my opinion that needs to be released soon ;-)

All 11 comments

@IOI-655321 this is possible but would require some works. There may be even an issue about this already.

Any news on this feature? I am currently using protonmail but I intend to switch over to Tutanota. This is the second TOP feature in my opinion that needs to be released soon ;-)

Yes, this function is needed.

Really, guys, there is totally no point in encryption at all, if user has no opportunity to set up pin or at least fingerprint protection on app.
Switched to tutanota from protonmail recently, and reaaly looking forward to see that feature!

Really, guys, there is totally no point in encryption at all, if user has no opportunity to set up pin or at least fingerprint protection on app.

That is a very debatable point, considering that the operating system allows encrypting the device storage and securing the device with a few different options, including the fingerprint and a PIN code.

Hello :) some news about this feature ? Yes I think too we really need this...

Under Android Keystore system can be used for secure fingerprint usage.

I'd sure like this. Not comfortable using email on mobile without fingerprint. Makes a lot of sense for a security-focused product. I prefer Tutanota overall but do like how ProtonMail uses Touch ID on iOS.

Some personal opinion here from the security perspective.

Fingerprints (like any other biometric data) themself are not secure as you leave them everywhere, are easy to fake / duplicate and you will have to store them in your passport in the future (databases of the government and so on). Anyone can retrieve most of these biometric data without applying any force, which is not the case for PIN codes and passwords that only you know and no one can see them in the plain sight like your fingers, eyes, face and so on.

Technically FIDO2 / UDF based (hardware) tokens are generally safer, and also PIN codes (master password algorithm for example).

See also
https://www.google.com/search?q=ccc+fingerprint+hack
https://www.google.com/search?q=biometric+database+leak
https://www.forbes.com/sites/daveywinder/2019/11/02/smartphone-security-alert-as-hackers-claim-any-fingerprint-lock-broken-in-20-minutes/
https://srlabs.de/bites/spoofing-fingerprints/
https://theconversation.com/fingerprint-and-face-scanners-arent-as-secure-as-we-think-they-are-112414

It's basically often comfort vs security.

With security, you must ask if you are protecting against a targeted threat or a general threat.
Biometrics is, as you point out, quite bad for security. Especially since it cannot be revoked after it have been compromised.
What it does though, is to add a thin protection layer, that actually forces an attacker to spend a few hours to extract and generate a fake fingerprint. Hence, it is probably sufficient protection against someone that just finds your phone, or some prying spouse / parent / aso.
And it is very convenient.

Also biometric protect against someone watching typing the PIN / Password.
A normal attacker doesn't have time hacking with biometrics or strong PIN/ password.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

geocfu picture geocfu  路  4Comments

EliasGabrielsson picture EliasGabrielsson  路  4Comments

4jNsY6fCVqZv picture 4jNsY6fCVqZv  路  4Comments

snaggen picture snaggen  路  7Comments

armhub picture armhub  路  3Comments