[GH-ISSUE #1004] Open password protected credential with biometrics #659

Closed
opened 2026-02-25 22:37:46 +03:00 by kerem · 2 comments
Owner

Originally created by @ghost on GitHub (Dec 1, 2021).
Original GitHub issue: https://github.com/floccusaddon/floccus/issues/1004

It's pretty anoying to open up the secured credential with password.

Describe the solution you'd like

Use the Windows hello / Touch ID / Yubikey / other passwordless, to open the locked floccus.

Describe alternatives you've considered

Generate a tray app (or work with lofloccus who generate a local webdav)), to actually securise credential within the browser without requiring to enter password each time.

Originally created by @ghost on GitHub (Dec 1, 2021). Original GitHub issue: https://github.com/floccusaddon/floccus/issues/1004 ### Is your feature request related to a problem? Please describe. It's pretty anoying to open up the secured credential with password. ### Describe the solution you'd like Use the Windows hello / Touch ID / Yubikey / other passwordless, to open the locked floccus. ### Describe alternatives you've considered Generate a tray app (or work with lofloccus who generate a local webdav)), to actually securise credential within the browser without requiring to enter password each time.
kerem 2026-02-25 22:37:46 +03:00
Author
Owner

@marcelklehr commented on GitHub (Dec 6, 2021):

Thank you for this feature request. It is my belief that it should be fairly rare for a user to require a password to secure the credentials stored in floccus, as the threat model in this case would include the attacker having being on / having full access to your machine. If this is your threat model, I understand that typing the passphrase every time you open the browser is tiresome. While passwordless auth would be cool, the flavor floccus would need is currently not supported widely enough in the browser landscape. Additionally, the ration between development time and users benefited for this feature would be too large for my taste at the moment.

<!-- gh-comment-id:987055233 --> @marcelklehr commented on GitHub (Dec 6, 2021): Thank you for this feature request. It is my belief that it should be fairly rare for a user to require a password to secure the credentials stored in floccus, as the threat model in this case would include the attacker having being on / having full access to your machine. If this is your threat model, I understand that typing the passphrase every time you open the browser is tiresome. While passwordless auth would be cool, the flavor floccus would need is currently not supported widely enough in the browser landscape. Additionally, the ration between *development time* and *users benefited* for this feature would be too large for my taste at the moment.
Author
Owner

@github-actions[bot] commented on GitHub (Mar 20, 2023):

This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.

<!-- gh-comment-id:1476409597 --> @github-actions[bot] commented on GitHub (Mar 20, 2023): This issue has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/floccus#659
No description provided.