[GH-ISSUE #2229] TOTP secrets not encrypted in database #1195

Closed
opened 2026-03-03 02:07:05 +03:00 by kerem · 0 comments
Owner

Originally created by @XXXXXTIGER on GitHub (Jan 13, 2022).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/2229

Hello, I just pulled Version 1.23.1(latest for now) image from docker hub.
When using sqlite3 as the data store, I found the TOTP secrets not encrypted at all.
I can not confirm this is desired, but I think it is not safe as the secrets are plaintexts.
Thanks.

Originally created by @XXXXXTIGER on GitHub (Jan 13, 2022). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/2229 Hello, I just pulled Version 1.23.1(latest for now) image from docker hub. When using sqlite3 as the data store, I found the TOTP secrets not encrypted at all. I can not confirm this is desired, but I think it is not safe as the secrets are plaintexts. Thanks.
kerem closed this issue 2026-03-03 02:07:05 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/vaultwarden#1195
No description provided.