Password/Security overview
Maintainer antworten meist innerhalb von 1 Tag
Dieses Issue hat noch niemand übernommen.
Bewertung
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Anfängerfreundlichkeit
- 28/100
- Issue-Typ
- Feature
- Klarheit
- Muss geklärt werden
- Aktivitätsstatus
- Aktiv
- Bereich
- mobile-dev, security
Rechercherichtung
Beginne mit LoginRepository.observePasswordScores(), FilterUseCase und PasswordGenerator in feature:item:create; feature:autofill zeigt, wie die Übersicht von diesem Modul abhängen könnte. Überprüfe die Anforderungen der HIBP Pwned Passwords Range API, einschließlich k-Anonymität und der Handhabung von Add-Padding. Die Arbeit ist erst vollständig definiert, wenn die Fragen zur Ergebnisspeicherung und zum Einstiegspunkt geklärt sind; anschließend müssen alle aufgeführten Verhaltensweisen für Übersicht, Neugenerierung und Breach-Check abgedeckt werden.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Beschreibung
A screen that gives an overview of how healthy the user's passwords are, and a quick way to fix weak ones.
Strength distribution
- Chart showing how many logins fall into each score (Ridiculous, Weak, Moderate, Strong, Excellent)
- Tapping a category opens the item list with that score filter applied
- Logins without a password (
PasswordScore.None) are not counted as weak
Scores are already stored unencrypted in password.password_score and exposed through LoginRepository.observePasswordScores(), so the chart needs no decryption. The list screen already filters by score (FilterUseCase), so the tap-through can reuse it instead of building a second list.
Scores are calculated when an item is saved (migrated v1 items keep their v1 score), so the chart is only as current as each item's last save.
Regenerate a weak password
The new password must never replace the working one before the user has actually changed it on the website. Otherwise a rejected or abandoned change locks them out.
- Generate a new password and copy it. The old password stays saved
- Open the service's website, if the login has one
- Save the new password only after the user confirms the change worked
- Quick options for length and symbols, since many sites reject some characters
PasswordGenerator lives in feature:item:create. The overview can depend on that module the way feature:autofill already does.
Breached passwords
Check passwords against the HIBP Pwned Passwords range API. It is free: no API key, no subscription, no attribution required (only HIBP's email and domain search APIs are paid). It uses k-anonymity, so only the first 5 characters of the password's SHA-1 hash ever leave the device.
- Opt-in, off by default. Nothing is sent until the user enables it
- Show breached logins as their own category, with a tap-through to the affected items
- Breached logins can use the regenerate flow above
- Send the
Add-Padding: trueheader and discard padded rows (count0) - Handle offline and failed requests without marking anything as safe
Passwords with http websites
- Show passwords that have http-websites applied
- Show the http protocol
- Fix button should offer a way to solve this issue. Maybe suggest the https version, or drop the domain??
Health List
- Sort by severity and within the group by alphanummerics
Open question: storing results
Re-check everything each time the screen opens, or persist a per-item result? A persisted flag would be readable without unlocking (like password_score), so it should either be encrypted or accepted as leaked metadata deliberately.
Open question: entry point
- A navigation bar tab (next to Home, Connectivity, Settings), or
- A summary card on Home ("4 weak passwords, Review") that opens the full screen
Out of scope (follow-up)
- Reused passwords. Finding these means comparing plaintext, so either decrypt all passwords while unlocked or store a hash keyed from the ARK (never a plain hash). This is security-sensitive and needs its own design.
- Vorherrschende Sprache
- Kotlin
- Sterne
- 56
- Forks
- 11
- Ø Merge
- 2 Std. 57 Min.
- Gemergte PRs (30 T.)
- 14
Entwicklungsumgebung
Dieses Projekt bietet weder Dev-Container noch Dockerfile noch Beitragsleitfaden – die Einrichtung liegt bei Ihnen. Beginnen Sie mit der README; die allgemeinen Schritte stehen in unserem Leitfaden für den ersten Beitrag.
Erste Schritte
- Lesen Sie das ganze Issue und danach den Beitragsleitfaden des Projekts.
- Schreiben Sie ins Issue, dass Sie es übernehmen — das erspart doppelte Arbeit.
- Forken Sie das Repository und arbeiten Sie in einem Branch.
- Öffnen Sie einen Pull Request, der die Issue-Nummer nennt.
Mehr aus OffRange/KeyGo
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 66/100
Maintainer antworten meist innerhalb von 1 Tag
-
Add more filter optionsOffenenhancement
Schwierigkeit 3/5 1-2 Tage Anfängerfreundlichkeit 65/100
Maintainer antworten meist innerhalb von 1 Tag
-
dependencies enhancement
Schwierigkeit 4/5 3-5 Tage Anfängerfreundlichkeit 52/100
OffRange/KeyGo#93 · 1 Kommentar ·
Maintainer antworten meist innerhalb von 1 Tag
-
Version 2.1.0Offen
Schwierigkeit 5/5 Über eine Woche Anfängerfreundlichkeit 10/100
Maintainer antworten meist innerhalb von 1 Tag
-
create an extension for the browserEvtl. wieder frei @OffRange hat das vor 872 Tagen übernommen, und es ist kein Pull Request offen. Offenenhancement
OffRange/KeyGo#30 · 1 zugewiesene Person ·
Maintainer antworten meist innerhalb von 1 Tag
Ähnliche Issues
-
bug
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 84/100
-
enhancement
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 78/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 72/100
SimonHalvdansson/Harmonic-HN#363 ·
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 88/100
Maintainer antworten meist innerhalb von 1 Tag
-
Schwierigkeit 2/5 1-3 Stunden Anfängerfreundlichkeit 90/100
Automattic/pocket-casts-android#6095 ·
Maintainer antworten meist innerhalb von 1 Tag