Sitelet https://web.archive.org/web/20210821123736/https://github.com/gsantner/markor/issues/1250
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Per-file encryption password #1250

Open
redstreet opened this issue Feb 22, 2021 · 8 comments
Open

Per-file encryption password #1250

redstreet opened this issue Feb 22, 2021 · 8 comments

Comments

@redstreet
Copy link

@redstreet redstreet commented Feb 22, 2021 •

Encryption is an awesome start, thank you @opensource21 and @gsantner for getting this in. For me, this was a critical feature.

The existing feature addresses the data at rest encryption. This feature request is to make "locking" easy. This allows one to let someone else use their phone for a few minutes, unsupervised, without fear that private notes can be read. This can be accomplished in one or more of these ways:

  • by having Markor forget the password on a configurable timeout (eg: after 5mins)
  • by having Markor forget the password when exiting the app
  • by placing a "forget" button on the main app screen

Is one or more of the above an easy feature to implement? Happy to hash this out further, provide examples of other open source apps that do this, etc. Thanks much for considering!

May I also take a moment to say how awesome Markor is. It's exactly what I was looking for. Thank you for building, sharing, and maintaining it @gsantner!

@opensource21
Copy link
Contributor

@opensource21 opensource21 commented Feb 26, 2021

I think there are very simple solutions:

  • Use the app protection from android to disable access to Markor
  • Simply set the password to 123456 instead of delete the password.
@redstreet
Copy link
Author

@redstreet redstreet commented Feb 26, 2021

Of course, those are simple solutions....and also extremely inconvenient to the point of being unusable if done 20 times a day. I already tried :).

Automation (the ideas I suggested above) removes the friction and increases security. These methods are pretty standard in most apps that deal with security, hence the request. If it's not trivial to implement any of them, I understand. I was hoping "forget while exiting" would be the easiest and most trivial option to implement.

@gsantner
Copy link
Owner

@gsantner gsantner commented Feb 27, 2021 •

I do say clearing / setting random password / whatever value is a easy option.
So a password input dialog triggers.

Plus some settings option, always ask for password when restarting the app (=onCreate at MainActivity). On top of that, have a delay of ~5 minutes for the restart check, so if you recently worked with Markor you don't have to re-type everytime you want to add a additional line of text.

@gsantner gsantner changed the title Feature request: Timeout encryption password Per-file encryption password Jul 27, 2021
@sk-Prime
Copy link

@sk-Prime sk-Prime commented Aug 13, 2021 •

I am using markor since last week. It is a great app. Only thing I miss is the password protection. Entire app password protection will create inconvenience. So per file password is indeed desirable.

@gsantner
Copy link
Owner

@gsantner gsantner commented Aug 13, 2021

This issue is about consuming passwords "per-file", encryption itself is already there.

You can enable it in settings. One password for all.

@sk-Prime
Copy link

@sk-Prime sk-Prime commented Aug 13, 2021

Yes there is an option for that, for example test.md.jenc is an encrypted file, anyone can open it from Markor, isn't it? So if anyone (e.g family members/kid) take my phone and they can see it. Am I missing something?
I thought that requiring a password to open encrypted file will be a good feature.

@gsantner
Copy link
Owner

@gsantner gsantner commented Aug 13, 2021

what you seemingly look for is more, locking Markor so you cannot use it without password.

@sk-Prime
Copy link

@sk-Prime sk-Prime commented Aug 13, 2021

Yes, you are right but not locking entire markor. Ask password only for encrypted file.
e.g. test.md.jenc is an encrypted file. So if i try to open it, there will be a popup dialog box which will ask for decrypt password. If i can not input correct password it will say password mismatch, otherwise open the file.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
4 participants