PhilippC / PhilippC/keepass2android

[QUESTION] Cannot open a password and HOTP protected database.

Open
#2,407 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

question
Dominant language
C#
Stars
6.2k
Forks
478
Avg merge
1h 4m
Merged PRs (30d)
2

Description

Version 1.09e-r7

Hello! I have not found a similar issue among the existing open and closed issues, so I thought I would ask. Also I am a simple user, not a developper, so I thought it would be best to open a question rather than an actual issue, as I could very well be the issue! :)

I managed to setup KeePass2 on my computer in order to use HOTP with the OtpKeyProv plugin, so that my password database is now protected by both a password AND 3 OTP codes.

I understand that the Keepass2Android GUI for a Master Key composed of a password + OTP works with Yubikey devices that will input the OTPs automatically, but I do not have sucha a device and would like to enter the OTPs manually.

I use Google Authenticator to generate the OTPs. What happens is that whatever I input in the password field or in an OTP field gets blanked whenever I switch from the Keepass2Android to the Google Authenticator APP and back to Keepass2Android to copy and paste the OTPs. So I am totally unable to get all the fields completed in order to open the database (password + 3 OTPs).

Am I doing something wrong? Is this an issue or rather a security feature, that the fields get blanked when switching APPs? Is this intended to work only with NFC Yubikeys that will enter all the OTP fields at once? Any plans on making it possible to use OTP codes generated by an authentication APP running on the same phone?

Many thanks in advance and sorry if this was covered elsewhere already, I could not find it.
Thank you for your work!

Eric.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the issue in Keepass2Android with a KeePass2 database protected by a password and three HOTP codes, using Google Authenticator and switching between apps. Determine whether the fields being cleared is intended security behavior or a defect, then establish the expected behavior and document or address the resulting change.

Written by the indexing model from the issue text.

Assessment

Tech stack
android, csharp
Domain
authentication, mobile, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.