Forum Discussion
pauljanssen
3 months agoNew Contributor
Hi Dave,
Thanks for that additional information. You said that the intruder could just "grab the local encrypted vault itself from my device" without using 2FA. Please confirm that you meant "decrypted vault" (otherwise it would make no sense to me). And why not improve application security by decrypting the vault in memory only, while the vault is open, after the user provides 2FA, leaving it encrypted on the local device storage at all times? Even with thousands of passwords in the vault, the volume of data is low so would not take a large amount of memory or time to decrypt, when the vault is opened only. Please let me know your thoughts; thank you.