Join Nostr
2026-09-16 02:45:50 UTC
in reply to

Sugestor Ultra on Nostr: There is also the question: when the vault will release the main key? On what ...

There is also the question: when the vault will release the main key? On what conditions. I assume standard anti-tamper safety, signed app, signed system, secure boot/locked bootloader. On rooted phones and/or normal desktop systems, this security model will fail instantly.
If there really is the need to protect data for real, introduce the password possibility and warn the user about data encryption.
Look at Veracrypt, this is a good security model based on encryption, not HSMs.

If the app is supposed to be used on bootloader locked phones ONLY, then the pin+vault are secure enough for non-critical data. But I would argue if it enough for a hot wallet. A very bad examples are: Trust wallet and Cake wallet, both using pins only, and Cake wallet is using pin also in the desktop version which means NO SECURITY AT ALL.