logoalt Hacker News

Cider9986today at 12:50 PM0 repliesview on HN

>>To make a strong passphrase convenient to use without ruining it with biometric unlock, GrapheneOS adds an optional 2nd factor fingerprint PIN. We reduce the allowed fingerprint attempts from 20 to 5 and failure to enter the correct 2nd factor PIN counts towards it. This enables using 6-8 random diceware words as the main unlock method required in Before First Unlock and fingerprint+PIN using a short PIN for convenience. Using a valid fingerprint prompts to enter the 2nd factor PIN which is needed to complete unlocking the screen and hardware keystore.

Pattern lock isn't exposed to the user afaik because it's insecure.

>I wonder why don't they just allow for longer passwords

They allow up to 128 digit passwords which they changed from AOSP.

I use a long passphrase for primary unlock and it's convenient because you only enter it when you restart.

If you rely on the secure element than 6 digits is fine. A long passphrase ensures you're protected even if the secure element is exploited.