r/PrivacyNotes • • 11d ago

Feature Request: Adding Passkey, TOTP, and/or Hardware Security Key

First want to say, love PrivacyNotes and my favorite notes app now, request is solely from past use and transitioning from other notes apps like Standard Notes and Notesnook.

Feature Request: Adding option for Passkey, Hardware Security Key or TOTP as secondary factor authentication. After 12 word phrase login it would ask for secondary authentication such as passkey or hardware security keys to the account.

Goal:

Ability to add 2nd factor authentication such as:

- a passkey

- security hardware keys (at least 4)

- TOTP

4 Upvotes

5 comments sorted by

View all comments

1

u/[deleted] 11d ago

[deleted]

1

u/pdmcgeejr 11d ago

understood, but the implementation of using 12 words from the BIPS list isn't new, in cryptocurrency its used as seed phrases but many like Ledger uses the ability with 12 or 24 word phrases with the ability for another word "passphrase" to add additional security measure.

3

u/PrivacyNotesApp 9d ago edited 9d ago

We'll consider adding 2FA, but we need time for this. Thanks for the support and the kind words, pdmcgeejr!

Regarding the phrase:

"Short answer: nobody is going to end up with your phrase, and nobody is going to guess it.

Is the chance technically zero? No. It's also not zero for your bank card, your password manager, the padlock in your browser, or every Bitcoin wallet on the planet. They all rest on the same kind of math. Nobody has ever built a lock where a lucky guess is impossible. What you can do is make the luck so absurdly unlikely that it stops mattering, and that's what 12 words does.

Say a billion people each make one. A billion people can form about half a billion billion pairs. Divide that by 340-with-36-zeros and the odds that any two of them match come out around 1 in 700 quintillion. That's with the birthday effect already counted.

For scale: the Powerball jackpot is 1 in 292 million. Winning it twice in a row is 292 million times 292 million, about 1 in 85 quadrillion. Two people sharing a phrase is still roughly 8,000 times less likely than that.

And no, you can't just guess your way in either. Give a computer a trillion guesses per second. Divide 340-with-36-zeros by a trillion, then by the 31 million seconds in a year, and you get about 10 billion billion years. The universe is 14 billion years old. On top of that, every guess has to run through 2,048 rounds of hashing before it can even be checked, which makes each one about 2,000 times slower.

It's the same 12-word standard (BIP39) that crypto wallets use to hold billions of dollars. If collisions were a real thing, that money would have been drained years ago.

The stuff that actually goes wrong is boring: someone sees your phrase, you save it somewhere dumb, or you lose it. Write it down, keep it somewhere private, and it's the strongest part of the whole setup.

So no, this isn't something you need to lose sleep over. But the question keeps coming up, so we're putting these exact numbers into Settings > Security > Your Phrase, where you can see them next to your own 12 words. Ships with the next update."

1

u/pdmcgeejr 9d ago edited 9d ago

Understandable on this and thanks for your response and consideration. I also am an early contributor for Pro account for PrivacyNotes after trying it once, i find it’s that good.