Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add possibility to define a "master password" / lock to open the app #1658

Open
anonymous-matomo-user opened this issue Aug 29, 2010 · 14 comments

Comments

@anonymous-matomo-user
Copy link

I would like to suggest that the password can be entered each time I access a Piwik installation. I do not like it being stored permantly since others might have access to my iPhone but should not have access to other data without me choosing so.

@sgiehl
Copy link
Member

sgiehl commented Sep 7, 2010

Well, I would suggest to make this behaviour optional. I guess most users do not want to enter the password each time they open the app.

@tsteur
Copy link
Member

tsteur commented Sep 29, 2010

Will it be enough to allow an user to specify a "master password"? Then, user have to enter the master password on each app start if master password is specified. The app will only open/display stats if master password is correct.

@mattab
Copy link
Member

mattab commented Nov 16, 2010

testeur, your proposal sounds good. How do other mobile app (handling sensitive data) handle this problem?

@tsteur
Copy link
Member

tsteur commented Nov 17, 2010

Hi matt

don't know much apps which handle this problem. Just some banking apps where you have to enter a pin on each start. Most phones are usually used by only one person.

@anonymous-matomo-user
Copy link
Author

What if i lose my phone or somebody steal it. This should really be optional. Otherwise i can't use this app. At the moment i just use the Android Browser Login.

@tsteur
Copy link
Member

tsteur commented Jun 4, 2011

A workaround is to change password of your Piwik account or delete your Piwik account on the server and create a new one if you lose your phone. This should create a new tokenAuth. We currently only store the tokenAuth, no password. But the tokenAuth is as secret as your login and password.

At the moment you can not change any Server settings via Piwik Mobile. Therefore, you could also create a new Piwik Account with only View Access which you only use in Piwik Mobile. If you lose your phone, someone has only the possibility to view your statistics.

@tsteur
Copy link
Member

tsteur commented Jun 4, 2011

A further workaround is to setup a "passcode" (additional to SIM Lock).

Under iOS open Settings -> General -> Passcode Lock

Under Android open Settings -> Security & Location -> Change Screen Lock and / or Password settings

This has the advantage that it works for all your installed apps.

@tsteur
Copy link
Member

tsteur commented May 14, 2012

Attachment:
loginscreen2.png

@tsteur
Copy link
Member

tsteur commented May 14, 2012

Attachment:
loginscreen1.png

@tsteur
Copy link
Member

tsteur commented May 14, 2012

just added 2 possible layouts...

@mattab
Copy link
Member

mattab commented May 15, 2012

is there a difference between both screenshots?

@tsteur
Copy link
Member

tsteur commented May 15, 2012

Just the "Welcome" Title Bar

@mattab
Copy link
Member

mattab commented May 24, 2012

I think I like the Welcome! title better :)

@mattab
Copy link
Member

mattab commented Sep 8, 2012

Security now has its own sub-category since they're "special" items :)

@anonymous-matomo-user anonymous-matomo-user added this to the Piwik Mobile Client milestone Jul 8, 2014
@tsteur tsteur added this to the Backlog milestone Jul 25, 2014
@tsteur tsteur changed the title Do not store password Add possibility to define a "master password" / lock to open the app Dec 21, 2014
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants