Device Passcode
A device passcode keeps the Encryption Keys this browser holds for your synced graphs encrypted on the device. It is optional, and you set it on each device separately.
What it protects
Once your Encryption Keys are unlocked on a device, the browser keeps them, so you are not asked again (Recovery Code And Device Approval). Without a passcode they are stored in this browser's storage as they are, beside the access tokens for your own Sync Servers. Anyone who can copy that storage, or a program that reads it, gets your Encryption Keys and your access tokens together.
With a passcode set:
- Your Encryption Keys and your access tokens are stored encrypted under a key made from the passcode. No plain copy is left.
- EtherPK asks for the passcode the first time it needs your Encryption Keys in a browser session: when the Graphs page opens, or when you open a synced graph. A new tab does not ask while another EtherPK tab already has the passcode. After you close every EtherPK tab, the next one asks again.
- One passcode covers the Encryption Keys for every Sync Server on the device.
- It does not cover the Headless Client, which keeps your Encryption Keys in a file only your user can read (The Headless Client).
The passcode protects Encryption Keys, not notes. Copies of synced graphs that the browser already holds stay readable on the device. Nor does it protect your Encryption Keys from a browser extension or another program that can run inside an unlocked EtherPK tab, because that tab holds them in memory. To remove them from a shared machine, use Remove under Synced graphs in this browser on the This Device tab (Where Your Data Is Stored). Local graphs never ask for the passcode.
Set, change or turn off the passcode
On the Graphs page, open the This Device tab. Device Passcode is at the top. While this device is connected to a Sync Server and no passcode is set, the tab shows an exclamation mark.
- Set a passcode: enter it twice. Any passcode of 4 or more characters is accepted. A passcode of 4 to 7 characters stops someone at the keyboard, but not someone with a copy of this device's data, who can try every short passcode on their own computer. 8 or more characters is much harder to guess.
- Enter passcode: shown when the passcode has not been entered in this browser session.
- Change passcode: needs the current passcode.
- Turn off: needs the current passcode. Your Encryption Keys are then stored without encryption again.
The first time you open a synced graph on a device with no passcode, EtherPK offers one, once, with Set a passcode and Not now.
While the passcode waits to be entered, a custom server's tab says "Waiting for this device's passcode" and the header shows Enter passcode, because the access token for that server is encrypted too.
If you forget the passcode
A passcode cannot be recovered, but forgetting it loses nothing. In the dialog that asks for it, select Forgot your passcode?, then Remove the Encryption Keys.
- EtherPK removes the Encryption Keys and the access tokens the passcode protected from this device. Nothing on your Sync Servers changes, and your access tokens keep working until you revoke them on the server.
- Unlock your Encryption Keys again by approval from another device, or with your Recovery Code, as on a new device (Recovery Code And Device Approval). Connect to each custom server again with an access token first.
- EtherPK then offers to set a new passcode. Leave it off keeps the device without one.