Sorry if this topic has been discussed before, didn't find a proper post for this.
As I understand the Owner profile encompasses/stores all secondary user profiles/their credentials. Setting up the owner profile to have secure at-rest state is easy. I would ideally use a 4+, probably 6 word diceware passphrase, this would be reasonably secure even with bruteforce. Unlocking the Owner gives access to secondary users.
My issues start with unlocking those secondary profiles. Ideally for me these should have biometric locks with a 6+ number pins. But where does the Two factor fingerprint PIN fit into all of this?
Normally I would have an encryption pass (pin or password) which would not be used after unlocking the second user if I added biometrics. This credential is used to putting the profile at rest/unlock it.
If I enable 2nd factor fingerprint PIN that just adds an extra PIN after fingerprint right? So I would have 3 credentials per profile before unlock 1 for unlocking, and one for 2nd factor PIN. That's a lot to remember.
So I would like to ask what would be my best choice for creating a credential system either by reusing some of these PINs or using some other method I haven't thought about?
I would imagine I shouldn't reuse main credentials across secondary user profiles as it would allow to unlock all of them if one got compromised right? That's already 1 to remember per profile.
- Can I reuse my main PIN for a secondary profile as a second factor PIN for that profile?
- Should I have the same second factor PIN under every profile?
- Is the 2nd factor PIN even universal or should be set per profile?
- What would be the most bang for the buck approach for me?