-
@joshis_tweets @shawnwillden @DaveKSecure @FSecure Could you, e.g., combine a key protected with user auth in Strongbox with a different key held by the app and protected with an app-provided key? These 2 could be used together instead of just 1? The problem with app passwords is that keystore effectively becomes an oracle.