4 ms·
Of the many password vault tools out there I still prefer ones that store the data locally, secure with published and and peer-reviewed crypto, sync directly ac
by gonewest 11y ago
Of the many password vault tools out there I still prefer ones that store the data locally, secure with published and and peer-reviewed crypto, sync directly across devices without uploading to a service. I just don't need the hassle of discovering belatedly that an online service has leaked any data. Especially if they are inclined to say it was by design.
- Velox 11y agoPerhaps I wasn't clear in the article. This is an entirely optional feature. If you don't want to store 1Password in Dropbox you don't have to, and you certainly don't need to have it in your public folder (I'm not sure those are even a thing any more?). The concern is that if someone has access to your keychain in any way at all, it is open to this. Perhaps you left your machine unlocked for a few minutes? Set up a read only network share for friends to stream movies from you? etc.
- deleted 11y ago[deleted]
- gonewest 11y agoI'm not sure I'm following you, but in short I'm not trying to attack this piece of software. All I'm saying is that I have a particular point of view and it appears based on the description that this tool isn't the one for me.
- Absentinsomniac 11y agoI wrote this: https://github.com/Jchase2/simple-pass-manager https://github.com/Jchase2/simple-pass-manager for that reason. It doesn't even store unencrypted things on disk. I'll still probably keep improving it, like the interface and what not, but I feel like the concept is pretty solid. Granted, it has a very limited feature set. But that's all I need. It doesn't do syncing though. I was thinking about an ocaml pw manager. If I get time.
- jdiez17 11y agoThe password manager I use stores the (GPG encrypted) data on a local git repository. http://www.passwordstore.org/ http://www.passwordstore.org/
- Absentinsomniac 11y agoMy only problem with that is that it stores stuff in different files, iirc, which you kind of have to name something recognizable. That is, the file names are exposed, which if you name them, for example, by which site they access, then presumably someone could figure out which sites you use. Of course, since they're all different files, that also adds some security I think.
- glass- 11y agoThis also stores the name of the site in plain-text.