5 ms·
I'm also a user of pass, but the fact that all the metadata is in clear is a big beef for me. How do you solve that, if at all?
by omtose 10y ago
I'm also a user of pass, but the fact that all the metadata is in clear is a big beef for me. How do you solve that, if at all?
- aban 10y agoFellow pass user here. freepass [0] seems like it could be a potential candidate, somewhere between pass and LessPass, but I haven't tried it out for myself yet. [0]: https://github.com/myfreeweb/freepass https://github.com/myfreeweb/freepass
- JetSpiegel 10y agoYou could encrypt the password store folder with another gpg container. That would be your master password.
- supergreg 10y agoMaybe you can put the whole .pass directory inside an encfs directory. Encryption all the way down.
- adilparvez 10y agoYou can use a hash of the site appended with a .pass wide pepper as the name of the directory storing credentials for a particular site, then use a wrapper script that hashes its input before passing it to pass. Also full disk encryption.
- omtose 10y agoThis is all a lot of effort, if I went down that road I might as well skip "pass" and handle the passwords myself. What I like about pass is that there isn't much setup. Full disk encryption also doesn't prevent a running application from seeing the directory structure. But I guess this is not a very realistic attack vector.
- adilparvez 10y agoYes, under that threat model you would lose with all of these password managers.
- omtose 10y agoHow so? If the entire directory structure is also encrypted then no program can easily know which sites or services I have passwords for.
- adilparvez 10y agoI was meaning if your machine was compromised.