4 ms·
Would need a whole bunch more features for me to want to switch from pass (passwordstore.org), which has already great git integration, command completion, stor
by infinisil 9y ago
Would need a whole bunch more features for me to want to switch from pass (passwordstore.org), which has already great git integration, command completion, stores arbitrary contents (not just username, password and url), a whole bunch of extensions and clients (I need an iOS client), can generate passwords, and more.
Also I think the 6 seconds for pasting the password before the clipboard is cleared is a bit too short, pass has 45 seconds which is a bit too much, maybe something between 15-30 seconds would be optimal, or better yet: Let the user configure it.
- alexeldeib 9y agoPass has a good iOS client? Do you mind sharing the name? I toyed around with pass but this would make a nice addition to my setup. E: quick Google and some digging later I see the situation, thanks for alerting me to this though!
- infinisil 9y agoYeah it's called 'passforios'. I couldn't live without it, it's really well made as well.
- asymmetric 9y ago> I need an iOS client Here you go: https://github.com/mssun/passforios https://github.com/mssun/passforios
- infinisil 9y agoI meant that I need an iOS client as in pass has one (and I'm using it) but passmgr doesn't
- urld 9y agoYou are right, the 6 second limit is on the low end. Ther is also a timeout for general inactivity which is currently set to 60 seconds. I want to make them both configurable and provide better defaults. The storage of arbitrary secrets is definitly on my todo list. As for the git integration i do not see the point of having it. For someone who is able to set up a remote git repo, it should be trivial to use git for synchronization, even without "git integration", since everything is stored in a single file. I have not yet looked into browser integration or clients for mobile platforms, but maybe there is a way to integrate with existing apps/extensions.
- infinisil 9y agoGit integration is nice because: - You never ever lose anything. Updated the wrong password? No problem, just `git reset` - Having everything in it's own file let's you merge changes made on different machines (I use this all the time, I'm not keeping every machine always up-to-date). If everything's in a single file, any change would result in a hard to resolve merge conflict. - All the other git goodness, including file history (e.g. when was the last time I changed this password), mutliple users (e.g. a shared family store), and more While some of these are debatable and git isn't really made for binary data, I still think it's a very good fit.
- urld 9y agoYou dont necessarily need "integration" to achieve this. You can always put a file under version control. I've stole some links from https://github.com/gioele/pw https://github.com/gioele/pw to show that there are downsides to the separate files approach: http://nms.csail.mit.edu/projects/ssh/ http://nms.csail.mit.edu/projects/ssh/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2666 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-2666