4 ms·
After few years of using lastpass (and following few of the more or less serious security breaches there) I am using https://www.passwordstore.org/ https://www.
by binaryapparatus 9y ago
After few years of using lastpass (and following few of the more or less serious security breaches there) I am using https://www.passwordstore.org/ https://www.passwordstore.org/ on both Mac and Linux machines. Works great, GPG encrypted, GIT synchronized, platform independent.
- OJFord 9y agoWhat's the point of using git to synchronise password storage? Assuming you're randomly generating passwords, the diffs basically amount to storing all prior passwords; fine, but git seems overkill for that?
- binaryapparatus 9y agoIn terms of who needs binary blob diffs, yes, its an overkill. In terms of having easy to set sync method anywhere it works beautifully. Pass has integrated git commands so pass git <command> does everything that git does. Commits are automatic with every change so all I need to do is "pass git push" on one machine and "pass git pull" on another to keep everything in sync.
- OJFord 9y ago> Pass has integrated git commands so pass git <command> does everything that git does. Ah, okay, I didn't realise it was integrated. I agree that for the target demographic git would seem to be an ideal already understood mechanism. I thought pass was just local storage, and you were suggesting using `GIT_DIR=/pass/localstorage/path git` to manage synchronisation.
- bjpbakker 9y agoI haven't used `pass` yet so I haven't tested this. But I would expect them to make git threat hashed passwords as binary. That would make git more like a file system with history, which is just what you want for a password store anyway.
- resf 9y agoWait so the name of the website is stored in plain text? So if I want to store my login for gaymidgetporn.com, there will be a file on my computer with that name? And anything or anybody on my computer can see all the websites for which I have logins just by doing ls ~/.password-store ? Erm, no thanks.
- syshum 9y agoThen you would want pass-tomb https://github.com/roddhjav/pass-tomb#readme https://github.com/roddhjav/pass-tomb#readme
- greenshackle2 9y agoNothing stops you from giving the sites an alias and storing the actual URLs in the encrypted files.
- eeeeeeeeeeeee 9y agoIf someone compromised your machine (even just user-level access, not root) you're already done. Your browser history is not encrypted and they could get the same kind of information from there.