21 ms·
Pass: A standard Unix password manager
- fwx 9y agoHow does this compare to other popular solutions? Specifically, KeepassX / Keepass2 which are the most common solutions I've seen most Unix / Linux users employ. Can we objectively state which one is a better solution?
- jm2dev 9y agoPass encrypted passwords are kept in your computer, which I find safer than web based solutions. Optionally you can use git to share passwords between computers but you still need the gpg2 keys from the original repo.
- nerdponx 9y agoHuh? Keepass is just an encrypted XML file. No GPG or remote storage required.
- aeorgnoieang 9y agoYou can setup a password store with Pass to use multiple keys – much better than sharing keys among multiple devices.
- deleted 9y ago[deleted]
- scbrg 9y agoA few differences: - There's no builtin GUI - Each entry is its own file - You control the storage format (meaning it's easy to store any kind of information, not just passwords) - It relies on GPG, so you need to set that up first
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- dbdr 9y ago> You need to handle X integration yourself by piping to xclip, or similar (or just cut and pasting from terminal) pass -c (or --clip) does that for you.
- Sir_Cmpwn 9y ago>- You need to handle X integration yourself by piping to xclip, or similar (or just cut and pasting from terminal) Wrong, pass provides the -c flag which puts it in your clipboard and clears it after a timeout.
- scbrg 9y agoSo it does, yes. I forgot about that, since I needed to write my own wrapper to paste both username and password (stored on separate lines) anyway. Thank you for the correction, I'll update my post.
- hdhzy 9y agoThere is also QtPass (GUI around pass), and various browser extensions (e.g. BrowserPass). Of course one has to set it up, it's not an integrated solution. But GPG provides interesting features like storing encryption keys on hardware devices. Some devices like Yubikeys can have touch-to-use enabled. So each use of a secret requires a touch (after PIN but that's once a session). Perfect combination of convenience and security for me.
- kronos29296 9y agoKeepassXC now supports YUBIkey now.
- hdhzy 9y agoWell "supports" is a very broad term given that yubikey supports multiple applets (OpenPGP, PIV, U2F, static passwords etc.). Do you mean this: > YubiKey challenge-response support for strengthening your database encryption key From https://keepassxc.org/blog/2017-06-26-2.2.0-released/ https://keepassxc.org/blog/2017-06-26-2.2.0-released/ Then it's not clear for me how this works exactly.
- laurent123456 9y ago> - You control the storage format (meaning it's easy to store any kind of information, not just passwords) In Keepass, there's a textarea associated with each password entry, which can be used to store extra data like security questions, etc.
- marcv81 9y agoObjective difference: KeePass encrypts the names of the websites where you have accounts. I would not want to live without this feature.
- DavideNL 9y agohttps://github.com/roddhjav/pass-tomb https://github.com/roddhjav/pass-tomb
- lower 9y agoI've been using this for a while and am very happy. Especially the ability to use a private git repository for synchronization of laptop and desktop makes this convenient.
- deleted 9y ago[deleted]
- thesmallestcat 9y agoNo, no it's not.
- kps 9y agoEd is the standard password manager.
- mdekkers 9y agoWhy?
- thesmallestcat 9y ago"standard Unix $THING" has meaning beyond marketing-speak. https://en.wikipedia.org/wiki/Single_UNIX_Specification https://en.wikipedia.org/wiki/Single_UNIX_Specification
- allerhellsten 9y agoPass is pretty awesome, but nowadays I've switched to gopass: https://github.com/justwatchcom/gopass https://github.com/justwatchcom/gopass - much better support for teams, structured secrets, binary secrets and quite a few other improvements. Oh, and it's (mostly) drop-in compatible.
- crypt1d 9y agoLooks nice. Unfortunately I would never use it for teams as it doesn't have audit logs. These are very useful in case a user is compromised - you can lookup which passwords he accessed and only change those. Same goes if the user left the team and u want to make sure all accesses are revoked.
- deleted 9y ago[deleted]
- jbg_ 9y ago"you can lookup which passwords he accessed" Really? What if s/he just decrypted the file themselves and had a look at the content, rather than using the convenient wrapper that a password manager provides?
- crypt1d 9y agoThats why password managers that do support audit logs (normally) do not provide this kind of mechanism of manually decrypting the file. The only way of accessing passwords would be through whatever interface they came up with.
- jbg_ 9y agoThe password manager of course does not "provide" such a mechanism (I imagine providing a "bypass audit logs" button would not be a popular feature). But if you know the key (the master password, or some derivative of it) and you have the ciphertext then you will be able to get the plaintext. The only way this kind of auditing could be trusted is if all the secrets are stored on the server that implements the auditing, which is exactly the model I believe that most users of `pass` are trying to avoid.
- nickjj 9y agoI've been using pass for a long time now. I have over 200 passwords stored. I like it because you can use it to store sensitive info along with metadata, not just single field passwords. It's also super easy to access the info on the command line with ways to auto-copy passwords to your clipboard (which expires after 45 seconds). I did a write up on it a while back at https://nickjanetakis.com/blog/managing-your-passwords-on-the-command-line-in-linux-with-pass https://nickjanetakis.com/blog/managing-your-passwords-on-th....
- amelius 9y agoHow do you deal with multiple devices? Do you sync your password files regularly between them?
- painted 9y agoThings like dropbox should be perfect for this, since the files are encrypted you don't need to trust anybody
- jbg_ 9y agoI use Git; pass has integration with it out of the box (makes a commit for each change to the password store). I just push and pull periodically myself, but this could be automated. There is an Android app called Password Store that is compatible with pass and has Git integration built in. I remember seeing some guy who had his `pass` Git repository public on GitHub and challenged the world to crack any of them. Myself, it's just git+ssh to a repository on my own server.
- nickjj 9y agoAs others have mentioned, git / dropbox works well for this. But personally I use a different approach. I rolled my own little rsync script that syncs files that I care about (passwords and other things) between my workstation and Chromebook (I run Linux natively on it).
- aeorgnoieang 9y agoI use Dropbox but I also use git-remote-gcrypt[0] to encrypt the entire Git repo so that even the file names and sub-directories don't leak outside any of my computers or devices. [0]: https://github.com/spwhitton/git-remote-gcrypt https://github.com/spwhitton/git-remote-gcrypt
- hasenj 9y agoIf it becomes standard, people would use it without a master password, and then stealing passwords via malicious scripts will become very easy.
- Sir_Cmpwn 9y agoWhat? How does this follow?
- deong 9y agoWell, I guess if you had no master password, any script you expect people to run could have a surreptitious "pass <some args> | curl" to post password data to some web service of your choosing. Still, if you use a password manager without a master password, I don't think you can be protected from consequence, regardless of what your tools do. Pass could refuse to allow the no master password scenario, or could force some type of blatant user interaction to allow it to work, but ultimately, that user is screwed by something somewhere.
- nzp 9y agoPass doesn't handle your "master password" at all, it's completely delegated to GnuPG (pass is really nothing more than a shell wrapper your file system, GnuPG, and Git). Does GnuPG let you easily get away without a password on your key, I don't remember ATM.
- hasenj 9y agoIt's completely possible to setup `pass` such that you can type `pass <name>` and it will print the password to stdout (you might has to pass an extra parameter or so) without ever asking the user to input anything to confirm they approve of this action. Now if this were to become mainstream, it's almost guaranteed that some percentage of users will set it up to work that way. And now you have the perfect opportunity to write a script that simply attempts to read passwords using pass and if it succeeds sends the results somewhere on the net.
- JetSpiegel 9y agoUsing this and something like rofi-pass: https://github.com/carnager/rofi-pass/ https://github.com/carnager/rofi-pass/ Gets me really close to the holy grail of password managers. Browser integration is possible too with PassFF: https://github.com/passff/passff https://github.com/passff/passff
- da_n 9y agoFor me, browser integration is an anti-feature for password managers.
- maccard 9y agoI prefer to trust the browser integration than to trust the clipboard.
- kronos29296 9y agoBrowser integration just means you trust the plugins that provide browser integration. May not always be secure. With the recent trend of popular browser extensions being made adware after purchasing them I wouldn't always trust them. A time out clipboard is sufficient for me.
- enobrev 9y agoThat's true, but the GP posted a link to the source of the browser plugin, which is to assume that could be avoided in this case.
- compuguy 9y agoPass/gopass really needs a good browser integration add-on. I have not found one that doesn't have some minor bug or issue.
- adtac 9y agoIsn't copying the password to clipboard a vulnerability? I think a better idea would be to fill in the password through something like xdotool
- thecopy 9y agoPassword managers clear the clipboard after 1 minute or so.
- painted 9y agothere are so many clipboard listeners out there :D so the fact that you clear the clipboard doesn't really matter
- reificator 9y agoClearing the clipboard protects against the user. A password manager effectively can't protect against other applications on the same machine. IMO that makes the universality of the clipboard more valuable than the safety of using alternate input methods. Though since there are plenty of things that block pasting passwords, those alternate options are appreciated.
- planetjones 9y agoWith all the discussion about 1password and its decision to "more or less" move to the web and a subscription based model, I had a TODO to look at what the open source community had; especially regarding browser plug-ins, mobile apps, etc. I don't understand why a simple problem like password management, needs a subscription and a private company to create software for the problem. This post seems to have saved me the trouble of Googling myself. I am installing on the Mac and iOS as we speak.
- nytesky 9y agoThis does seem attractive. Any feedback on iOS client passforios it's MIT licensed? And how is sync done,itunes?
- jbg_ 9y agoI haven't used the iOS client, but on Android the most common way to sync is to use your own Git repository accessed over SSH. You could use a private GitHub repo or one on your own server.
- planetjones 9y agosame on iOS it authenticates to your git repo either with password or SSH key. The only "complexity" in setting the app up is giving your public and private GPG keys to the iOS app (you can transfer them using itunes - there's also a facility to scan a QR code, but I don't know how you generate that from your GPG credentials)
- SingletonIface 9y ago> there's also a facility to scan a QR code, but I don't know how you generate that from your GPG credentials Search for qr on the python package index using pip. There's a module that you can pipe text to and then it'll render a qr code in your terminal using Unicode glyphs. Worked well last I tried. Don't remember what the module was called but you'll be able to find it I som sure.
- alex_duf 9y agoI don't like the fact someone with access to my hard-drive can figure out all the services I'm using just by looking at the filenames. It's convenient yes, but I prefer one encrypted file that contains it all.
- YorickPeterse 9y agoThis shouldn't really be an issue if you're using full disk encryption.
- jrochkind1 9y agoThat seems like saying why use an encrypting password manager at all if you're using full disk encryption, isn't it okay to just keep your passwords in plaintext on your encrypted disk?
- rythie 9y agoNot if you use cloud backup or get a virus.
- chme 9y agoThis isn't how real security works. There is a concept for 'defense in depth', saying that every component should be secure on its own and not rely on other components.
- pavon 9y agoEncryption only protects files at rest. The vast majority of attacks are against live systems connected to a network, where full disk encryption won't help you one bit. It is a nice extra layer of protection for when a device is lost/stolen, but I don't consider it a primary form of protection for any important data.
- painted 9y agoyeah, from a security point of view it's similar to have one file or multiple ones encrypted with the same key
- amelius 9y agoAnybody else here simply hashing their master password with the domain name of the website? I think this is something the browser should offer by default.
- jimktrains2 9y agoHow do you rotate passwords?
- hiq 9y agoIf your master password leaks you are exposed on every website where you used this scheme (and you should then change every password), so on the security side this is inferior to a master password granting access to uncorrelated passwords.
- amelius 9y agoWell, you can add a salt to this scheme. I know, it's not perfect, but it beats carrying around password files between devices.
- jbg_ 9y agoBut you would just need to carry the salt around instead. You're just trading convenience for (significantly) lower security.
- amelius 9y agoYes, it's a trade-off. By the way, I'd prefer to have a password manager on my phone (or smartwatch), and have it beam my password to my keyboard by NFC. But this solution does not exist yet.
- hiq 9y agoAs the other commenter pointed out, you need to carry your salt with you to deduce the actual password. On top of that, you need to keep your salt secret, otherwise it is trivial to deduce your password. So your system [password = hash(master password, salt, domain)] is exactly the same as a master password protecting several other ones. Just use your salt as a password directly at this point...
- rkeene2 9y agoRelated: hunter2[0], a password manager which uses a smartcard to manage the keys for each password, and supports multiple users. [0] https://chiselapp.com/user/rkeene/repository/hunter2/ https://chiselapp.com/user/rkeene/repository/hunter2/
- mrhigat4 9y agoI use pass and love it. It provides a lot of flexibility. To fix the "website metadata is leaked in filenames" issue, I use another project by Jason, ctmg[0]. I changed the pass directory to be one directory deeper, encrypted it and just do `ctmg open` when I boot to open my password list (similar to unlocking a keypassX store) then use pass as normal. On shutdown, the opened folder is re-encrypted automatically. You could also set a ctmg close on a timer if you don't want the list to be available during your entire session after open. Other things I do: * store all the files as .toml files so I can rip specific keys with a custom script. * Have a directory for web so `pass web` will give me all websites. Have a script to fill username pass for each. * Have a directory for contacts. Then wrote a script to generate vCard files by crawling and pulling keys, base64 profile images and all. * use syncthing to keep all devices up to date. It's pretty slick workflow IMHO [0] https://git.zx2c4.com/ctmg/about/ https://git.zx2c4.com/ctmg/about/
- painted 9y agolooks like a nice setup, but what about mobile?
- mrhigat4 9y agoSyncthing has a mobile app and there's an app for pass called PasswordStore[0] using OpenKeychain[1] (pgp manager). I'm not a fan of putting my private key on my mobile, but if I were, this would be a nice setup. [0]: https://github.com/zeapo/Android-Password-Store https://github.com/zeapo/Android-Password-Store [1]: https://github.com/open-keychain/open-keychain https://github.com/open-keychain/open-keychain Edit: yeah for ctmg support, probably have to hold out for something like PostMarketOS to save us.
- painted 9y agoyes, I saw this for pass, but I was referring to his setup where he uses ctmg also
- pietroalbini 9y agoIf your phone has NFC you can use a YubiKey to store the gpg key and decrypt the password via NFC.
- leshow 9y agoI've used pass for years, it's great.
- jbg_ 9y agoI've used this for a long time, and along with its Git integration (pushing/pulling to/from a repository on my own server, accessed over SSH) and a GPG key stored on a Yubikey Neo, I've got basically seamless sync between two laptops, a desktop and an Android phone, without using any third-party service. The "Password Store" app on Android is compatible with `pass` and supports Git and NFC for using the Yubikey Neo to decrypt the passwords.
- emilecantin 9y agoI've got the same setup, it's pretty great. One thing, though: make sure you have another way of decrypting your passwords! I lost my Yubikey once, and I lost all my passwords. Now I have a copy of that key on a USB drive I keep at home in a small safe.
- jbg_ 9y agoYeah, my passwords are encrypted to two private keys. One is on the Yubikey, the other is printed and stored securely.
- Karissa44 9y agomy FATHER co-worker's sister-in-law makes $73 /hour on the computer . She has been without a job for nine months but last month her check was $20283 just working on the computer for a few hours. This Sitemore information>>>>>>>>>>>http://ow.ly/iBXm30dNtIZ http://ow.ly/iBXm30dNtIZ
- jethro_tell 9y agoGeneral recommendation is to have a backup for everything on a yubi key. Two keys or printed backup codes or whatever.
- xur17 9y agoWhat's the best way to backup the private key on your yubikey? Do you just generate it on your computer instead of on your device, and then back that up?
- dsacco 9y agoNote that pass was developed (and is maintained) by Jason Donenfeld (zx2c4), the same person who developed Wireguard, the new VPN protocol. Not that my opinion is worth a whole lot, but this is the password manager I would choose to use if I wasn't using 1Password. Where many other password managers use convoluted constructions with (e.g.) AES and PBKDF2, this is very straightforward GPG.
- Spooky23 9y ago> Where many other password managers use convoluted constructions with (e.g.) AES and PBKDF2, this is very straightforward GPG. That's a bonus until you need to demonstrate FIPS 140-2 validation.
- dsacco 9y agoGPG is FIPS 140-2 compliant (though pass itself might not be, depending on the specific way it's used). Most likely pass would have to use GPG in a specific FIPS-compliant mode to pursue validation.
- Spooky23 9y agoGPG has a FIPS mode that will use FIPS 140-2 primitives. But you'll have a finding an audit in some circumstances as it hasn't been validated. I've seen cases where they'll miss that if it's running on RHEL, but it's a risk.
- foobar__ 9y agoFWIW, the source code looks fairly solid to me, considering that it's a bash script meant to be used on trusted inputs. To illustrate my point, look at the elaborate loop to iterate over *.gpg files: https://git.zx2c4.com/password-store/tree/src/password-store.sh?id=38ec1c72e29c872ec0cdde82f75490640d4019bf#n400 https://git.zx2c4.com/password-store/tree/src/password-store... This looks to me like the correct way to do this in bash, as long as you can guarantee that $PREFIX does not start with whitespace (which may be a valid assumption here). From what I can tell, the code quality is way better than what you see in your average bash script.
- Aissen 9y agoI've been using password managers for while now, but I've recently discovered pass-rotate: https://github.com/SirCmpwn/pass-rotate https://github.com/SirCmpwn/pass-rotate It's basically a rotation manager ! Very powerful and lets you properly change your passwords regularly on many websites (like the proprietary Dashlane Password Changer or Lastpass' similar feature).
- Sir_Cmpwn 9y agoI'm glad you like it! Please send patches with support for new services :)
- tombert 9y agoI love Pass, but the problem I've had is that I always feel like I have to spend a bunch of time setting it up when I'm on Windows. I understand it's the standard UNIX password manager, so I suppose I don't have a ton of room to complain, and most of my computers are Mac or Linux, so it's not a huge deal, but I think it increases the barrier of entry a ton of people. That said, I think Pass is awesome, and having my passwords stored in Github makes me really happy.
- y4mi 9y agothe nonexistent browser support makes it even more troublesome to setup. there is some support on linux systems, but windows is plain out of luck i Really like the idea of pass, but ill never accept copy pasting logins/passwords again. they'll need to be automatically inserted on a matching website. everything else is too much manual overhead for my taste.
- Spivak 9y agoIn Windows or in general, because pass has a ton of browser extensions. https://addons.mozilla.org/en-US/firefox/addon/passff/ https://addons.mozilla.org/en-US/firefox/addon/passff/ https://addons.mozilla.org/en-US/firefox/addon/pass-manager/ https://addons.mozilla.org/en-US/firefox/addon/pass-manager/
- y4mi 9y agoyes, as i said before. there is some support for linux systems. i'm using both linux and windows as well as android. my password manager will need to support and autofill on all environments with at least firefox and chrome. pass got linux covered (both chrome and firefox), but doesn't really work for winndows. android is really tiresome as well, as there is no way to skip my long masterpassword in favour of a fingerprint. I know, its not easy to implement that feature securely.
- aeorgnoieang 9y agoIf you want passwords automatically inserted why not just use the browser's features that do that? I do that for some sites.
- darrmit 9y agoI think pass is awesome if you have the workflow that supports it, but for the vast majority (myself included) it's entirely too difficult to setup and maintain. Particularly if you're using Windows regularly.
- aeorgnoieang 9y agoSetup is a bit of a pain, but what workflow is required? I just keep a Cygwin window or a Bash on Ubuntu on Windows window open and tab over when I need a password. With the shell auto-completion I find it easier to use than other password managers, tho I prefer not using my mouse so I'm surely biased about that aspect. I was previously using Password Safe, on Windows, and various compatible alternatives on Linux and Mac OS. Years ago I had tried using a single 'safe' synced via Dropbox but that was a big pain in the ass because sometimes I'd inadvertently lock the safe file by, e.g. starting to add a new password but not finishing. So instead I created a separate safe file for each computer or device. To sync new passwords or changes to existing passwords I'd have to periodically merge all of the safes and manually cleanup any conflicts between them. The main reason why I switched to Pass is that syncing the password stores on each of my devices is so much easier using Git.
- darrmit 9y agoWell, I'm talking from a non-developer perspective. I don't use Git daily, so I had to stand up my own Git instance or pay Github for a private repo. PassFF works well for Firefox on my Mac, but no equivalent for Windows. If you're willing to forgo browser integration then that's less of an issue. Lack of browser integration might also be less of an issue in Linux with dmenu or rofi plugins like others have mentioned, but that still doesn't solve Windows issues. I had considered the Bash/Ubuntu/Windows option (instead of qtpass) but haven't tried it yet.
- bqe 9y agoBoth Bitbucket and Gitlab have free private repos.
- ben0x539 9y agoI've seen pass mentioned like a million times but I didn't realize there were so many third party extensions for it, the comments here are pretty helpful. Thanks for the submission!
- zabil 9y agoI started with pass and switched to gopass because it automatically pushes new passwords to your remote git repository. I use a fish script to hook it up to https://github.com/junegunn/fzf https://github.com/junegunn/fzf for easy search and copying to the clipboard. https://github.com/zabil/thanksforallthefish/blob/6145e98691312361a18cfcdb6eaaf7b2f0a13fce/p.fish https://github.com/zabil/thanksforallthefish/blob/6145e98691...
- burnbabyburn 9y agoyou could already do that with git hooks and pass .git/hooks/post-commit #!/bin/sh git push origin master
- leighflix 9y agoAlright guys, I tried using this as I was curious, and miserably failed. Found out I needed GPG, and some encryption key or ID and whatnot. I have no clue what these things are and would like to know. How can I learn about this encryption stuff like keys and RAS and whatnot? (Books n Articles)
- jolmg 9y agoArchlinux wiki typically have very good guides: https://wiki.archlinux.org/index.php/GnuPG https://wiki.archlinux.org/index.php/GnuPG https://wiki.archlinux.org/index.php/Pass https://wiki.archlinux.org/index.php/Pass The simplest way to create your gpg-id is with: $ gpg --gen-key Fill in your name and email in the prompts. When it tells you it needs to generate a lot of random bytes, you'll probably want to do something like $ find / to generate disk entropy for gpg to pull enough random bytes from /dev/random to create your keys. You can use the email you provided as the gpg-id you give to pass $ pass init $email
- spoopy01 9y agoThis is a great tutorial in setting up pass on multiple accounts: https://medium.com/@davidpiegza/using-pass-in-a-team-1aa7adf36592 https://medium.com/@davidpiegza/using-pass-in-a-team-1aa7adf...
- tobias2014 9y agoIf you're using XMonad, you definitely want to use the pass addon in the xmonad-contrib package: https://hackage.haskell.org/package/xmonad-contrib-0.13/docs/XMonad-Prompt-Pass.html https://hackage.haskell.org/package/xmonad-contrib-0.13/docs... I would claim that there isn't a more convenient password management solution than this.
- xiaomai 9y agoIf you're not using XMonad, 'passmenu' is a really handy way to get your passwords. I bind it to ctrl-alt-p and rarely run pass manually now.
- molsson 9y agoImplemented as 700 lines of shell script?! Why?
- alexnewman 9y agoI use pass on all my devices. IOS, chromebook and cli. I freaking love it! passforios is still on testflight but so good. Only a few issues with passforios: - It forgets my github password everytime i upgrade - I honestly don't like the fact that I can't turn off the pin. 4 digits with unlimited retries. - It can't merge sometimes. I think they should be more aggressive about git rebase
- 0x6c6f6c 9y agoYou should be able to generate an SSH key that you can use in your application, right? If you can't that's definitely gotta be an issue in their backlog. Seems more robust to have a key for an application to connect with that you can simply revoke.
- mmagin 9y agoThanks for mentioning it. I previously couldn't have my passwords available from my phone. I created a seperate ssh key and did this on my server https://superuser.com/a/444899 https://superuser.com/a/444899
- ViktorEvil 9y agoPass for iOS is now on the App store
- guillaume20100 9y agoI recommend using Pass or Keepass, because we can see the source code. But like all these password managers, you need to synchronize your password vault. If you do not want to synchronize your vault among all your devices, but still want to have a unique password per site, try LessPass[1]. LessPass is a stateless open source password manager. Disclaimer I am the creator of LessPass [1] https://lesspass.com/ https://lesspass.com/
- arthulia 9y agoThis is pretty brilliant. My biggest concern is that if my password for a site gets compromised, it gets a lot more complicated. Presumably I'd have to memorize a separate master password for retrieving the new password for that site.
- prophesi 9y agoThey have a counter option that you can increment which allows you to generate a completely different password for the same site.
- arthulia 9y agoBut then you have to remember the counter setting for that website. So it's almost the same problem; I could just add a 1 to the end of my master password for that website.
- prophesi 9y agoNo, the counter would be saved by LessPass. Every time you look up the password for that site, it'll already know what the counter is set to for that site. This blog post[0] shows how LessPass lets you change passwords per site, and get around tricky password requirements. [0] https://blog.lesspass.com/lesspass-how-it-works-dde742dd18a4 https://blog.lesspass.com/lesspass-how-it-works-dde742dd18a4
- hansjorg 9y ago
- qrv3w 9y agoFor those interested, I've been working on something similar but for journal entries instead of passwords. [1] [1]: https://github.com/schollz/gojot https://github.com/schollz/gojot
- wallunit 9y agoI wrote a similar password manager (without knowing that pass already exists): https://github.com/snoack/mypass https://github.com/snoack/mypass But I ended up storing everything into one single encrypted file, rather than having one file per password. Though I see the point about the UNIX philosophy (i.e. "everything is a file"), but that way you'd leak information, i.e. what the passwords stored are for. Anyway, I'd appreciate any feedback on mypass.
- Galanwe 9y agoYou miss the point. Having multiple files is not a matter of Unix philosophy. Pass works with GPG keys... Multiple of them! The pass repository is to be shared among your team, so every file can be encrypted for a different, specific set of keys/users.
- Accacin 9y agoI'm currently a Lastpass user. I know, trusting them to store my passwords is probably not a great idea but it works on Windows, macOS and Linux and my iPhone with no problems at all. Would I like to move to something that isn't stored online? Yes, of course but I haven't found a decent solution that works everywhere. Any recommendations?
- homakov 9y agoDid anyone here NOT write their own pw manager?
- tuxninja 9y agoIf anyone needs a quick tutorial on pass I wrote about some it's features a while back http://tuxlabs.com/?p=450 http://tuxlabs.com/?p=450