4 ms·
But... why? If this isn’t peak “because we fucking can, that’s why,” then what is?
by cfadvan 8y ago
But... why? If this isn’t peak “because we fucking can, that’s why,” then what is?
- rschulman 8y agoCame here to say this. Why? What defect of password managers can you possibly be fixing by adding a global trustless append-only ledger to it?
- woodaroo 8y agoInstead of trusting a third party to protect your credentials, you're trusting an auditable, open source platform. I cant see myself using it for anything important, but I understand the draw.
- detaro 8y agoAny password manager that does the encryption stuff in offline, open-source software and puts it on any untrusted storage provides that, with the difference that it does not require making your encrypted copy public for all eternity, exposing it to unnecessary risk of compromise down the road.
- woodaroo 8y agoThere are risks either way. There have been plenty of vulnerabilities in popular password managers (some that also apply to this blockchain model). But I think your AES encrypted password being publically visible is a pretty low risk, compared to a PW manager being breached, having a flaw in the client, their being coerced by government, etc
- the_snooze 8y agoHow is this project any less at risk for those client-side implementation risks you mention? Basically, why should this nascent project be trusted over, say, KeePass?
- zwevgzewgzv 8y agoMany password managers require you to have an account online, to store the password vault. Passwords don't take up much space, so instead of uploading your encrypted password vault to google drive or some other service, where google might decide to lock you out or stop maintaining the service, you can put it on the ledger. When you need the passwords, assuming the chain functions normally, you can download the chain and your vault (that no one else can open, since they don't have your key). How confident are you that a typical company/project will be around in 20 years? How confident are you that the BTC ledger will be intact in 20 years? Either way, keep a local backup if you can.
- pps43 8y agoOn reflection, this is probably not as stupid as it sounds. The point is using blockchain to store your (encrypted) data. It's not feasible to backup everything this way, but a list of passwords is short enough. If all you do is open source and the only things you need to back up privately are passwords, this way you can avoid having your own backups at all.
- GordonS 8y agoBut why would a blockchain be any better than a peer-to-peer filesystem, for example? Also, it seems like a really bad idea to have your encrypted passwords open for anyone to have a crack at - any flaws in the b.lock encryption protocol or implementation could have disastrous consequences. Unfortunately I wasted some minutes of my life looking into their encryption, and it's bad (not using authenticated encryption, using a malleable encryption mode (CTR), directly encrypting secrets with your wallet private key...)