4 ms·
> For example, if you store your database on a cloud, say, Dropbox, Dropbox could switch your Dropbox.com file with google.com file That's sad- could we includ
by smegcicle 5y ago
> For example, if you store your database on a cloud, say, Dropbox, Dropbox could switch your Dropbox.com file with google.com file
That's sad- could we include a hash to detect stuff like this?
- deleted 5y ago[deleted]
- PureParadigm 5y agoWhat you probably want is a signature. Since pass can be a git repo, you could use git to sign your commits [1]. But you'll have to remember to check the git commit signatures or automate checking it somehow. [1] https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work https://git-scm.com/book/en/v2/Git-Tools-Signing-Your-Work
- KMag 5y agoRestricting to a git repo and making sure to check that the commit is signed and there's no diff to current would work, but it's easier to just put the login URL (or at least the domain) as the second line of the encrypted file (Pass allows arbitrary metadata). OpenPGP (GPG / etc.) use a MAC on the file, so an attacker can't modify the encrypted file and still get it to decrypt (at least without some flag to ignore broken MAC). An attacker could create a new password file for you for their domain, but then they'd have to make up a random password for you that's not going to match your FriendFace/Congo/Vigintillion password.
- KMag 5y agoMake the login URL (or at least the domain) the second line of the encrypted file. Pass supports arbitrary metadata.