4 ms·
tl;dr rant, and not an exaggeration: the amount of time I've spent skimming these (edit to be nicer) exhausting comment threads about password managers has take
by wereallterrrist 4y ago
tl;dr rant, and not an exaggeration: the amount of time I've spent skimming these (edit to be nicer) exhausting comment threads about password managers has taken 10x the amount of time it took to use a pass-compatible or age-based password manager.
Okay, here we go, let me be explicit: there's a Venn diagram I imagine in my head of two circles - first is "password managers that require a web ui and browser integration", second is "password managers written in a language and with an overall complexity that I'm comfortable with".
For certainly-informed users, there's ZERO overlap in 2023. what's super fun is that this comment would get entirely different scores in yah, every 2 years for the past decade+ now. (think abour Rust circa 2021, 2019, 2017, I feel confident saying... for well most, opinion has been shifting in a certain direction).
luckily recently there is a tool which is,
1. rust-written
2. pass, pass-totp, and pass-tomb compatible
3. hasn't yet broken the CLI UX in nearly every release like another prominent "safe-lang" re-write of pass. that's all I'll say because it turned into a many-paragraph rant otherwise.
I'm trying so hard to watch myself here, but it's just not that hard. Let's imagine what needs to break for me to compromise your WV account versus what you'd need to compromise my public-hosted git-repo-backed yubikey-hardended-gpg-encrypted pass accounts. "I'll post mine if you post yours?"
- runnerup 4y ago> luckily recently there is a tool which is, ...and that is???
- BrightOne 4y agoNot GP, but https://github.com/timvisee/prs https://github.com/timvisee/prs seems to fit the bill.
- timvisee 4y agoThanks for mentioning prs [1], dev here! :) Yeah it definitely meets those requirements, being written in Rust, supporting pass, TOTP, Tombs amongst other things out of the box. Though its CLI is slightly different than classic pass. That is on purpose in fact, to achieve a better UX and less ambiguous commands. [1]: https://github.com/timvisee/prs https://github.com/timvisee/prs
- plaguepilled 4y agoWhat about KeePassXC? CLI comes with its own risks so I would have thought it is not universally applicable. Also what is this new rusty pass app you speak of? Sounds cool but you didn't link it. :(
- npigrounet 4y ago[dead]