4 ms·
A pass[0] extension called pass-otp[1] can produce otp codes from the command line > pass edit git/hub [... put in your totp ...] otpauth://totp/Gi
by evanb 3y ago
A pass[0] extension called pass-otp[1] can produce otp codes from the command line
> pass edit git/hub
[... put in your totp ...]
otpauth://totp/GitHub/...
then you can
> pass otp -c git/hub
Copied OTP code for git/hub to clipboard. Will clear in 45 seconds.
pass-otp is also compatible with the passff firefox plugin; not sure beyond that.
[0]: https://www.passwordstore.org/ https://www.passwordstore.org/
[1]: https://github.com/tadfisher/pass-otp https://github.com/tadfisher/pass-otp
- crtasm 3y agoIf you copy something else to the clipboard afterwards does it know not to clear it?
- Xophmeister 3y agoI wrote a CLI password manager as a personal project a few years ago and it would only clear the clipboard if the hash of the contents matched the hash of what was originally copied. I presume `pass` does something similar.
- 8organicbits 3y agoI don't think it does, it looks like it clears the clipboard and then restores the previous clipboard item. Your suggestion seems better. https://git.zx2c4.com/password-store/tree/src/password-store.sh#n195 https://git.zx2c4.com/password-store/tree/src/password-store...
- pxx 3y agoHash? Why would you do any hashing? The domain is only so large so it's meaningless even if you cared about keeping the original bytes in RAM (which you don't). This is the same concept behind the fact that it typically makes little to no sense to hash phone numbers or credit card numbers.
- GoblinSlayer 3y agoIt makes sense if your password is something like hc0z3kjwedngwh4hgwct0-hunter2.
- Xophmeister 3y agoThe way my clipboard-clearer worked would have exposed* the plaintext secret if it wasn't hashed. Surely this would be generally true; however, in my case, it would have been particularly trivial to exfiltrate. (* The clipboard exposure was more limited...although probably only in a "security by obscurity" sense :P)
- Tmpod 3y agoI use it almost every single day, it's pretty simple and neat, haven't had the need for anything fancier.
- miggol 3y agoNeat! I should try this. Been using pass since forever. Does it support autofill on Android? GNU Pass is a great example of Unix-y interoperability for me. I sync the .password-store folder over to my phone with Syncthing, where the Password Store android app reads it. Password Store in turn talks to OpenKeychain for my encryption key with biometrics support. Changes are also synced back to my other devices. Each piece of the puzzle can focus on doing one thing and doing it well, even on Android! Password store for android: https://f-droid.org/packages/dev.msfjarvis.aps/ https://f-droid.org/packages/dev.msfjarvis.aps/ Openkeychain: https://f-droid.org/packages/org.sufficientlysecure.keychain/ https://f-droid.org/packages/org.sufficientlysecure.keychain...
- walteweiss 3y agoWhy not sync it via git? It’s way better, imo.
- miggol 3y agoThing is, I often create or update passwords from my phone. I have yet to find a good UX for committing and pushing those changes from Android. Though I would be interested in that, because I have little protection against accidental deletion now. With syncthing it's just instantly everywhere whenever I add an account, no action required. That's particularly useful when I create an account on my computer, then have to scan an OTP QR code with my phone. By the time my phone's out of my pocket the fresh account is already in the store to save the OTP code into.
- walteweiss 3y agoBut both Android [1] and iOS [2] clients have git functionality built-in. You just swipe it up (for iOS) or press sync (and swipe too, don’t remember if it works on Android) and it syncs. A couple of iOS notes: - The iOS app has a nasty bug, when you have not the latest repo on your iPhone, it cannot merge changes. So I recommend syncing your repo first, and then add new passwords from your mobile. IIRC, Android has no issues with that, but I’m not sure here. - If you have a complicated ssh key (I have gpg-key for that) the iOS client doesn’t work properly. Could also have issues with other keys. IIRC, it’s the iOS issue. So I use a very special iPhone-only key that I added to my GitLab repo, where my passwords are stored. I generated the key with `ssh-keygen -t rsa -b 4096 -m PEM -f /tmp/id_rsa` and transferred it to my iPhone via iTunes, to ‘pass for iOS’ application. ---- [1]: GitHub: https://github.com/android-password-store/Android-Password-Store https://github.com/android-password-store/Android-Password-S... + Website: https://passwordstore.app/ https://passwordstore.app/ + Play Store: https://play.google.com/store/apps/details?id=dev.msfjarvis.aps https://play.google.com/store/apps/details?id=dev.msfjarvis.... + F-Droid https://f-droid.org/packages/dev.msfjarvis.aps/ https://f-droid.org/packages/dev.msfjarvis.aps/ [2]: GitHub: https://github.com/mssun/passforios https://github.com/mssun/passforios + AppStore: https://apps.apple.com/us/app/pass-password-store/id1205820573 https://apps.apple.com/us/app/pass-password-store/id12058205...
- zimbatm 3y agoAlso worth looking at gopass[0], the Go re-implementation. It supports OPT out of the box. [0]: https://github.com/gopasspw/gopass https://github.com/gopasspw/gopass
- rendaw 3y agoI used gopass for a while and regret it. They kept messing with the contents of passwords, sometimes in ways that it itself couldn't read. Adding `GOPASS-1.0` etc. I feel like it also did way too many encrypts/decrypts for each password (I'd have to press my hardware button 4 times just to rename a password I think). Slowly fixing all my passwords having moved back to pass. I'm no fan of bash or pass's rather anemic built in structure but I don't feel like gopass were the right stewards.
- rendaw 3y agoI think browserpass ff+chromium plugin supports otp as well. A nice thing is it's a native plugin so you can manage it with your system package manager (rather than the extension store).