6 ms·
Android "Password Store" client for pass discontinued
- felixc 2y ago“pass” in this context refers to a GPG-encrypted file based password manager: https://www.passwordstore.org/ https://www.passwordstore.org/ https://en.wikipedia.org/wiki/Pass_(software) https://en.wikipedia.org/wiki/Pass_(software) https://wiki.archlinux.org/title/Pass https://wiki.archlinux.org/title/Pass. “pass” itself can be used in many contexts, but is primarily a desktop command-line tool. “Password Store” is the Android client for it.
- WD-42 2y agoDang, this is rough. Pass is imo still the best password manager if you set it up right. Hopefully someone picks this up.
- fahimscirex 2y agoThat's saddening. APS used to be my daily driver once, and later I moved to Bitwarden.
- gurjeet 2y agoShameless plug: A few months ago I wrote a blog post [1] about integrating PasswordStore + GnuPG + TouchID on MacBook, and used that to automate my work VPN (Cisco AnyConnect) auto-connection [2], hence avoiding the need to interact with a very bad UI that is AnyConnect. Hopefully others find it useful. [1]: https://gurjeet.singh.im/blog/passwordstore+gnupg+touchid https://gurjeet.singh.im/blog/passwordstore+gnupg+touchid [2]: https://gurjeet.singh.im/blog/cisco-anyconnect-vpn-automation-with-touchid-on-macos https://gurjeet.singh.im/blog/cisco-anyconnect-vpn-automatio...
- too_damn_fast 2y agoIn the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?
- tjoff 2y ago> Bitwarden has been trying to move away from a fully FOSS system Details?
- josephcsible 2y agohttps://news.ycombinator.com/item?id=41893994 https://news.ycombinator.com/item?id=41893994
- levzzz 2y ago[dead]
- tout 2y agofwiw i've recently moved to sharing my kpdb using taildrive. The KeePass Android app can open databases from WebDAV
- TheBozzCL 2y agoFor iOS, Keepassium can use WebDAV as well.
- sunshine-o 2y agoThe reason is the idea of a free operating system and software has been shattered and is now a guest in big corporations and Github. It still kind of work but it is starting to crack in a few places.
- dailykoder 2y agoI've been using keepass for quite a number of years now. I have my database and a security key. I sync my database with dropbox (because I am too lazy to self-host something like nextcloud) between devices and just manually copy my key on everry device. My key was never synced through the internet. I hope that's secure enough and works fine for me. I guess syncthing is just smaller and obviously doesn't need a third party?
- deleted 2y ago
- mr_mitm 2y agoThis seems to happen more and more often, or at least it feels that way to me. FLOSS projects that aren't highly critical but very useful are maintained by only one person which loses interest, burns out or simply has other priorities. Sometimes they don't even make an announcement like here and just ghost the project. Very sad, even though understandable.
- prmoustache 2y agoIt happens also to proprietary apps maintained by individual developpers / small teams. At least in this case an open source project is easier to fork even if original dev becomes unresponsive/unreachable.
- wvh 2y agoA lot of FOSS projects are started by young people, often students. At some point, life hits, with spouses and children and real jobs demanding lots of time. Slowly people burn out, and most of the time, other people want to scratch their own itch and don't necessarily continue what already exists. I guess password managers are relatively simple at the core but have to fulfil very different requirements so there isn't one obvious piece of software that everybody can focus on. See also bike-shedding vs building a nuclear reactor. A better philosophy on how to herd cats would be useful in the FOSS world, though. It's a formidable force, but terribly scattered.
- computerfriend 2y agoThis is such a great application. I feel like it's complete already and would be happy if it just continued to exist without much or any maintenance.
- sam_lowry_ 2y agoThere is always need for maintenance on Android.
- prmoustache 2y agoThat maintenance can be relatively minimal if you aren't distributing the app through the playstore. Like once per n android release.
- azurezyq 2y agoConsumer softwares in the current environment can probably only live a few years at most (if you count security in, probably months) without maintenance. The author's decision to pull it from play store is very sensible and should be appreciated.
- Kwpolska 2y agoPassword Store sounds like a cool Unixy idea, but it's quite janky in my experience, especially if non-desktop-Unix systems are involved. The Android app was fine; it integrated with a GPG app that was less fine.
- sunshine-o 2y agoThis is actually a better outcome than finding out one day the app have a serious security problem. While i like `pass` and that Android app looked really good, this is just not serious. Because the fact that most people will end up trusting a random app as their password manager because it has 2k star on Github is crazy. If you want to use `pass` on Android you should tinker something with termux .
- mr_mitm 2y agoIn actually SSH into my desktop PC and use pass there to access my secrets. Luckily, I only need to do this occasionally, so the inconvenience is bearable. Still waiting on the day where I randomly get logged out of an important app while not having internet access, or the power going out in my apartment right after I leave for two weeks (happened once, luckily didn't need my passwords then).
- mid-kid 2y agoThe point of `pass` is to offload the security aspect to gpg, so unless something goes wrong with that, I don't believe continued use, even if unmaintained, is very insecure.
- rvense 2y agoThe Android app will by necessity receive the decrypted passwords from GPG to display and copy them to the clipboard. It could do whatever else it wants with them.
- deleted 2y ago[deleted]
- hashworks 2y agoI think termux has some limitations here (due to missing libraries), namely gpg decryption via hardware keys.
- grouchypumpkin 2y agoI worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromised by money or threats? * Would password managers from Google/apple/microsoft fare better because they already face these risks and have controls? Or maybe not?
- LeoPanthera 2y ago> add a back door? What's your threat model here? Some kind of mass hacking attempt? It would be easier to attack the service providers, rather than steal legitimate logins. A targeted attack on a specific person? It would be easier to, as the famous XKCD suggests, drug and/or hit them with a wrench until they voluntarily hand over whatever information you want. It's difficult to conceive of a situation where hacking password managers is the path of least resistance.
- grouchypumpkin 2y agoIsn’t it the same threat model as Lastpass breach? Login credentials seem to be worth money, and crypto keys even more.
- pantulis 2y agoThe comment was referring to Keepassium and Strongbox, which do not store credentials on their servers so it's not exactly the same. While conceivably a compromised Keepass wrapper could decrypt and send the dump of each and every file it opens, I doubt it would pass unnoticed.
- Etheryte 2y agoThe idea is to sell the dump, this is the case for nearly every dataset you see reported on Have I Been Pwned. I'm not really sure how there is even any question about oh why would anyone do this?
- deleted 2y ago[deleted]
- wvh 2y agoI use `pass` and am sad about this. This whole password thing, by far, is not a solved problem in my book. But thank you for your contributions!
- jasonm23 2y agohttps://github.com/android-password-store/Android-Password-Store/discussions/3260 https://github.com/android-password-store/Android-Password-S... For a useful discussion
- tomsel 2y agoWelp, time to switch to a linux phone.