4 ms·
I have a KeePassX db in a git repo I clone on all my hosts plus two backup remotes. Why would Bluepass be any better than my current setup? I already have P2P
by l-p 13y ago
I have a KeePassX db in a git repo I clone on all my hosts plus two backup remotes.
Why would Bluepass be any better than my current setup?
I already have P2P secure synchronization (via git+ssh), full control over my data and everything is based on portable FOSS.
- geertj 13y agoA few things: * Bluepass does push synchronization. So you wouldn't need to manually sync. * It would work on smartphones / tables too. * Are the remote git repos under your physical control? If not then your setup is vulnerable to a dictionary attack on your password / passphrase. * The Bluepass database is set up such that it can resolve conflicts due to concurrent updates (actually it's an append-only graph of parent->child nodes with a algorithm that selects the most likely lineage in case of conflict). [Edit: some clarifications]
- zacgarrett 13y agoI use keepass database that I store in a truecrypt volume which is then stored in dropbox which solves the first two items listed. With two separate 20+ char pass phrases the last issue is not one that I currently worry about. This is not saying that this project isn't interesting, I've just found a solution that has solved these issues for me for the last several years.
- geertj 13y agoI've been using a similar approach actually, with a keepass db on Dropbox. It provides a reasonable level of security assuming your passphrases are indeed random and computer generated (humans are lousy random number generators). However I wanted to bring the security to the next level after that, and this is what Bluepass is about.
- jezfromfuture 13y agoWhat advantages over 1password does your application give ?
- bigiain 13y agoFor one thing - auditable source code. Except for my most paranoid moments, I pretty much trust AgileBits to not be selling me out to the NSA, but that'd be much easier to completely trust if the source code was public and audited/approved by smarter people than me who know their crypto shit. Having said that, I'm currently storing my 1Password file in the unencrypted section of my DropBox storage, so my iOS devices can easily access it. (I've got EncFS/BoxCryptor working, but I don't think it's easy/possible to convince the DropBox app to read from the encrypted filesystem…)