13 ms·
Mitro Releases a New Free and Open Source Password Manager
- vijayp 12y agoWe're very excited to make this available to the community and welcome pull requests, bug reports, etc.. Pitch in on Github: https://github.com/mitro-co/mitro https://github.com/mitro-co/mitro
- dannyr 12y agoHow do I get started if I want to build an Android app?
- evanj 12y agoThe Android app is in the mitro-core/android/MitroApp directory, and should build with the Eclipse ADT. See: https://github.com/mitro-co/mitro/tree/master/mitro-core/android https://github.com/mitro-co/mitro/tree/master/mitro-core/and...
- scrollaway 12y agoCongratulations on the release guys. Would you mind talking about your strengths and weaknesses compared to KeepassX?
- timonel 12y agoFor starters, maybe we should ask why Mitro is only using 128bit AES (stated in their PDF design doc)?
- helper 12y agoPlease see the answer by cryptographer Thomas Pornin on AES 128 vs 256: http://security.stackexchange.com/questions/14068/why-most-people-use-256-bit-encryption-instead-of-128-bit http://security.stackexchange.com/questions/14068/why-most-p...
- AaronFriel 12y agoAES-256 is not the most secure variant of AES any longer, as it appears that variant with key extension improves certain types of attacks. One of those, called a related key attack, requires only 2^119 time against AES-256, and 2^172 time against AES-192. (Time against AES-128 is approximately 2^128, I'd wager about 2^126-127). This is a very particular kind of attack, however, and it doesn't necessarily mean other weaknesses will be exposed. Cryptographers, though, are a conservative sort by nature, and many feel more comfortable sticking with AES-128, which was part of the original Rijndael specification and what was designed most rigorously. AES-128 also seems to have had the fewest weaknesses developed against it. The fact that any attack succeeded in reducing AES-256 to below AES-128's security can give crypto folks pause. I think realistically they are all very safe and AES-128 is unlikely to be broken by anything within the next decade. After that? I wouldn't wager.
- nightcracker 12y agoBecause it's the most secure.
- drvortex 12y agoI liked the idea of a free and open-source password manager. It seems that Mitro has been around for nearly a year.[1]. It does not seem anywhere near as mature as Lastpass though. There are no additional features such as a credit card or notes store. Also, it seems buggy since I was only able to login once through the Chrome extension. I guess I will stick with Lastpass for now.
- dmacvicar 12y agoMain feature from Lastpass that I use and I would miss is Yubikey support (http://www.yubico.com/products/yubikey-hardware/yubikey/ http://www.yubico.com/products/yubikey-hardware/yubikey/)
- marcoamorales 12y agoIf I can host my own server, this sounds like a very promising solution.
- evanj 12y agoThat is absolutely the intention. Currently the docs are lacking, but we will try to add directions about running your own server in the next few days.
- zellyn 12y agoYou should consider porting it to sandstorm.io - that would be perfect!
- mercnet 12y agoWill there be an option to use your own server in the chrome extension and android app? Or will I have to compile both with my custom server address?
- vijayp 12y agoThe chrome extension already supports this via an option on a hidden preferences page: chrome-extension://EXTENSIONID/html/preferences.html
- marcodena 12y agoIs it similar to Lastpass?
- expose 12y agoI've been looking for open-source alternatives to LastPass. I'll give this a whirl -- thanks!
- click170 12y agoI would suggest Password Gorilla if you don't want your passwords stored in the cloud.
- nicpottier 12y agoThis looks really great, sadly this is the type of product where being an early adopter makes me nervous, but after a few minutes of playing with it I'm impressed with the UI. I love the functionality of LastPass, I really do, but man their UI is terrible. I trust them from a security front though and in the end that is what matters most to me. If Mitro builds up that same rep then I'll switch over, but until then waiting it out. (sorry!)
- edcastro 12y agoThe UI is indeed awesome. I'd love to see a little more development on the features (doesn't support wildcard domains, for example). But it's definitely a great starting point to work on.
- missmeng 12y agoAw, your comment about the UI made my day. Wildcard domains didn't come up at all as a use case—interesting you bring it up. Since it's open source now, I'll upload the rest of the UI design that hasn't been implemented yet which supports a few other features. Anything else you'd like to see?
- isaacdl 12y agoI'm with you on that - I'm an early adopter for many, many things, but security software is not one of them. I'm happy to play with it a little, but I'm not certainly going to migrate my passwords until it's show to be relatively reliable (and long-lived)!
- missmeng 12y agoAw, thanks for the UI love, nicpottier! I appreciate the support.
- JungleGymSam 12y agoYeah, that's the thing. LP doesn't give any love to their design.
- filmgirlcw 12y agoThis looks great. I'm a diehard 1Password user, and that probably won't change, but I love having open source options that have great features.
- sobkas 12y agoWhere one could find a specification of the protocol used by Mitro?
- vijayp 12y agoThe design doc describes the architecture: https://github.com/mitro-co/mitro/blob/master/PasswordManagerDesign.pdf https://github.com/mitro-co/mitro/blob/master/PasswordManage... We unfortunately don't have a great description of the protocol. The closest you can get is to look at the RPC proto spec: https://github.com/mitro-co/mitro/blob/master/mitro-core/java/server/src/co/mitro/core/server/data/RPC.java https://github.com/mitro-co/mitro/blob/master/mitro-core/jav...
- dnfehren 12y agoSince the company has been acquired what are the plans for the service? http://labs.mitro.co/ http://labs.mitro.co/ says that "The service will continue to operate as-is for the foreseeable future." but there is a lot of ambiguity in 'forseeable.' While I really appreciate the value of having the client and server code open sourced I don't want to run my own server nor do I want to sign up for a service that, with the changes that will likely happen after the acquisition, could disappear without a lot of warning. Can anyone clear this up? from Mitro, EFF? Congrats and thanks!
- ipedrazas 12y agoI'm in the same boat here... What will happen?
- dingdingdang 12y ago"Mitro has committed to funding continued operations of its servers until at least the end of 2014. If their code proves to be secure and popular with the community, we will be advising them on how to create a sustainable home for that infrastructure.". Erh. Yes, so I'll be staying on KeePass, strategically "cloud" backupped in encrypted form to my email address (also, yes, this does not solve Android integration..etc. so suggestions are welcome!)
- smacktoward 12y agoKeePassDroid? http://www.keepassdroid.com/ http://www.keepassdroid.com/
- JelteF 12y agoI recently started using KeePass2Android [1] instead of KeePassDroid. It has some features I really like, like cloudstorage integration with Google Drive, Dropbox and more. [1] https://play.google.com/store/apps/details?id=keepass2android.keepass2android https://play.google.com/store/apps/details?id=keepass2androi...
- 12y ago
- frakkingcylons 12y agoThe secret sharing across teams works which is good (LastPass's organization features are broken), but saving secrets is very slow right now.
- marcoamorales 12y agoThe server are probably getting hammered.
- pwman 12y agoHow are LastPass' organization features broken? Over 7,500 companies are using them successfully. https://enterprise.lastpass.com/enterprise-administration-basics/shared-folders/ https://enterprise.lastpass.com/enterprise-administration-ba...
- frakkingcylons 12y agoI'm sure a lot do, but when we tried to set it up this past Wednesday, we couldn't get it to actually share credentials. Perhaps we were using it wrong, but if we couldn't get it to just work in an hour, there's a fundamental problem with the product.
- jtheory 12y agoWe use LastPass internally, specifically to share long random passwords among the people that need them. It's not been a flawless experience, but it works -- what are the problems you've seen?
- frakkingcylons 12y agoWe were unable to get LastPass to actually share passwords at all. Created a shared folder with some passwords, checked to see if a coworker could see it, and sometimes they could see it, but most of the times the folder wouldn't show up at all. Spent at least an hour just debugging why this was happening, but we kept getting totally inconsistent results. I say this as a mostly satisfied LastPass (Personal) user.
- jfchevrette 12y agoI received this by email shortly after installing Mitro: "Congratulations on adding your first secret to Mitro" This makes me a little uncomfortable. How do they know? Why should they know? Edit: I could not find those words in the github repo.
- lobster_johnson 12y agoSecrets are stored on Mitro's servers. Presumably -- hopefully -- the passwords themselves are encrypted. Edit: Ah, yes: Mitro is distinctive amongst free/open source password managers in that it's architected around cloud storage. For security, the online password databases are encrypted with client-side keys derived from your master password. For availability, they are mirrored across three cloud storage providers. With this design ... passwords can be synchronized across all of your computers and devices with minimal effort.
- jfchevrette 12y agoThis I understand very well. So presumably they sent the email only after I sent them the first "blob of gibberish" telling them I added _at least_ one entry to my password database. Presumably they don't know if and when or how may entries I have. In this case they only noticed the first time I sent in my encrypted database.
- vijayp 12y agoSecrets are stored as described in the design document; the server knows how many secrets there are, but nothing about them: https://github.com/mitro-co/mitro/blob/master/PasswordManagerDesign.pdf https://github.com/mitro-co/mitro/blob/master/PasswordManage...
- Numberwang 12y agoNo information or demo on the webpage = Worthless.
- pyre 12y agoPresumably the code is released first, then the documentation is created. It sounds like the product wasn't initially developed with the idea that it would be released to others. That doesn't make it worthless. If Twitter spent the time + money to acquire them and open-source their product, I would assume that they have a vested interest in doing more than just dumping the code on Github and ignoring it.
- andrey-p 12y agoCurrently using KeePassX + Dropbox. What sort of benefits would I get from Mitro?
- JohnTHaller 12y agoCurrently, this is the best option. Though I recommend KeePass proper as opposed to X since KeePassX's last stable release was over 4 years ago and they've only pushed out alpha builds since then.
- isaacdl 12y agoUnfortunately, if you want to run on Linux, KeePassX is the best choice. KeePass "proper" does work on Linux under Mono, but the UI is pretty buggy (textfields don't render the cursor in the right place, and the UI just looks awful in general). I really do wish there was a better native Linux client - some new features would be nice.
- snassar 12y agoThere are several good reasons to use KeePassX over Keepass, even with the current status of Alpha 6 in the KeePassX 2 series. * KeePassX has a consistent UI across Windows, OS X, Linux * It's a small, portable binary. I've had good luck running the Windows and Linux binaries off of USD drives. * Alpha 5 and Alpha 6 have been really stable. I started using Alpha 5 and haven't had a need to look back. I've been recommending KeePassX as the go-to password manager for Windows, OS X, and Linux over Keepass.
- Rapzid 12y agoI use Keepass2 exclusively now(started using it this past year due to needing windows and cloud sync support) and have had no major issues across linux and windows. I guess YMMV, but it's been a great success for me.
- SideburnsOfDoom 12y agoNot keeping sensitive data in Dropbox.
- Kequc 12y agoIt would be nice since I don't have to remember any passwords anymore, if Mitro would generate password strings for me.
- Numberwang 12y agoI wonder if they have any plans for a phone app.
- vijayp 12y agoiOS and Android apps are available on the respective app stores now. Note that the Android app might be vulnerable to clipboard hijacking, as described in http://fc13.ifca.ai/proc/4-2.pdf http://fc13.ifca.ai/proc/4-2.pdf
- mrbill 12y agoI imported my LastPass vault into Mitro, but can't get it to auto-fill pages I have stored data for. I have to search for the page and then click "sign in".. Am I wrong in expecting it to work exactly like Lastpass did?
- vijayp 12y agoStrange, if the URL is shown in the 'details' view, the dropdown should show up. If not, please email inbound@mitro.co.
- hamburglar 12y agoIt would be cool if they developed this using something like RemoteStorage so you don't have to tie yourself to their server backend, which they say they're only committed to keeping around until the end of the year.
- SideburnsOfDoom 12y agoStoring my passwords in the cloud means it's already got one mark against it. What does it do to make make for that?
- hackcasual 12y agoPresumably encrypting them with a password you control?
- SideburnsOfDoom 12y agoIt's still an avoidable risk. And one that can be applied retroactively. https://www.techdirt.com/articles/20130620/15390323549/nsa-has-convinced-fisa-court-that-if-your-data-is-encrypted-you-might-be-terrorist-so-itll-hang-onto-your-data.shtml https://www.techdirt.com/articles/20130620/15390323549/nsa-h...
- wlesieutre 12y agoI'm a 1password user, but I'll definitely be checking this out. Having recently switched to Windows, I'm liking it a lot less. To put it charitably, their Windows version is not quite as nice as the Mac and iOS releases. It's a sunk cost at this point, but owning 1password on 3 platforms is expensive. $70 for my laptop and desktop, and another $18 for my phone. But I bought into it because the Mac version is great and I was primarily a Mac user at the time. Oh well.
- cheshire137 12y agoYeah, I get the feeling they don't care about their Windows users at all. I just try to ignore the Windows desktop app because at least the Chrome extension is fine in Windows.
- guiambros 12y agoThere's a v4 beta for Windows, which is very similar to the Mac version. Better than the stable v3. I'm using it on Linux (under Wine) and works well. The Chrome extension is a lot better.
- elithrar 12y ago> There's a v4 beta for Windows, which is very similar to the Mac version. Better than the stable v3. Agreed. The v4 Windows client is much, much better than the old v3 - and finally allows you to use the same Chrome extension. I previously had to run two versions of the extension (and all the frustration that brings) if I wanted to use 1Password on my Windows installs.
- niels_olson 12y agoWait, you switched from Mac to Windows? How's that going?
- wlesieutre 12y agoHonestly, it's going great. I've been a Mac user pretty much forever (the first home computer I used was running System 7), but now I'm on a Surface Pro 3 with Windows 8. It's a fantastic computer. The last thing that made me think "Oh shit I'm living in the future" this much was my first iPod Touch. I'd been dual-booting OS X / Windows on my desktop already because Apple's GPU drivers are garbage, so it wasn't a huge step. Dropping OS X completely was mostly based on being a game dev hobbyist who's doing a lot of 3D work and digital painting. OS X had turned into a web browsing and email platform for me, and I can do that just as well elsewhere. The experience with 1password is far from unusual though; Windows doesn't have a lot of developers making software of any quality. For every Mac program I try to find a substitute for, Windows has 30 different options that are all equally bad (looking at you, IRC clients that aren't Colloquy). So if you rely on a lot of little 3rd party software, it's not a good ecosystem. But if all you need is Firefox, blender, Unreal Engine, and Substance Designer, it's not a problem. And that's not even mentioning the price of a Mac with an upgradable GPU. I could do yearly GPU upgrades on my desktop and still be cheaper than a baseline Mac Pro.
- Sephr 12y agoThere's no method to reset Mitro, so if you're like me and Mitro ran into an error partway through importing your KeePass database, you won't be able to reset Mitro and try importing with a different method. Do I seriously have to click manage->delete secret thousands of times just to reset Mitro?
- dguaraglia 12y agoNot really, nobody is forcing you to delete everything manually. You can always implement the feature yourself! (Sorry, didn't meant to be that guy, but seriously don't know why people expect a clearly new piece of open source software to do everything they want.)
- deleted 12y ago[deleted]
- dserodio 12y agoApparently, it's just been open sourced but it's not a new project
- mstachowiak 12y ago"Good security practices require us to use different passwords for most or all of the websites .... remembering all of your passwords requires an inhuman display of memory." It actually is possible to create unique passwords for every website and remember them without inhuman displays of memory. To do so, there are two basic things you need to remember: 1) A unique base password 2) A simple hashing function The input to the hashing function can be the company's name or website address (an overly simplified example - your hashing function could be the first two characters of the website's domain name). A unique password for any website could then be: password = hash_function(domain) + base_password A very simple way to create unique passwords for every website, inhuman memorization skills not required.
- ig1 12y agoExcept if your password gets compromised on two sites than hackers could identify the pattern and compromise every account you have.
- vially 12y agoYes, but that is also the case if your password manager's password gets compromised.
- aroman 12y agothat's a very very different scenario. your password manager's password is not sent over the wire, and you know it to have very secure hashing. it is stored only on your hardware not so with external websites — if you use the proposed strategy on two websites with poor security (something which is completely opaque to you), your passwords are compromised.
- rsanek 12y agoI used this form for a while but realized that if someone is doing a targeted attack specifically on you and happens to find a single compromised password of yours, all the others are only a few guesses away. It's better than re-using passwords, but still worse than using truly unique ones.
- IbJacked 12y agoDoes the Firefox add-on not work, or is it just me? (It seems like it's trying to load the full-size desktop page in the little drop-down window. Firefox 31 on Win7.)
- k2enemy 12y agoI'll use this as an opportunity to give a shout out for my new favorite password manager: pass [0] It uses gpg to encrypt passwords that are then stored locally, but can be synced using Dropbox, rsync, unison, etc. It is a command line program, so it doesn't have things like browser integration, but on a mac, a little Automator magic alleviates most of that pain. Besides, after trying 1password, lastpass, and a few others, the browser integration was usually a source of frustration instead of convenience. For my setup, I have a keyboard combo mapped to an Automator action that gets the current URL from Safari, passes it to a shell script that strips out the hostname, then uses pass to copy the password to the clipboard for 45 seconds. Then, I use another script to have a notification pop up with my username in case I've forgotten it. So I press "cmd+\", then a second later I have my password in the clipboard and my username showing on a temporary desktop notification. I'm also using pass to store bank credentials, software keys, and other things. I also have it set up to use a different gpg key to keep a journal. It has turned out to be a very versatile and reliable piece of software. [0] http://www.passwordstore.org http://www.passwordstore.org
- zellyn 12y agoVery nice, but: 1) one of the reasons I use a password store is to share passwords with my wife. I can't imagine her using this 2) iPhone? Android? 3) 1password's integration with the browser is very helpful: since I've been using a linux box as my day-to-day machine (where 1password doesn't have a native version), I've been using it significantly less, because it adds friction. On Mac OS, I would just auto-gen a horrific 12-16 character random password for any website, and have it automatically saved to my 1password. As you might guess, I have high hopes for Mitro, especially if they (well, I guess it's now we) can create a compelling don't-use-their-host story (either hosted, or file-based (eg. dropbox)) and pass at least a cursory security smoke test. :-)
- reedlaw 12y agoI'd love to find a way to securely share passwords with mobile devices. But from what I understand, there's no very secure way to do it on Android. If you store a private key on the device then other applications may have access to it. And with iOS, each app is its own silo, so I'm not sure how you'd get password autocomplete working. An ideal solution would allow selective sharing because there are some secrets you wouldn't want stored on your mobile device.
- JoshTriplett 12y agoHow does this compare to letting Firefox remember my passwords and sync them via Firefox Sync?
- RyanMiller 12y agoI don't know much about Mitro but most Password software don't store your passwords as plaintext on your computer. They also don't make it easy to generate random password under certain criteria. Personally, I'd trust Mozilla with at most my bookmarks/settings/tabs. Keep your security safer with people dedicated to just it. Doubt that's an endorsement for Mitro, though. At least for now.
- 0xeeeeeeee 12y agoIt looks great. UI is really nice to look at. Looking around, this has a long way to go before it is able to compete feature wise with current commercial managers. Also, it's going to take a long time, security-wise, to get up to par with the current commercials as well. It sounds like I'm being harsh but there are a lot of possible issues to consider. An HSTS header would be a nice start......
- marco1 12y agoSpiderOak [1] released (or rather "endorsed") an "open source, 'Zero-Knowledge', cloud-based password manager" called Encryptr [2] as well. [1] https://spideroak.com/ https://spideroak.com/ [2] https://github.com/devgeeks/Encryptr https://github.com/devgeeks/Encryptr
- JungleGymSam 12y agoHi. Looks very nice but why would I switch from LastPass? They don't know my passwords too. They also have multi-factor authentication. They also have add-ins for all browsers and mobile too.
- dserodio 12y agoBecause it's open source, so it will be easier to audit, and probably because of the UI (Lastpass UI got a lot better in the latest releases, but still sucks).
- JungleGymSam 12y agoAs computer people we should move away from teaching people that a strong password is one that is made up of random numbers, letters, symbols, and is hard to remember. Instead, let's teach them to create much longer passwords that are nonsensical sentences. *You can't beat the carrot! OR Passwords? They're for Sundays.
- SideburnsOfDoom 12y ago> let's teach them to create much longer passwords that are nonsensical sentences. Doesn't matter; nobody is going to remember fifty different ones. I have more website logins that that. Password reuse is going to happen and it is bad. The only secure way is for each password to be made up of a unique long, generated string of "random numbers, letters, symbols" for maximum entropy and stored in a password manager. The user just has to remember the password manager's master password (and maybe a desktop PC login). Now these remaining memorised passwords can be long nonsensical sentences if need be.
- JungleGymSam 12y agoI did a really poor job of explaining myself. Really poor. I meant the master password. Mitro's password strength meter uses guidelines which are becoming (are?) old. So let's just move away from that altogether (for passwords that people should remember) and doing something that makes it easy to use lots of characters.
- buyx 12y agoFNB South Africa is a bank that has horribly complex rules for passwords - no repeated letters, no sequential letters, in addition to the normal password strength requirements. Given the complexity, many people I know just save their passwords in plain-text.
- cpeterso 12y agoThe blog post says Mitro is "joining" and "transitioning" to Twitter, but doesn't say that Twitter acquired them. How does that work for Mitro's investors? Why would Mitro join Twitter’s location team to work on "geo-related projects" instead of identity and authentication projects like "Sign in with Twitter"?
- wastedhours 12y ago"Soft landing" "acquihire"?
- pixelcort 12y agoHow does the sharing access work? Does it sign in with the password locally and share the resulting cookies to the recipient?
- whyagaintango2 12y agoReally surprised none mentioned firefox sync?
- substa 12y agoIt seems great, but... if the mitro.co server goes down? I misunderstood or is not possible to copy passwords on your computer?
- ern 12y agoA warning: this still seems very buggy, it seems to not have an easy easy way to delete an account, and even deleting individual entries is not totally reliable (deleted entries seem to stay in the list). So unless you want to spend a lot of time repeatedly trying to delete duplicates (created by failed imports) and/or every single entry, stay away, for now.
- gabriel34 12y agoI'm no crypto or security expert, but this worries me: "For security, the online password databases are encrypted with client-side keys derived from your master password" What is going on here? Does it hash my master password, generating a new pass? If so, this seems like it would only increase the number of bits in the possible keyspace but not increase the number of possible keys, while actually lowering security (since hash collisions can occur). This worries me because non-standard crypto applications tend to actually introduce holes and vulnerabilities. What other vulnerabilities lie hidden here?
- throwaway41597 12y agoI'm no expert but I see no harm here. In order to use symmetric encryption, you need a certain key size (e.g. 128-bit key for AES-128). How do you transform a password of, say, 15 characters to 128 bits? You guessed it, with a hash (well a key derivation function to slow down brute force). What they do is I think standard practice. > but not increase the number of possible keys So yes, if your password is weak, then it won't make it strong. > while actually lowering security (since hash collisions can occur) But I think you're wrong here. On a human password of 30 bits of entropy, there is very little chance of collision. If one collision was to happen, you'd still have a key space of (30^2) - 1, which is very much the same number.
- arantius 12y agoMy guess is they're using the standard approach for deriving an encryption key from a password: http://en.wikipedia.org/wiki/PBKDF2 http://en.wikipedia.org/wiki/PBKDF2
- gabriel34 12y agoThanks for the clarification (and thanks to throwaway above as well), seems this is standard. Is there a salt in this implementation? Is it bruteforced the first time I open the database on a new device?
- throwaway41597 12y ago
- Spooky23 12y agoJust use KeePassX. Cost is zero, available on all platforms that you care about, and it's a stable format. What more do you want? Cleartext cloud storage is a no-no. Browser integration from my POV is really dangerous as well... trying to keep secrets using the most widely attacked platform out there sounds like an exercise in futility.