3 ms·
Sorry, should have mentioned a bit about that. The Password Safe format is public, open, and available here [1]. There's also plenty of code/libraries you can u
by MarkMc2412 11y ago
Sorry, should have mentioned a bit about that. The Password Safe format is public, open, and available here [1]. There's also plenty of code/libraries you can use to write your own clients, e.g. Javascript [2], Java [3], Python [4]. For what it's worth the core data encryption is done using the Twofish cipher. Hope that helps.
[1]: http://sourceforge.net/p/passwordsafe/git-code/ci/master/tree/docs/formatV3.txt http://sourceforge.net/p/passwordsafe/git-code/ci/master/tre...
[2]: https://github.com/scintill/pwsafejs https://github.com/scintill/pwsafejs
[3]: http://sourceforge.net/projects/jpwsafe/ http://sourceforge.net/projects/jpwsafe/
[4]: https://github.com/ronys/pypwsafe https://github.com/ronys/pypwsafe
- pckspcks 11y agoThat both does and doesn't help. There is the format, which looks sensible. There are the protocols around it, key generation, salt generation, overall design, etc. which are not. What actually scares me about the design is if my machine is compromised, an attacker can grab my Password Safe file (plus keylogs or whatever) and has access to all of my passwords. The design seems not very robust at a designs+protocols level. (In contrast, right now, if a machine is compromised, it only compromises the passwords I've used from that machine).