7 ms·
http://www.passwordstore.org/ http://www.passwordstore.org/ is a similar solution, and I prefer it to this solution for a few reasons: * git integration. * Se
by nmrm2 11y ago
http://www.passwordstore.org/ http://www.passwordstore.org/ is a similar solution, and I prefer it to this solution for a few reasons:
* git integration.
* Separate file for each secret, so that I can store the password on the first line and then other sensitive account details on subsequent lines.
* -c flag for copying passwords to clipboard (but only copies the first line of the file, so it doesn't interfere with the usecase above)
* tab completion for user account names. However, this comes at a slight cost to security -- anyone with access to your machine (or git repo) can see all of the websites / accounts for which you have a password.
* Everything happens via the file system and secrets are just gpg encrypted text files. So it's really easy to implement new utilities on top of your password store. This is true for this solution as well, but somehow having separate files for each account makes it safer to implement utilities that do account management.
- jrcii 11y agoIt would be nice if there were a way to integrate it with the OS X keychain, unfortunately I haven't gotten around to it and I haven't been able to find anyone who has done this already since it's tricky to google.
- QuantumRoar 11y agoIt would be nice if I could at least export from the OS X keychain (you can always write up a simple script to add them to pass). Internet accounts can be exported, but all the rest won't work. I've given up on it, but I'd like to know if anyone might have found something that I overlooked.
- mnem 11y agoHave you tried the security commandline utility? As far as I know it reads anything you want from the keychain. For example, to grab what password Spotify is storing in my keychain: `security find-generic-password -s Spotify -w`
- QuantumRoar 11y agoIt's some time ago that I tried exporting, so I don't recall exactly what I did. As far as I know, I tried it with that command line tool but it simply wouldn't export everything. There's also the issue that if it does export something, you have to accept every exported item individually. If you search the internet, you'll find people who wrote scripts for "automatic accept-clicking." But as I said, once I looked up what it exported, I noticed that it was far from complete.But maybe there's some command line option buried somewhere that will accomplish what I wanted to do... The whole export thing is just terribly broken.
- mnem 11y agoAre you aware of the command line utility, security? https://developer.apple.com/library/mac/documentation/Darwin/Reference/ManPages/man1/security.1.html https://developer.apple.com/library/mac/documentation/Darwin... Some examples of using it: http://joshtronic.com/2014/02/17/using-keyring-access-on-the-osx-commandline/ http://joshtronic.com/2014/02/17/using-keyring-access-on-the...
- jrcii 11y agoYep, I use it to provide passwords to my shell scripts, for example. security<->pass integration is precisely what I'm looking for, I get the feeling I'm going to end up having to implement it myself.
- k2enemy 11y agoI'm not sure exactly what you mean by "integrate," but you can have gpg-pinentry use keychain to remember your gpg passphrase for pass.
- bdamos 11y agoAnother reason for me is the cross-platform compatibility. With git, I'm able to synchronize passwords across OSX and Linux machines, and the features (even copying) work well on both platforms.
- aidenn0 11y agoSeparate files for each secret is a downside for me, particularly since it exposes the lookup key. [edit] deleted paragraph that was supposed to be added to a different comment.
- nmrm2 11y agoIt's a definite tradeoff, I agree. But I think pass is on the correct side of this tradeoff: 1. ./blah.sh | grep LookupKey exposes just as much information as pass -c LookupKey. If someone has access to your machine and you don't carefully prune your bash history file, then you're screwed. However, in the latter case, at least you get something at the cost of giving up security -- namely, the convenience of tab completion. 2. The only way to solve problem #1 in general is to have multi-stage authentication, where you authenticate to access to lookup keys and then authenticate again to access the passwords. That's achievable using pass and some Bash -- obfuscate file names and store a obfuscated -> actual mapping in a gpg-encrypted file, and write a bash script that does the ln -s'ing. And then the command that does that dumps you into a shell that doesn't record history. I did this for a while but found it's a bit of PITA. Also, I can almost always come up with names that would be difficult to exploit without a lot of information about my life (bank_primary, bank_secondary; email/personal, email/business, email/spammy; server/personal, server/2011; and so on. I won't remember these verbatim, but once tab-completion reminds me of my options I typically recall which is which. And in case you're afraid in several years you'll forget which server you first purchased in 2011, you can always just pass -e server/2011 and explain which one you meant in subsequent lines.
- deleted 11y ago[deleted]
- amelius 11y agoMay i ask how you would use this on a mobile device?
- caoimhin 11y agoWith the password store android app...
- nmrm2 11y agoI use Android. Here's an app: https://play.google.com/store/apps/details?id=com.zeapo.pwdstore https://play.google.com/store/apps/details?id=com.zeapo.pwds... edit: looks like there's an iPhone app as well. See http://www.passwordstore.org/ http://www.passwordstore.org/
- davej 11y agoThese tools really need a browser plugin for them to be useful to me.
- mbrock 11y agoThere's one for Firefox.
- tdkl 11y agoNot to mention mobile.
- nmrm2 11y agoThe Android app is acceptable: https://play.google.com/store/apps/details?id=com.zeapo.pwdstore https://play.google.com/store/apps/details?id=com.zeapo.pwds... There's a iPhone one I cannot comment on.
- DDub 11y agoHas anyone tried using these? - https://github.com/gustaebel/passext https://github.com/gustaebel/passext (Chrome) or - https://github.com/jvenant/passff https://github.com/jvenant/passff (firefox)
- werkshy 11y agoFrom the chrome extension github: "This is pre-alpha quality software, the result of a three day project. It will crash your browser, leak your passwords and destroy your home. This is actually my first Chrome extension and I am no expert javascript programmer." YMMV
- bruo 11y agoI use passff a lot of times everyday. I can't complaint :)
- k2enemy 11y agoFor Safari (and Chrome) I made a little automator service that gets the url from the browser, strips the hostname, then feeds that into a shell script that calls pass and puts the password in the clipboard for 45 seconds. It actually works better (for me) than 1password which was always a little flaky at recognizing a website after any kind of site update.
- raldu 11y agoThis nice solution is minimal, well scripted and very UNIXy. However, one tradeoff is that filenames for the stored password are plain. Running the tree command on the directory where encrypted files are stored would give us something like, $ tree .password-store irc ├── efnet └── freenode
- blfr 11y agoYes, it even has a built-in pass ls (which uses tree). It might be a feature, depends on how you look at it. Frankly, just encrypt the entire drive. Otherwise, there will always be a leak somewhere. If not in the file structure, then in the swap.
- uxcn 11y agoYou can avoid a lot of these types of issues using a digest for the username and password plus a master key as a salt. It generates a unique and relatively complex sequence for each site and doesn't require any persistent state other than the salt. The downside is a lack of control over complexity and the issue of passwords being strictly dependent on the salt. So, if one set of credentials is compromised, you would need update them all. I've seen software that does this, but there are subtle details to consider to actually get it correct.
- tbe 11y agoFor this reason I'm thinking of switching from gpg to encfs. It has an option for auto-unmounting after a period of unactivity. It would also play well with programs that need to read password from a file. Has anyone else here had the same thought? This guy seems to at least; https://github.com/equivrel/password-store-encfs/blob/master/add-encfs.patch https://github.com/equivrel/password-store-encfs/blob/master... Edit: spelling
- INTPenis 11y agoWould be much easier and still acceptable to simply mount the password-store on encfs. Could use autofs to make it auto mount when pass accesses the mount point.