Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
urld
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
urld
4y ago
Nice read. I'm looking forward to try out a bunch of those things. But my favourite part is the SOCKS proxy. It reminds me of simpler times, when we used this to freely use the schools wifi, which had an overly restrictive web proxy.
2.
▲
Show HN: Fatdeps – show the size of your golang package dependencies
(godoc.org)
3 points
by
urld
9y ago
|
0 comments
3.
▲
by
urld
9y ago
You dont necessarily need "integration" to achieve this. You can always put a file under version control. I've stole some links from https://github.com/gioele/pw to show that there are downsides to the s
4.
▲
by
urld
9y ago
Thank you for all of your feedback. I've already implemented some features based on your ideas: - configurable timeouts: https://github.com/urld/passmgr/commit/069c209 - basic filter functionality: http
5.
▲
by
urld
9y ago
It depends on how you use it. As long as the identifiers are not visible to anyone else (like you described), its okay. But if you sync your secrets across devices, using services that are not under your control, or your device gets stolen,
6.
▲
by
urld
9y ago
I think there are many users or who dont want to setup gpg on multiple machines. I can also imagine scenarios where it is simply not possible to setup gpg on every machine. Maybe you could workaround such scenarios with portable versions of
7.
▲
by
urld
9y ago
Personally i dont see the point in integrating synchronization features for now. There are already tools which are good at synchronizing files. And since everything is stored in a single file, it should be trivial to setup sync. E.g. you co
8.
▲
by
urld
9y ago
You are right, the 6 second limit is on the low end. Ther is also a timeout for general inactivity which is currently set to 60 seconds. I want to make them both configurable and provide better defaults. The storage of arbitrary secrets is
9.
▲
by
urld
9y ago
Lets wait together then. In the meantime i suggest this link: https://team-sik.org/trent_portfolio/password-manager-apps/ Almost everything seems to be terrible.
10.
▲
by
urld
9y ago
Featurewise, no (not yet). However i think my aproach, using a single encrypted file for all secrets is somewhat more secure as it does not leak information like what sites are managed by the password manager. I guess you could also argue t
11.
▲
by
urld
9y ago
Good point. Im going to implement this, although its probably not possible to make it an atomic operation.
12.
▲
by
urld
9y ago
The main difference is, that passmgr uses authenticated symmetric encryption (aes-gcm) to store the contents in a single file, while pass as you already mentioned stores each secret in a separate file, using asymmetric encryption provided b
13.
▲
Show HN: Passmgr – Securely store passphrases and retrieve them via commandline
(godoc.org)
94 points
by
urld
9y ago
|
40 comments