Live data from Hacker News

KeeWeb: Unofficial KeePass web and desktop client

github.com

91–100 of 125 posts

Re: KeeWeb: Unofficial KeePass web and desktop client

#91

Does there exist an enterprise grade server/webui solution based on a keepass db? We are looking for an enterprise password manager solution that does not need all the ldap/ad integration bells/whistles (although we may explore ldap integration with the tool in the future). So I was thinking why not just use keepass. And by enterprise grade I guess I really mean it needs to be a multi user solution, but everyone woul…

PleasantSolutions.com may help. (Full disclosure: I sell an unrelated KeePass plug-in.)

Re: KeeWeb: Unofficial KeePass web and desktop client

#93
post #87
post #86

Earlier quoted context omitted.

Just to clarify what I mean; we have to make decisions based on tradeoffs. Having the most secure password possible is not the only thing that matters. So "trust security experts" is not a good response; I need to know threat levels so I can make informed decisions. I'm not just going to do the same thing a security enthusiast does because I value different things, to different degrees.

Looks like you didn't understand the sadness of the issue I was reporting. The author of the software constructed his own random number generator from two primitives: Salsa20 stream generator and Math.random. The last part is what makes this PRNG theoretically insecure: because Math.random is not guaranteed to give cryptographically secure random numbers, thus, theoretically, the generated passwords can be guessed. (…

This is what I'm talking about. You, a security enthusiast, are only interested in the technical security details. You respond to a comment about tradeoffs with details on the bug.

I don't care about why the bug happened or how easy it is/isn't to fix. I care about whether the existence of the bug is something I should be so concerned about as to not use the software. In order to gauge that, I need a little more info about the threat level.

Re: KeeWeb: Unofficial KeePass web and desktop client

#94
post #24

Earlier quoted context omitted.

Which version of KeePassX are you using? The 2.0 seems better. And if you use a Mac, have you tried MacPass?

MacPass is excellent. It finally helped me completely move to a password manager based life.

Except it can't synchronise (edit: yet) so it's useless for multiple users.

Re: KeeWeb: Unofficial KeePass web and desktop client

#95
post #49

Earlier quoted context omitted.

>strong-encryption something that 1password is fundamentally opposed to? where did you this idea?

The comment I replied to which suggested that strong-encryption was a differential between keepass and 1password.

As far as I can see, the comment you replied to contains no mention of these things. Can you quote the relevant part?

Re: KeeWeb: Unofficial KeePass web and desktop client

#96
post #24

Earlier quoted context omitted.

Which version of KeePassX are you using? The 2.0 seems better. And if you use a Mac, have you tried MacPass?

A warning about Macpass: After I saved my Keepass database with Macpass, KeepassX couldn't open it any more. So keep a backup unless you're sure you want to switch permanently. This probably applies to switching from any password manager to any other, honestly. (I think I was able to fix it in that case by opening and saving it with Keepass.)

> by opening and saving it with Keepass

The mono version?

Re: KeeWeb: Unofficial KeePass web and desktop client

#97

Earlier quoted context omitted.

You are uploading a file that is encrypted using very strong encryption, not plain text password. An employee of that company, or if the file was leaked due to technical errors, a member of the general public won't be able to decrypt it. If one of the richest governments wanted to, they might be able to, but if you had reasons to be a target you'd know better than using this. Also, take a look at SpiderOak.

Is strong-encryption something that 1password is fundamentally opposed to, or something they just haven't implemented yet? If I'm going to switch, the answer to question is pretty important.

No, but my understanding is that with 1passsword and similar service the web client sends the password in unencrypted form to the server. A rogue employee, is even the combination of a bug and a leak would expose your password.

With keepassx, your password never leaves your device in unencrypted form.

Re: KeeWeb: Unofficial KeePass web and desktop client

#98

Earlier quoted context omitted.

Is strong-encryption something that 1password is fundamentally opposed to, or something they just haven't implemented yet? If I'm going to switch, the answer to question is pretty important.

No, but my understanding is that with 1passsword and similar service the web client sends the password in unencrypted form to the server. A rogue employee, is even the combination of a bug and a leak would expose your password. With keepassx, your password never leaves your device in unencrypted form.

This is very much untrue. 1Password syncs an encrypted vault through separate channel (e.g. Dropbox, iCloud) -- it has zero-knowledge of your passwords. It just picks up a big encrypted blob from wherever you store it.

"The easiest way for us to protect your data and data about you is to not have that data in the first place. You may be noticing a theme by now: we can’t reveal or abuse data that we don’t have.

We do not have your 1Password data. We do not know your 1Password Master Password. We don’t even know if you use 1Password. We do not know how many items you have in your vault or their type."

https://support.1password.com/private-by-design/#what-we-cou...

Re: KeeWeb: Unofficial KeePass web and desktop client

#99
post #41

Earlier quoted context omitted.

No, it's not worse for your scenario. (That wasn't my assertion) However, this is an alternative to KeePass/KeePassX, so the typical behavior of KeePass users is to generate passwords with it, not reuse bad passwords. For example, I use KeePassX to generate strong passwords for long-term encrypted archives, and if I switched to this app, I wouldn't get the same security. I'm confused, though, should I say: "All right…

I use KeePass and I don't use it to generate passwords. It's a pain to open and close every time I need to login somewhere, especially if I'm on mobile. I use it for when I forget my passwords, and I honestly believe that is the common use case, but who knows?

The intent of KeePass is generally to let it generate sufficiently strong passwords for you, and a way to store those passwords. It's probably a bad idea to store passwords you've devised in it, because then you're not getting any additional security.

Re: KeeWeb: Unofficial KeePass web and desktop client

#100
This looks awesome. My only gripes with KeePass is the confusion between KeePass,2,X etc; get it together guys. Also there is a serious lack of good browser extensions. There only seems to be one offering and its the clunkiest thing I have ever used. -- That said, as soon as the second problem is addressed, I'll be switching as soon as possible. I'd love to move off my proprietary solution to an open one.
Post reply on HN