Live data from Hacker News

Introducing Remembear, new password manager

remembear.com

11–20 of 98 posts

Re: Introducing Remembear, new password manager

#11
From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes.

Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors complain about. You really want to see a password manager get the basics right.

Notice also that the end of the Cure53 report complains about the project scope and the amount of time given. This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before.

Re: Introducing Remembear, new password manager

#15
It might be a good alternative to Enpass. They use Rust and libsodium, which is a good sign.

But browser integration is the trickiest part in a modern password manager, yet what makes a password manager actually usable for most people.

So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here.

Making these extensions smart (able to guess where login and password fields are, when passwords are being updated, etc) is also far from trivial. It's actually way more complex than password storage.

Gonna stick with Enpass for now, but that's definitely a project to watch.

Re: Introducing Remembear, new password manager

#17
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

The trouble I had with 1password is that it's secure in stupid ways.

Every time I log on a new device in there's SIX factor authentication and that's just too much work to get into my fap sites on my wankbook.

Re: Introducing Remembear, new password manager

#18
I don't get it at all. How on earth i will give someone (encrypted or not) my passwords? If you want to give convenience, make it local and secure with easy interface and charge money for your work. I will buy instantly well designed and secured product. This no.

Re: Introducing Remembear, new password manager

#20
post #7

What differentiates RememBear from other password managers? After looking through the blog and website it's not immediately clear to me. What makes (or will make) RememBear better than, say, 1password, which appears to have the same features, is also easy to use, and has a long history with which to work out issues?

I disagree that 1Password is easy to use. It’s easy enough for me to use, but trying to get my parents through the setup and UI has not been an easy task. It could be far more simple and straightforward.
Post reply on HN