Live data from Hacker News

Introducing Remembear, new password manager

remembear.com

21–30 of 98 posts

Re: Introducing Remembear, new password manager

#21
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

They also had 3 'Critical' vulnerabilities reported by Cure53 in their extension VPN offering last year.

https://cure53.de/summary-report_tunnelbear.pdf

Re: Introducing Remembear, new password manager

#22
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

That report: https://cure53.de/pentest-report_remembear.pdf

> It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical

> it has been noticeable that the development process of the RememBear suite was affected by tight deadlines. Evidencing this was the fact that builds were generally provided only one or two days before actual testing started, leaving little room for in-depth reconnaissance

TunnelBear's pull-quote @ https://www.remembear.com/blog/remembear-security-audit/:

> we’re proud to share that no critical security issues were discovered

I'd consider putting credentials on an incorrect domain a showstopper for a password manager, but whatever.

Re: Introducing Remembear, new password manager

#25
post #14

Seems to be yet another proprietary walled garden. No thanks.

Can you recommend any reputable open source password managers?

https://www.passwordstore.org/ (windows, android, and ios clients exist in addition to the better known linux/osx cli client)

Keepass (and keepassX and keepassC)

https://bitwarden.com/

Re: Introducing Remembear, new password manager

#26
post #14

Seems to be yet another proprietary walled garden. No thanks.

Can you recommend any reputable open source password managers?

Gopass, the 98% `pass` compatible password manager with a lot of nice improvements on the UX side:

https://www.justwatch.com/gopass/ https://github.com/justwatchcom/gopass

Re: Introducing Remembear, new password manager

#27
post #7

What differentiates RememBear from other password managers? After looking through the blog and website it's not immediately clear to me. What makes (or will make) RememBear better than, say, 1password, which appears to have the same features, is also easy to use, and has a long history with which to work out issues?

I feel the company's modus operandi is to have easy and cute UX to simplify using security tools.

Their VPN software is apparently very easy to use (from reddit comments). The same will probably apply to the password manager. They also seem to have a good marketing and PR team since I see them around quite a bit in youtube videos (Linus' being the most prominent one) and ads thinly veiled as articles. These two points alone have the ability to make the difficult mainstream user market to use it.

If all your security tools had similar UX and only a single login (what we see as single point of failure is usually seen as convenience), then you'll get many people to use it.

Re: Introducing Remembear, new password manager

#28
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

That report: https://cure53.de/pentest-report_remembear.pdf > It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical > it has been noticeable that the development process of the RememBear suite was affected by tight deadlines. Evidencing this was the fact that builds were generally…

It's got to at least be in the top 3 problem-domain-specific vulnerabilities you can have in a password manager, that's at least for sure.

Re: Introducing Remembear, new password manager

#29
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

What password manager do you recommend?
Post reply on HN