Live data from Hacker News

Introducing Remembear, new password manager

remembear.com

31–40 of 98 posts

Re: Introducing Remembear, new password manager

#31
I think they are burying the lede, and being a little disingenuous with the big "Get Started, It's Free" button.

we will be introducing subscription-based pricing when RememBear leaves the public beta phase.

https://help.remembear.com/customer/en/portal/articles/28907...

A non-subscription product would be one thing that would get me to move off 1password.

Re: Introducing Remembear, new password manager

#32

It might be a good alternative to Enpass. They use Rust and libsodium, which is a good sign. But browser integration is the trickiest part in a modern password manager, yet what makes a password manager actually usable for most people. So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here. Making these extensions smart (able t…

> So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here.

Do you have a source for that? We are currently using teampasswordmanager.com and I was wondering if there are any known security issues I have not heard about.

Altgough the author refused to provide the sourcee, I had a look at the Chrome Extension anyway, but any additional info would be great.

Re: Introducing Remembear, new password manager

#35
post #21
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

They also had 3 'Critical' vulnerabilities reported by Cure53 in their extension VPN offering last year. https://cure53.de/summary-report_tunnelbear.pdf

To be fair though, as per the report all of these "Critical" vulnerabilities were fixed by mid-2017. So they're listening, at least.

Re: Introducing Remembear, new password manager

#36
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

What password manager do you recommend?

I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread.

It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!

Re: Introducing Remembear, new password manager

#37
post #33

Earlier quoted context omitted.

KeePassX?

Why is this downvoted? is there something wrong with KeePassX?

It hasn't been receiving improvements or maintenance for almost two years, and as a result, it has been forked and is actively developed by a different team under the name of KeePassXC. So nothing inherently wrong with KeePassX but you need to be aware that it is almost abandoned at this point and that there is a better alternative

Re: Introducing Remembear, new password manager

#38
post #35
post #21

Earlier quoted context omitted.

They also had 3 'Critical' vulnerabilities reported by Cure53 in their extension VPN offering last year. https://cure53.de/summary-report_tunnelbear.pdf

To be fair though, as per the report all of these "Critical" vulnerabilities were fixed by mid-2017. So they're listening, at least.

[deleted]

Re: Introducing Remembear, new password manager

#39
post #35
post #21

Earlier quoted context omitted.

They also had 3 'Critical' vulnerabilities reported by Cure53 in their extension VPN offering last year. https://cure53.de/summary-report_tunnelbear.pdf

To be fair though, as per the report all of these "Critical" vulnerabilities were fixed by mid-2017. So they're listening, at least.

And I bet the critical sub-domain vulnerability was fixed too.

The problem is that they are going to keep adding code, but won't get a security audit with every update. So all it takes is a slight mistake for it to be vulnerable again. What you need is a strong in-house pentesting team to be sure about there not being any new vulnerabilities with each release. Or atleast a bug bounty starting with beta releases, and let them bake before releasing them publicly.

The fact that such serious vulnerabilities come up at the time of an audit shows that they don't have one.

Re: Introducing Remembear, new password manager

#40
post #14

Earlier quoted context omitted.

Can you recommend any reputable open source password managers?

KeePass, pass, PasswordSafe, KeePassXC, bitwarden, enpass

Sadly Enpass is not open source.

https://discussion.enpass.io/index.php?/topic/210-open-sourc... https://www.enpass.io/legal-end-user-license-agreement/

Post reply on HN