Live data from Hacker News

Introducing Remembear, new password manager

remembear.com

71–80 of 98 posts

Re: Introducing Remembear, new password manager

#71

I use 1Password, and the only incentive which make me switch is completely open source good quality UX solution.

So.. KeePassXC?

Browser integration is poor at best. I've given it multiple goes and walked away disappointed every time.

Re: Introducing Remembear, new password manager

#72
post #65

I use 1Password, and the only incentive which make me switch is completely open source good quality UX solution.

I'm working on that ( https://passit.io ) and I'm curious what your opinion of good UX is. Many here mention vulnerabilities from web extension autofill (domain matching issues, etc). Do you have any opinion between: A) No autofill. Copy and paste (but good simple shortcuts). Least attack vectors, but least convenient. B) Autofill but only when user prompts (with shortcut). This avoids having to inject js into web pa…

Autofill with shortcuts would be my vote.

Re: Introducing Remembear, new password manager

#73
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

> ...with Safari and Firefox coming very soon.

I’m holding my breath...

Re: Introducing Remembear, new password manager

#74
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

Bruce Schneier agrees so designed his to not have some convenience features like that. Its kind of a pain sometimes but seems like good design to me.

"Schneier on Security: Security of Password Managers" https://www.schneier.com/blog/archives/2014/09/security_of_p...

Re: Introducing Remembear, new password manager

#76
post #62
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

> This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before. Yes, and it's getting really old. I'm tired of seeing security consulting firms wax poetic about how good the client's security is in their reports, then bend over backwards to frame obviously serious findings in the best possible light. Th…

Relevant: https://news.ycombinator.com/item?id=14825508

it's an industry secret that one of the reasons you do an audit is so you don't have to publish the "real" findings

Re: Introducing Remembear, new password manager

#77

Earlier quoted context omitted.

Ohh I like the idea of knowing the password requirements for the top 1000 websites!

Would it be wrong to wish this could (or should?) be standardized? That is, for example, one upper case letter, same special characters, etc. The lack of a standard seems to hurts users more than hackers. The hackers know it and adjust. User just get confused and default to overly simplistic and common PWs.

There should be a "robot.txt" for passwords. ie: /password.txt

This file could define the accepted password format. Password managers could retrieve that file and know exactly how to generate a password.

Re: Introducing Remembear, new password manager

#79
post #77

Earlier quoted context omitted.

Would it be wrong to wish this could (or should?) be standardized? That is, for example, one upper case letter, same special characters, etc. The lack of a standard seems to hurts users more than hackers. The hackers know it and adjust. User just get confused and default to overly simplistic and common PWs.

There should be a "robot.txt" for passwords. ie: /password.txt This file could define the accepted password format. Password managers could retrieve that file and know exactly how to generate a password.

no. if you're going to go through the trouble to do that, just fix your bullshit broken fucking password requirements.
Post reply on HN