Earlier quoted context omitted.
Pass ( https://www.passwordstore.org/ ) uses git as a password database in a similar way.
AFAIK pass won't handle conflicts for you (please correct me if I'm wrong!). This isn't a big problem for a password manager since conflicting changes are very uncommon, but for other apps this starts to get more important.
Firefox Lockbox
111–120 of 156 posts
Re: Firefox Lockbox
#112I am curious how it works, technically speaking. I already have this capability with password-store (pass), that works for Firefox, Chrome and Safari on destop and mobile. pass - https://www.passwordstore.org (core program) passff - https://github.com/jvenant/passff (firefox desktop) passforios - https://mssun.github.io/passforios (ios w/firefox mobile) qtpass - http://qtpass.org (osx, linux, windows)
Re: Firefox Lockbox
#113Earlier quoted context omitted.
I, too, want to know the implementaion details. That said I’ve watched hundred of eyes gloss over as I emphatically implored lay-persons about password policies and tools like password managers and Frankly their definition of ‘secure’ can be encapsulated in ‘256-bit encryption’. An oversight on Mozilla’s part for security-types and engineers, but maybe they have the masses in mind with this tool & it’s marketing site…
Maybe the ship has sailed, but I would prefer laypersons not associate the phrase "256-bit encryption" with anything , and would much rather one like "strong encryption practices" if it's a link to the technical specifications. They have no basis on which to evaluate what 256 bits of anything actually mean, so using it as a technical term to throw at their face intending for them to latch onto it as a valuable metric…
Re: Firefox Lockbox
#114Re: Firefox Lockbox
#115Earlier quoted context omitted.
Maybe the ship has sailed, but I would prefer laypersons not associate the phrase "256-bit encryption" with anything , and would much rather one like "strong encryption practices" if it's a link to the technical specifications. They have no basis on which to evaluate what 256 bits of anything actually mean, so using it as a technical term to throw at their face intending for them to latch onto it as a valuable metric…
On the other side, is it fair to say 8-bit encryption is NOT secure?
Re: Firefox Lockbox
#116Earlier quoted context omitted.
Exactly that, but shouldn't we expect better from Mozilla?
For Mozilla to be successful they have to appeal to the largest demographic possible. I'd only ask that Mozilla make additional technical information easy to find and well laid out. This is LastPass's page: https://lastpass.com/support.php?cmd=showfaq&id=1096 But that too you won't find when you use the app/extension normally.
Re: Firefox Lockbox
#117Earlier quoted context omitted.
Wirecutter has done a comparison of them. https://thewirecutter.com/reviews/best-password-managers/
And they picked the one that has had several high-profile security breaches... Not very credible.
Lots of grimness: https://www.theregister.co.uk/2017/02/28/flaws_in_password_m...
Re: Firefox Lockbox
#118I'm disappointed. Instead of making password management modular, so any password manager capable of certain queries and operations (KeePass, LastPass, Bitwarden, KWallet/Gnome Keyring/libsecret, Microsoft Credentials Management API, Apple Keychain, etc) could become a storage backend with some programming effort... they're doing the exact opposite - they've created yet another password manager UI and yet another prop…
Re: Firefox Lockbox
#119Am I missing something?
Re: Firefox Lockbox
#120Earlier quoted context omitted.
OpenKeychain and Password-store (paired with a yubikey) is the entire reason I use Android over iOS. I really wish there was hardware GPG key solution for the iphone.
Did you see it's missing a maintainer? I agree, using gpg on yubikey for password encryption is ideal. My only problem with it is that nobody makes money, so who is maintaining it?