Live data from Hacker News

Firefox Lockbox

testpilot.firefox.com

111–120 of 156 posts

Re: Firefox Lockbox

#111
post #69

Earlier quoted context omitted.

Pass ( https://www.passwordstore.org/ ) uses git as a password database in a similar way.

AFAIK pass won't handle conflicts for you (please correct me if I'm wrong!). This isn't a big problem for a password manager since conflicting changes are very uncommon, but for other apps this starts to get more important.

It just does what git does. Since every site has its own file containing just a password, merging conflicts isn't a common issue.

Re: Firefox Lockbox

#112

I am curious how it works, technically speaking. I already have this capability with password-store (pass), that works for Firefox, Chrome and Safari on destop and mobile. pass - https://www.passwordstore.org (core program) passff - https://github.com/jvenant/passff (firefox desktop) passforios - https://mssun.github.io/passforios (ios w/firefox mobile) qtpass - http://qtpass.org (osx, linux, windows)

I've been using pass with a yubikey for the past year and a half and have been very happy with it. The ability to call out to the pass binary in personal scripts is a really handy feature that I didn't realize would be so useful until I started using it.

Re: Firefox Lockbox

#113
post #80

Earlier quoted context omitted.

I, too, want to know the implementaion details. That said I’ve watched hundred of eyes gloss over as I emphatically implored lay-persons about password policies and tools like password managers and Frankly their definition of ‘secure’ can be encapsulated in ‘256-bit encryption’. An oversight on Mozilla’s part for security-types and engineers, but maybe they have the masses in mind with this tool & it’s marketing site…

Maybe the ship has sailed, but I would prefer laypersons not associate the phrase "256-bit encryption" with anything , and would much rather one like "strong encryption practices" if it's a link to the technical specifications. They have no basis on which to evaluate what 256 bits of anything actually mean, so using it as a technical term to throw at their face intending for them to latch onto it as a valuable metric…

On the other side, is it fair to say 8-bit encryption is NOT secure?

Re: Firefox Lockbox

#115

Earlier quoted context omitted.

Maybe the ship has sailed, but I would prefer laypersons not associate the phrase "256-bit encryption" with anything , and would much rather one like "strong encryption practices" if it's a link to the technical specifications. They have no basis on which to evaluate what 256 bits of anything actually mean, so using it as a technical term to throw at their face intending for them to latch onto it as a valuable metric…

On the other side, is it fair to say 8-bit encryption is NOT secure?

yeah, but if I'm rotating a 256-bit key using XOR, is that really secure? It's 256-bit encryption, but about the weakest thing I could possibly do short of plain text.

Re: Firefox Lockbox

#116

Earlier quoted context omitted.

Exactly that, but shouldn't we expect better from Mozilla?

For Mozilla to be successful they have to appeal to the largest demographic possible. I'd only ask that Mozilla make additional technical information easy to find and well laid out. This is LastPass's page: https://lastpass.com/support.php?cmd=showfaq&id=1096 But that too you won't find when you use the app/extension normally.

Mozilla can do a lot of things that harm users or the general public but increase its success. Mozilla shouldn't do these things.

Re: Firefox Lockbox

#117
post #110

Earlier quoted context omitted.

Wirecutter has done a comparison of them. https://thewirecutter.com/reviews/best-password-managers/

And they picked the one that has had several high-profile security breaches... Not very credible.

Which ones have fewer breaches? Is there a comparison writeup somewhere?

Lots of grimness: https://www.theregister.co.uk/2017/02/28/flaws_in_password_m...

Re: Firefox Lockbox

#118

I'm disappointed. Instead of making password management modular, so any password manager capable of certain queries and operations (KeePass, LastPass, Bitwarden, KWallet/Gnome Keyring/libsecret, Microsoft Credentials Management API, Apple Keychain, etc) could become a storage backend with some programming effort... they're doing the exact opposite - they've created yet another password manager UI and yet another prop…

While a lot of Mozilla's work is great, this seems to be the tendency of every "Test Pilot" project I've seen; NiH and always a reimplementation of ideas there are plenty of alternatives for already, without much consideration for learning from/interop with those alternatives. It's a bit odd: it all seems quite separate and "distant" from the core work I expect from Mozilla.

Re: Firefox Lockbox

#120
post #63
post #38

Earlier quoted context omitted.

OpenKeychain and Password-store (paired with a yubikey) is the entire reason I use Android over iOS. I really wish there was hardware GPG key solution for the iphone.

Did you see it's missing a maintainer? I agree, using gpg on yubikey for password encryption is ideal. My only problem with it is that nobody makes money, so who is maintaining it?

Capitalism continues to wow the masses
Post reply on HN