Live data from Hacker News

Firefox Lockbox

testpilot.firefox.com

141–150 of 156 posts

Re: Firefox Lockbox

#141

I'm disappointed. Instead of making password management modular, so any password manager capable of certain queries and operations (KeePass, LastPass, Bitwarden, KWallet/Gnome Keyring/libsecret, Microsoft Credentials Management API, Apple Keychain, etc) could become a storage backend with some programming effort... they're doing the exact opposite - they've created yet another password manager UI and yet another prop…

Seriously, if you put Mozilla in the same box as Google, Microsoft and Apple, then you are ignoring company culture completely.

Yes, I want a big privacy oriented, non profit organization with strong engineering practices to handle my passwords. This is not Google, Microsoft or Apple.

I only wish Mozilla wasn't American due to the insane laws about "national security".

Re: Firefox Lockbox

#142
post #136

Earlier quoted context omitted.

Just plain old Lockfox. However, I understand you probably have some branding/marketing/PR concerns to keep in mind with naming.

Lockfox sounds like something that breaks or works around locks to me, fox being a sneacky tricky animal; not really reassuring.

>> "fox being a sneacky tricky animal"

Foxes are good and pure creatures.

Re: Firefox Lockbox

#143

If this is any good I'll be considering it as a replacemnt for Keepass. A bit off topic, but while looking at this I noticed another expirement - Firefox Side View. It looks like it lets you have two open tabs side-by-side in one browser window. This is exactly why I used the Tile Tabs[0] extension and had to switch to Tile Tabs WE[1] with the Quantum update. I'm happy to see this coming back without the WE workaroun…

Ot: Shouldn't your window manager handle this ? Consider using i3wm if it does not. Does this work seamless with other web extensions ? As a webextension developer i do not know how those tabs will be handled. I do not see any benefits using this.

Re: Firefox Lockbox

#144
post #136

Earlier quoted context omitted.

Lockfox sounds like something that breaks or works around locks to me, fox being a sneacky tricky animal; not really reassuring.

>> "fox being a sneacky tricky animal" Foxes are good and pure creatures.

But it has certain connotations in many cultures, which is not positive. I too like them and know they aren't a part of our value system, but naming a security product that is meant to protect your valuable stuff "fox" is like calling a bank Robbers&co.

Re: Firefox Lockbox

#145
post #80

Earlier quoted context omitted.

I, too, want to know the implementaion details. That said I’ve watched hundred of eyes gloss over as I emphatically implored lay-persons about password policies and tools like password managers and Frankly their definition of ‘secure’ can be encapsulated in ‘256-bit encryption’. An oversight on Mozilla’s part for security-types and engineers, but maybe they have the masses in mind with this tool & it’s marketing site…

Do the masses have any idea of what "256-bit encryption" would mean anyway?

Not at all! But that’s what all the other security whitewash on financial and ecommerce sites say, so to most folks it, like, totally means it’s really really secure— pinky swear!

Re: Firefox Lockbox

#146
post #144

Earlier quoted context omitted.

>> "fox being a sneacky tricky animal" Foxes are good and pure creatures.

But it has certain connotations in many cultures, which is not positive. I too like them and know they aren't a part of our value system, but naming a security product that is meant to protect your valuable stuff "fox" is like calling a bank Robbers&co.

That was humor. I'm aware of the centuries of anti-fox propaganda.

Re: Firefox Lockbox

#147

Earlier quoted context omitted.

They are on day one, sure, but if the file format is documented and clear then there's no reason why other managers couldn't interoperate. It's not as good as using an existing standard, but I'm not sure there is _an_ existing standard right now.

> I'm not sure there is _an_ existing standard right now I think there is none, except for the OS-provided APIs (but those have complications of their own, e.g. Chrome had dropped Apple Keychain support for a reason). > there's no reason why other managers couldn't interoperate Why would they? I don't think anyone was invited to this party. And I find it highly unlikely someone will bother to interoperate beyond impl…

That isn't what proprietary means, though. Every criticism you level at this file format _can also be levelled at the others_. There's no way around that at this stage. The only way mozilla could not have caused that problem is to not have built anything like this.

Re: Firefox Lockbox

#148

This is interesting, and I'm looking forward to seeing where it goes. However, it's very unlikely to replace Bitwarden for me.

There is a surprising lack of unit tests in Bitwarden, which is mostly maintained by one person. If Mozilla can apply its rigorous engineering practices to maintaining an open source password manager with all the features I use, I will switch from my current system.

I'll admit that some of the Bitwarden clients are... less reliable than I would like.

Re: Firefox Lockbox

#149

Earlier quoted context omitted.

Totally reasonable. I figure the people who write the unofficial ports I use have a personal reputation to protect. It bothers me a lot that the "professional" password management people disclaim all of their liability and just expect me to hope that it works the way they want.

I kind of figure almost the opposite - those commercial entities have both the resources (hopefully) for subject matter experts and auditing (also hopefully) and a strong financial interest in not having a disclosed breach (and almost all significant breaches are likely to be disclosed/discovered at some point). On the other side a small development team of individuals seem (to me) less likely to have the resources a…

Because they don't offer to save your passwords the breach can always just be if someone attacks your personal computer, which is so much less likely than that someone tries to attack a company which hosts thousands or even millions password databases.

In the open source world you have at least the possibility that someone who you trust looks at the code, with the closed source you don't.

Re: Firefox Lockbox

#150

Why not integrate it with the mobile browser like Chrome does on Android? Am I missing something?

Firefox on iOS provides an integrated experience for logins and filling those logins into browser forms automatically.

The team is currently working on autofill from Lockbox into other apps: https://github.com/mozilla-lockbox/lockbox-ios/issues/486. This will only be available in iOS12 when that ships.

Are there other kinds of integration you see as valuable?

Post reply on HN