Live data from Hacker News

Mitro Releases a New Free and Open Source Password Manager

eff.org

21–30 of 131 posts

Re: Mitro Releases a New Free and Open Source Password Manager

#22

I received this by email shortly after installing Mitro: "Congratulations on adding your first secret to Mitro" This makes me a little uncomfortable. How do they know? Why should they know? Edit: I could not find those words in the github repo.

Secrets are stored on Mitro's servers. Presumably -- hopefully -- the passwords themselves are encrypted. Edit: Ah, yes: Mitro is distinctive amongst free/open source password managers in that it's architected around cloud storage. For security, the online password databases are encrypted with client-side keys derived from your master password. For availability, they are mirrored across three cloud storage providers.…

This I understand very well.

So presumably they sent the email only after I sent them the first "blob of gibberish" telling them I added _at least_ one entry to my password database.

Presumably they don't know if and when or how may entries I have. In this case they only noticed the first time I sent in my encrypted database.

Re: Mitro Releases a New Free and Open Source Password Manager

#26

No information or demo on the webpage = Worthless.

Presumably the code is released first, then the documentation is created. It sounds like the product wasn't initially developed with the idea that it would be released to others. That doesn't make it worthless. If Twitter spent the time + money to acquire them and open-source their product, I would assume that they have a vested interest in doing more than just dumping the code on Github and ignoring it.

Re: Mitro Releases a New Free and Open Source Password Manager

#27

Currently using KeePassX + Dropbox. What sort of benefits would I get from Mitro?

Currently, this is the best option. Though I recommend KeePass proper as opposed to X since KeePassX's last stable release was over 4 years ago and they've only pushed out alpha builds since then.

Re: Mitro Releases a New Free and Open Source Password Manager

#28
post #2

We're very excited to make this available to the community and welcome pull requests, bug reports, etc.. Pitch in on Github: https://github.com/mitro-co/mitro

Congratulations on the release guys. Would you mind talking about your strengths and weaknesses compared to KeepassX?

For starters, maybe we should ask why Mitro is only using 128­bit AES (stated in their PDF design doc)?

Re: Mitro Releases a New Free and Open Source Password Manager

#29

Since the company has been acquired what are the plans for the service? http://labs.mitro.co/ says that "The service will continue to operate as-is for the foreseeable future." but there is a lot of ambiguity in 'forseeable.' While I really appreciate the value of having the client and server code open sourced I don't want to run my own server nor do I want to sign up for a service that, with the changes that will li…

"Mitro has committed to funding continued operations of its servers until at least the end of 2014. If their code proves to be secure and popular with the community, we will be advising them on how to create a sustainable home for that infrastructure.". Erh. Yes, so I'll be staying on KeePass, strategically "cloud" backupped in encrypted form to my email address (also, yes, this does not solve Android integration..etc. so suggestions are welcome!)

Re: Mitro Releases a New Free and Open Source Password Manager

#30

Since the company has been acquired what are the plans for the service? http://labs.mitro.co/ says that "The service will continue to operate as-is for the foreseeable future." but there is a lot of ambiguity in 'forseeable.' While I really appreciate the value of having the client and server code open sourced I don't want to run my own server nor do I want to sign up for a service that, with the changes that will li…

"Mitro has committed to funding continued operations of its servers until at least the end of 2014. If their code proves to be secure and popular with the community, we will be advising them on how to create a sustainable home for that infrastructure.". Erh. Yes, so I'll be staying on KeePass, strategically "cloud" backupped in encrypted form to my email address (also, yes, this does not solve Android integration..et…

KeePassDroid? http://www.keepassdroid.com/
Post reply on HN