Live data from Hacker News

Android "Password Store" client for pass discontinued

github.com

11–20 of 60 posts

Re: Android "Password Store" client for pass discontinued

#12
This is actually a better outcome than finding out one day the app have a serious security problem.

While i like `pass` and that Android app looked really good, this is just not serious.

Because the fact that most people will end up trusting a random app as their password manager because it has 2k star on Github is crazy.

If you want to use `pass` on Android you should tinker something with termux .

Re: Android "Password Store" client for pass discontinued

#14

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

fwiw i've recently moved to sharing my kpdb using taildrive. The KeePass Android app can open databases from WebDAV

Re: Android "Password Store" client for pass discontinued

#15

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

The reason is the idea of a free operating system and software has been shattered and is now a guest in big corporations and Github.

It still kind of work but it is starting to crack in a few places.

Re: Android "Password Store" client for pass discontinued

#16

This is actually a better outcome than finding out one day the app have a serious security problem. While i like `pass` and that Android app looked really good, this is just not serious. Because the fact that most people will end up trusting a random app as their password manager because it has 2k star on Github is crazy. If you want to use `pass` on Android you should tinker something with termux .

In actually SSH into my desktop PC and use pass there to access my secrets.

Luckily, I only need to do this occasionally, so the inconvenience is bearable. Still waiting on the day where I randomly get logged out of an important app while not having internet access, or the power going out in my apartment right after I leave for two weeks (happened once, luckily didn't need my passwords then).

Re: Android "Password Store" client for pass discontinued

#17
post #14

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

fwiw i've recently moved to sharing my kpdb using taildrive. The KeePass Android app can open databases from WebDAV

For iOS, Keepassium can use WebDAV as well.

Re: Android "Password Store" client for pass discontinued

#18

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

I've been using keepass for quite a number of years now. I have my database and a security key. I sync my database with dropbox (because I am too lazy to self-host something like nextcloud) between devices and just manually copy my key on everry device. My key was never synced through the internet.

I hope that's secure enough and works fine for me. I guess syncthing is just smaller and obviously doesn't need a third party?

Re: Android "Password Store" client for pass discontinued

#19

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

Turns out living the FOSS dream is kind of hard.

Re: Android "Password Store" client for pass discontinued

#20
I worry a lot about password managers on mobile. Such as:

* if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families?

* if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromised by money or threats?

* Would password managers from Google/apple/microsoft fare better because they already face these risks and have controls? Or maybe not?

Post reply on HN