Live data from Hacker News

Firefox Lockbox

testpilot.firefox.com

121–130 of 156 posts

Re: Firefox Lockbox

#121
post #116

Earlier quoted context omitted.

For Mozilla to be successful they have to appeal to the largest demographic possible. I'd only ask that Mozilla make additional technical information easy to find and well laid out. This is LastPass's page: https://lastpass.com/support.php?cmd=showfaq&id=1096 But that too you won't find when you use the app/extension normally.

Mozilla can do a lot of things that harm users or the general public but increase its success. Mozilla shouldn't do these things.

This neither harms users nor the general public, so I don't see relevance.

Re: Firefox Lockbox

#122
Nice, will check it out! FF is already my default browser. One question though, is there a good way to import from other exported sources such as LastPass or KeepassXC?

Re: Firefox Lockbox

#123

If this is any good I'll be considering it as a replacemnt for Keepass. A bit off topic, but while looking at this I noticed another expirement - Firefox Side View. It looks like it lets you have two open tabs side-by-side in one browser window. This is exactly why I used the Tile Tabs[0] extension and had to switch to Tile Tabs WE[1] with the Quantum update. I'm happy to see this coming back without the WE workaroun…

The reason I haven't switched to Keepass is its very decentralized nature - not in terms of how it stores data, but in terms of it being a format not a unified set of tools.

Maybe I'm misunderstanding it, but it feels to me like I can get Keepass (v2.x or v1.x) for Windows from a somewhat-official source. I can also run that v2.x on Linux or OSX via Mono (via the packages on the download page?), or I can use any of 4 unofficial OSX ports or 2 unofficial Linux ports, plus any of several unofficial browser ports, plus an unofficial webserver based port, plus 3 unofficial Android ports or a bunch of unofficial iOS ports. It's not clear to me how many (if any) of these are actual "ports" of the software not "reimplementations of the file format," nor is it clear to me whether any or all of them are audited (or who's doing that if they are).

Basically, massive fragmentation and independently developed clients in the software that I'd use to store all my passwords behind a strong master key creeps me the f out. I don't have the time, math or detailed language knowledge to personally audit a bunch of cryptography implementations in a bunch of different languages and I know it, and I'm not sure I'd pick up any obfuscated transmission or concealment of security/decryption information, but I also don't feel like I have a trustworthy source that I know is doing that auditing.

Re: Firefox Lockbox

#124
post #53

Earlier quoted context omitted.

Hm, enpass seems to be closed source which makes it unusable for me to store all my passwords basically because of the same as someone wrote in their forum: "The fact that Enpass isn't submitting all my passwords to enpass.io right now doesn't mean anything. I'm currently using iptables to restrict Enpass from doing so, but I don't know yet how to archive the same thing on my unrooted Android."

That's the problem I have with all of the commercial password managers: I simply don't trust them. I find it incredibly telling that every big password manager has a mandatory, binding arbitration clause in their user agreements. This tells me that I am supposed to take their word on everything yet I have zero recourse to a neutral third party if the password manager company leaks (or intentionally hands over) all of…

Unfortunately, I have a similar issue with things like Keepass - perhaps the core project has enough eyes on it, but how about all those "Contributed/Unofficial KeePass Ports"?

Re: Firefox Lockbox

#125

Earlier quoted context omitted.

That's the problem I have with all of the commercial password managers: I simply don't trust them. I find it incredibly telling that every big password manager has a mandatory, binding arbitration clause in their user agreements. This tells me that I am supposed to take their word on everything yet I have zero recourse to a neutral third party if the password manager company leaks (or intentionally hands over) all of…

Unfortunately, I have a similar issue with things like Keepass - perhaps the core project has enough eyes on it, but how about all those "Contributed/Unofficial KeePass Ports"?

Totally reasonable. I figure the people who write the unofficial ports I use have a personal reputation to protect. It bothers me a lot that the "professional" password management people disclaim all of their liability and just expect me to hope that it works the way they want.

Re: Firefox Lockbox

#126

I am considering this but worry that mozilla has a history of shutting down initiatives and products.

A history of shutting down site-identity related products, no less. [1] The fact that it's not on Android as of day one looks pretty bad too; the sort of developers who think iOS obviously comes first are (in my experience) likely to be chasing hype and their apps are dead in a year (or at least still not on Android). I don't know if that's the case here, but I have no interest in using this until it's been adopted by Mozilla as more than an experiment and has several years of strong support.

[1] https://developer.mozilla.org/en-US/docs/Archive/Mozilla/Per...

(I admit I'm biased here but I'm still bitter about them nixing Persona.)

Re: Firefox Lockbox

#127

Earlier quoted context omitted.

Unfortunately, I have a similar issue with things like Keepass - perhaps the core project has enough eyes on it, but how about all those "Contributed/Unofficial KeePass Ports"?

Totally reasonable. I figure the people who write the unofficial ports I use have a personal reputation to protect. It bothers me a lot that the "professional" password management people disclaim all of their liability and just expect me to hope that it works the way they want.

I kind of figure almost the opposite - those commercial entities have both the resources (hopefully) for subject matter experts and auditing (also hopefully) and a strong financial interest in not having a disclosed breach (and almost all significant breaches are likely to be disclosed/discovered at some point). On the other side a small development team of individuals seem (to me) less likely to have the resources and more ability to simply walk away in case of a breach.
Post reply on HN