From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
Introducing Remembear, new password manager
21–30 of 98 posts
Re: Introducing Remembear, new password manager
#22From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
> It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical
> it has been noticeable that the development process of the RememBear suite was affected by tight deadlines. Evidencing this was the fact that builds were generally provided only one or two days before actual testing started, leaving little room for in-depth reconnaissance
TunnelBear's pull-quote @ https://www.remembear.com/blog/remembear-security-audit/:
> we’re proud to share that no critical security issues were discovered
I'd consider putting credentials on an incorrect domain a showstopper for a password manager, but whatever.
Re: Introducing Remembear, new password manager
#23Re: Introducing Remembear, new password manager
#24Seems to be yet another proprietary walled garden. No thanks.
Can you recommend any reputable open source password managers?
Re: Introducing Remembear, new password manager
#25Seems to be yet another proprietary walled garden. No thanks.
Can you recommend any reputable open source password managers?
Keepass (and keepassX and keepassC)
Re: Introducing Remembear, new password manager
#26Seems to be yet another proprietary walled garden. No thanks.
Can you recommend any reputable open source password managers?
https://www.justwatch.com/gopass/ https://github.com/justwatchcom/gopass
Re: Introducing Remembear, new password manager
#27What differentiates RememBear from other password managers? After looking through the blog and website it's not immediately clear to me. What makes (or will make) RememBear better than, say, 1password, which appears to have the same features, is also easy to use, and has a long history with which to work out issues?
Their VPN software is apparently very easy to use (from reddit comments). The same will probably apply to the password manager. They also seem to have a good marketing and PR team since I see them around quite a bit in youtube videos (Linus' being the most prominent one) and ads thinly veiled as articles. These two points alone have the ability to make the difficult mainstream user market to use it.
If all your security tools had similar UX and only a single login (what we see as single point of failure is usually seen as convenience), then you'll get many people to use it.
Re: Introducing Remembear, new password manager
#28From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
That report: https://cure53.de/pentest-report_remembear.pdf > It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical > it has been noticeable that the development process of the RememBear suite was affected by tight deadlines. Evidencing this was the fact that builds were generally…
Re: Introducing Remembear, new password manager
#29From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
Re: Introducing Remembear, new password manager
#30I use 1Password, and the only incentive which make me switch is completely open source good quality UX solution.