This is such a great application. I feel like it's complete already and would be happy if it just continued to exist without much or any maintenance.
Android "Password Store" client for pass discontinued
21–30 of 60 posts
Re: Android "Password Store" client for pass discontinued
#22This is actually a better outcome than finding out one day the app have a serious security problem. While i like `pass` and that Android app looked really good, this is just not serious. Because the fact that most people will end up trusting a random app as their password manager because it has 2k star on Github is crazy. If you want to use `pass` on Android you should tinker something with termux .
Re: Android "Password Store" client for pass discontinued
#23I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…
What's your threat model here? Some kind of mass hacking attempt? It would be easier to attack the service providers, rather than steal legitimate logins.
A targeted attack on a specific person? It would be easier to, as the famous XKCD suggests, drug and/or hit them with a wrench until they voluntarily hand over whatever information you want.
It's difficult to conceive of a situation where hacking password managers is the path of least resistance.
Re: Android "Password Store" client for pass discontinued
#24This is actually a better outcome than finding out one day the app have a serious security problem. While i like `pass` and that Android app looked really good, this is just not serious. Because the fact that most people will end up trusting a random app as their password manager because it has 2k star on Github is crazy. If you want to use `pass` on Android you should tinker something with termux .
Re: Android "Password Store" client for pass discontinued
#25I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…
> add a back door? What's your threat model here? Some kind of mass hacking attempt? It would be easier to attack the service providers, rather than steal legitimate logins. A targeted attack on a specific person? It would be easier to, as the famous XKCD suggests, drug and/or hit them with a wrench until they voluntarily hand over whatever information you want. It's difficult to conceive of a situation where hacking…
Re: Android "Password Store" client for pass discontinued
#26I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…
This.
It is just slightly more difficult and longer to target it in a large company because you usually have to actually be hired by that company and do not necessarily have the choice of the team/products you will be working on.
But adding backdoors and vuln, yes totally possible on random products that person would be affected to. There is review fatigue the same way there is fatigue in a lot of processes.
Re: Android "Password Store" client for pass discontinued
#27I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…
> add a back door? What's your threat model here? Some kind of mass hacking attempt? It would be easier to attack the service providers, rather than steal legitimate logins. A targeted attack on a specific person? It would be easier to, as the famous XKCD suggests, drug and/or hit them with a wrench until they voluntarily hand over whatever information you want. It's difficult to conceive of a situation where hacking…
Re: Android "Password Store" client for pass discontinued
#28In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?
Turns out living the FOSS dream is kind of hard.
It is more about individual developpers/small teams versus large companies.
Re: Android "Password Store" client for pass discontinued
#29I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…
> Or maybe not? This. It is just slightly more difficult and longer to target it in a large company because you usually have to actually be hired by that company and do not necessarily have the choice of the team/products you will be working on. But adding backdoors and vuln, yes totally possible on random products that person would be affected to. There is review fatigue the same way there is fatigue in a lot of pro…
Re: Android "Password Store" client for pass discontinued
#30This seems to happen more and more often, or at least it feels that way to me. FLOSS projects that aren't highly critical but very useful are maintained by only one person which loses interest, burns out or simply has other priorities. Sometimes they don't even make an announcement like here and just ghost the project. Very sad, even though understandable.