What differentiates RememBear from other password managers? After looking through the blog and website it's not immediately clear to me. What makes (or will make) RememBear better than, say, 1password, which appears to have the same features, is also easy to use, and has a long history with which to work out issues?
Introducing Remembear, new password manager
41–50 of 98 posts
Re: Introducing Remembear, new password manager
#42What differentiates RememBear from other password managers? After looking through the blog and website it's not immediately clear to me. What makes (or will make) RememBear better than, say, 1password, which appears to have the same features, is also easy to use, and has a long history with which to work out issues?
Their Bearanding
Re: Introducing Remembear, new password manager
#43I use 1Password, and the only incentive which make me switch is completely open source good quality UX solution.
Re: Introducing Remembear, new password manager
#44Seems to be yet another proprietary walled garden. No thanks.
Can you recommend any reputable open source password managers?
It's primarily a password generator, rather than a password manager. It reproducibly generates difficult-to-guess passwords, using as input: the site's URL, your username and a master password. You save, sync and retrieve your passwords using your browser's built-in password manager.
I never previously used a password manager because I wanted to ensure I would always have access to my passwords. I started using LessPass because:
* When I need to log in on a non-synced device (such as someone else's computer), I can read the site's password from Firefox on my phone and transcribe it. * If I lose all of my devices, I can still retrieve my existing passwords, because the password generation algorithm uses only my master password as salt.
Re: Introducing Remembear, new password manager
#45It might be a good alternative to Enpass. They use Rust and libsodium, which is a good sign. But browser integration is the trickiest part in a modern password manager, yet what makes a password manager actually usable for most people. So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here. Making these extensions smart (able t…
> So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here. Do you have a source for that? We are currently using teampasswordmanager.com and I was wondering if there are any known security issues I have not heard about. Altgough the author refused to provide the sourcee, I had a look at the Chrome Extension anyway, but any addit…
https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
Re: Introducing Remembear, new password manager
#46Earlier quoted context omitted.
What password manager do you recommend?
I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread. It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!
Re: Introducing Remembear, new password manager
#47From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
> As far as the actual five security vulnerabilities discovered during testing are concerned, one important point to make is that not a single problem was deemed to be of a “Critical” severity or security implications. For the two issues ranked as “High”, the first problem had to do with a design flaw around the autofill functionality and incorrect handling of top level domains
> They are grounded in the deployment of libsodium, which is a state-of-the- art cryptographic library. While various notes and suggestions were collected during the cryptographic analysis, no severe implementation-related vulnerability was spotted. In other words, it is believed that a real-world attacker would remain powerless in face of the employed defense mechanisms
> All in all, the RememBear is a robust and promising project.
Re: Introducing Remembear, new password manager
#48- Written in Rust. Cool.
- Cool marketing.
- Cool name.
- Online only. Not gonna trust my passwords with anyone, sorry (even encrypted).
- Good (upcoming) crossplatform support.
Looks like they are competing with LastPass and not the 1Password (Desktop) and Keepasses of the world.
Re: Introducing Remembear, new password manager
#49I use 1Password, and the only incentive which make me switch is completely open source good quality UX solution.
So.. KeePassXC?
This is not really an acceptable UI for OSX
Re: Introducing Remembear, new password manager
#50>RememBear encrypts your passwords using both your Master Password and a unique device key generated by the application. It stores your passwords in an encrypted file on your device and on our secure servers for sync and backup purposes. However, RememBear will only encrypt and decrypt the items on your physical device. This means that your passwords and other items are always encrypted during syncing and remain encrypted when in storage on our secure servers. You and ONLY you are ever able to access your items as long as you keep your master password private.
Proprietary sync, no thanks.