Live data from Hacker News

Android "Password Store" client for pass discontinued

github.com

51–60 of 60 posts

Re: Android "Password Store" client for pass discontinued

#51

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

I've been using keepass for quite a number of years now. I have my database and a security key. I sync my database with dropbox (because I am too lazy to self-host something like nextcloud) between devices and just manually copy my key on everry device. My key was never synced through the internet. I hope that's secure enough and works fine for me. I guess syncthing is just smaller and obviously doesn't need a third…

[deleted]

Re: Android "Password Store" client for pass discontinued

#52
post #19

Earlier quoted context omitted.

Turns out living the FOSS dream is kind of hard.

Tbh the same struggle affect proprietary software. It is more about individual developpers/small teams versus large companies.

You have financial gain to show when proprietary software ends. When FOSS ends, you just have the experience. That’s fine for some, know what you’re getting into.

Re: Android "Password Store" client for pass discontinued

#53

Earlier quoted context omitted.

Tbh the same struggle affect proprietary software. It is more about individual developpers/small teams versus large companies.

You have financial gain to show when proprietary software ends. When FOSS ends, you just have the experience. That’s fine for some, know what you’re getting into.

The license doesn't have anything to do with the financial gain. There are plenty of proprietary freeware and OSS devs who sell their apps on the playstore.

Re: Android "Password Store" client for pass discontinued

#54

I worry a lot about password managers on mobile. Such as: * if an app has a single developer (keepassium? strongbox?), how much money would it take them to add a back door? 1M USD? 10M USD? Let’s say they are exceptionally honest, and won’t take money. How about threats to their lives or families? * if an app has a small number of engineers with commit access (bitwarden? 1paasword?) could any one of them be compromis…

I'm really confused. How do you think that would work with an opensource password manager like pass / password-store.org - The data is stored in Git at a location of your choosing and security level - The data encryption is provided by GnuPG using your personal key This is why I use it, there's no potential for anyone to add a back door, except me. BitWarden, LastPass, etc etc... you have a point, and I would not tru…

pass clients can totally be backdoored. They decrypt the secret to plain text and add it to your clipboard or whatever... could easily shuttle it off somewhere else at that point.

Re: Android "Password Store" client for pass discontinued

#55
post #41

Earlier quoted context omitted.

yes, it's my biggest worry too. At least with keepassDX on android there is no internet access permission needed by default, but if a compromised update suddenly required it I don't know if Android would prompt about it since all apps have internet access granted without prompting :( I also wish it was possible to block automatic updates of specific apps on the play store... So at least we could be in control over up…

On GrapheneOS there is a prompt when installing an app that asks if you would like to grant network access. I am not sure if that pop up displays if network access is added later in an app update though.

I'm pretty sure I got prompted once or twice before updating to app with new permissions added.

Re: Android "Password Store" client for pass discontinued

#56

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

> Bitwarden has been trying to move away from a fully FOSS system

Again, as Harvey Dent said it…

Re: Android "Password Store" client for pass discontinued

#57
post #54

Earlier quoted context omitted.

I'm really confused. How do you think that would work with an opensource password manager like pass / password-store.org - The data is stored in Git at a location of your choosing and security level - The data encryption is provided by GnuPG using your personal key This is why I use it, there's no potential for anyone to add a back door, except me. BitWarden, LastPass, etc etc... you have a point, and I would not tru…

pass clients can totally be backdoored. They decrypt the secret to plain text and add it to your clipboard or whatever... could easily shuttle it off somewhere else at that point.

You build it from source if you have concerns, so no, it can't "totally be backdoored".

Re: Android "Password Store" client for pass discontinued

#58
post #19

In the past two days, the official Syncthing Android client has been discontinued, making the use of KeePass harder. Bitwarden has been trying to move away from a fully FOSS system. And now this?

Turns out living the FOSS dream is kind of hard.

Why? The app can still be built / installed / source forked etc.

That is the FOSS dream.

Post reply on HN