From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
> This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before. Yes, and it's getting really old. I'm tired of seeing security consulting firms wax poetic about how good the client's security is in their reports, then bend over backwards to frame obviously serious findings in the best possible light. Th…
Introducing Remembear, new password manager
81–90 of 98 posts
Re: Introducing Remembear, new password manager
#82Earlier quoted context omitted.
Ohh I like the idea of knowing the password requirements for the top 1000 websites!
Would it be wrong to wish this could (or should?) be standardized? That is, for example, one upper case letter, same special characters, etc. The lack of a standard seems to hurts users more than hackers. The hackers know it and adjust. User just get confused and default to overly simplistic and common PWs.
Re: Introducing Remembear, new password manager
#83Earlier quoted context omitted.
I would like to see a version of 1Password that 1) did only passwords - no fishing licenses and secure notes, which adds UX complexity 2) did not distinguish between passwords and logins, which causes endless confusion for my users 3) knew and managed the text requirements for the top 1000 websites so the app could generate legitimate passwords and not ask users to manage password complexity
Ohh I like the idea of knowing the password requirements for the top 1000 websites!
Re: Introducing Remembear, new password manager
#84From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…
Re: Introducing Remembear, new password manager
#85Earlier quoted context omitted.
What password manager do you recommend?
I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread. It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!
I don't know you, so I guess you have a vested interest? Is that it?
Re: Introducing Remembear, new password manager
#86Earlier quoted context omitted.
I feel the company's modus operandi is to have easy and cute UX to simplify using security tools. Their VPN software is apparently very easy to use (from reddit comments). The same will probably apply to the password manager. They also seem to have a good marketing and PR team since I see them around quite a bit in youtube videos (Linus' being the most prominent one) and ads thinly veiled as articles. These two point…
I use TunnelBear, and I can say it works beautifully. It really is just turn on, turn off.
Re: Introducing Remembear, new password manager
#87Earlier quoted context omitted.
So.. KeePassXC?
Browser integration is poor at best. I've given it multiple goes and walked away disappointed every time.
KeePassXC has a KeePassHTTP server built-in, so no plugins needed on that side.
Re: Introducing Remembear, new password manager
#88Earlier quoted context omitted.
I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread. It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!
I don't understand this response. Why would it be improper to discuss alternative products? I don't know you, so I guess you have a vested interest? Is that it?
Re: Introducing Remembear, new password manager
#89Earlier quoted context omitted.
There should be a "robot.txt" for passwords. ie: /password.txt This file could define the accepted password format. Password managers could retrieve that file and know exactly how to generate a password.
no. if you're going to go through the trouble to do that, just fix your bullshit broken fucking password requirements.
I can order a pizza via Twitter, but I'm still using passwords?
Re: Introducing Remembear, new password manager
#90Earlier quoted context omitted.
I use TunnelBear, and I can say it works beautifully. It really is just turn on, turn off.
But it does not work very well. Often it does not connect at all, is very slow, and it blocks many things like TeamSpeak and torrents, for example.
I use it for very basic things, so I guess I wouldn't know.