Live data from Hacker News

Introducing Remembear, new password manager

remembear.com

81–90 of 98 posts

Re: Introducing Remembear, new password manager

#81
post #62
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

> This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before. Yes, and it's getting really old. I'm tired of seeing security consulting firms wax poetic about how good the client's security is in their reports, then bend over backwards to frame obviously serious findings in the best possible light. Th…

This person gets it. At least NCC doesn't pretend to say something is secure or not. People are getting used to Cure53 reports like they're normal.

Re: Introducing Remembear, new password manager

#82

Earlier quoted context omitted.

Ohh I like the idea of knowing the password requirements for the top 1000 websites!

Would it be wrong to wish this could (or should?) be standardized? That is, for example, one upper case letter, same special characters, etc. The lack of a standard seems to hurts users more than hackers. The hackers know it and adjust. User just get confused and default to overly simplistic and common PWs.

NIST recently updated their standard guidance to no specific characteristics requirements, just long and unique. But no doubt it will take a while to trickle down to many websites that they don’t need this craziness any more.

Re: Introducing Remembear, new password manager

#83

Earlier quoted context omitted.

I would like to see a version of 1Password that 1) did only passwords - no fishing licenses and secure notes, which adds UX complexity 2) did not distinguish between passwords and logins, which causes endless confusion for my users 3) knew and managed the text requirements for the top 1000 websites so the app could generate legitimate passwords and not ask users to manage password complexity

Ohh I like the idea of knowing the password requirements for the top 1000 websites!

What if there were a protocol for password management, such that you never had to use a signup form again? Kind of like OAuth, but for a password generator/manager. It would support password changing (with an e-mail confirmation), so that it would be extremely easy for people to convert from manually managed passwords to automatically managed.

Re: Introducing Remembear, new password manager

#84
post #11

From the Cure53 report: the version tested had a terrible vulnerability (unfortunately somewhat common to password managers): it tries to match passwords to subdomains, and in doing so misparses domains, allowing it to be tricked into giving passwords to bogus almost-look-alike domains. Yikes. Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors…

Props for using 'effusive' and 'throw shade' in contiguous sentences.

Re: Introducing Remembear, new password manager

#85
post #36

Earlier quoted context omitted.

What password manager do you recommend?

I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread. It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!

I don't understand this response. Why would it be improper to discuss alternative products?

I don't know you, so I guess you have a vested interest? Is that it?

Re: Introducing Remembear, new password manager

#86
post #27

Earlier quoted context omitted.

I feel the company's modus operandi is to have easy and cute UX to simplify using security tools. Their VPN software is apparently very easy to use (from reddit comments). The same will probably apply to the password manager. They also seem to have a good marketing and PR team since I see them around quite a bit in youtube videos (Linus' being the most prominent one) and ads thinly veiled as articles. These two point…

I use TunnelBear, and I can say it works beautifully. It really is just turn on, turn off.

But it does not work very well. Often it does not connect at all, is very slow, and it blocks many things like TeamSpeak and torrents, for example.

Re: Introducing Remembear, new password manager

#87
post #71

Earlier quoted context omitted.

So.. KeePassXC?

Browser integration is poor at best. I've given it multiple goes and walked away disappointed every time.

I'm not having any issues with https://addons.mozilla.org/en-US/firefox/addon/keepasshttp-c... and https://chrome.google.com/webstore/detail/chromeipass/ompiai.... My only annoyance is that KeepShare's autofill doesn't pick up Firefox Android's password fields, but Chrome works fine there.

KeePassXC has a KeePassHTTP server built-in, so no plugins needed on that side.

Re: Introducing Remembear, new password manager

#88
post #36

Earlier quoted context omitted.

I feel OK talking about the audit report, the basics of security for password managers, and the dynamics of using an audit report to market a product, and I feel OK talking about what my preferred password manager is, but it occurred to me I wasn't psyched about doing both on the same thread. It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!

I don't understand this response. Why would it be improper to discuss alternative products? I don't know you, so I guess you have a vested interest? Is that it?

No, I do not.

Re: Introducing Remembear, new password manager

#89
post #79
post #77

Earlier quoted context omitted.

There should be a "robot.txt" for passwords. ie: /password.txt This file could define the accepted password format. Password managers could retrieve that file and know exactly how to generate a password.

no. if you're going to go through the trouble to do that, just fix your bullshit broken fucking password requirements.

The password - as currently implemented - is a fax machine (read: dated technology). Anyone reasonable sees it's far from ideal. Yet there seems to be little _significant_ innovation on solving this problem with something better.

I can order a pizza via Twitter, but I'm still using passwords?

Re: Introducing Remembear, new password manager

#90

Earlier quoted context omitted.

I use TunnelBear, and I can say it works beautifully. It really is just turn on, turn off.

But it does not work very well. Often it does not connect at all, is very slow, and it blocks many things like TeamSpeak and torrents, for example.

That's probably true...

I use it for very basic things, so I guess I wouldn't know.

Post reply on HN