KeepassC – Curses based keepass written in Rust
raymontag.github.io
raymontag.github.io
Not trying to debunk this or anything, but could anyone expand on this (eg. what does secure mean in this context)? Has the author written somewhere about his decision (I couldn't find anything)?
While Rust is considered a "safe" language, I think the term is a little misleading. I prefer "memory-safe." There are plenty of ways to mess up something like a password manager that don't involve failures of memory safety.
Additionally, Rust is only memory-safe to the extent that you do not use unsafe code and that includes the libraries that your project depends on.
That said, I am not qualified to evaluate the security of this project. It may very well be that this password manager is very secure.
In much the same way other languages are only memory-safe to the extent that you don't use an FFI (or make sure you're using theme safely). You can trivially segfault CPython with ctypes.
Though unsafe code is probably more common in Rust than native code is in Ruby or Python owing to it being in closer reach and not requiring language switch and great complexity increase in distribution.
> probably more common
It depends. The idea with unsafe is to wrap it up inside of a library, and expose a safe interface, keeping the surface area as small as possible. So libraries will sometimes use unsafe code, but application code generally doesn't. Cargo, for example, has no unsafe in it. Regex, currently at the top of the benchmarks game, has no unsafe in it, even as a library.[1] upd: besides ctypes, but not sure if we can consider this builtin or not...
- ability to reliably erase memory that held passwords/keys with assurance it wasn't copied accidentally. AFAIK Python doesn't guarantee zeroing of freed memory.
- type safety, error handling enforced by the type system, and race-condition-free concurrency might be an extra assurance.
http://www.daemonology.net/blog/2014-09-04-how-to-zero-a-buf...
I'm the author of KeePassC and yes these are the main reasons to write KeePassC new in Rust. I had a private repo with a C implementation, however after a friend pointed me to Rust I decided to give it a try and was immediately fascinated. The reason for the rewrite in Rust is _not_ that I'm unconvinced with the original project.
There are some problems though, as stated in another post, especially with this write_bytes-thing. But I'm working on this.
https://doc.rust-lang.org/core/intrinsics/fn.volatile_set_me...
I know it's very tricky in presence of an optimizer. The current implementation in KeePassC uses the pointer after memset in Drop, so it might be just lucky (https://github.com/raymontag/rust-keepass/issues/4).
http://doc.rust-lang.org/1.1.0/test/fn.black_box.html
I've never actually tried it outside of tests, so I don't know if it applies here.
C only promises the behavior of the C abstract machine. Data will randomly get spilled from registers into random places on the stack where you may be completely unable to reach them to zeroize them.
All you can do is best effort, in C-- I wouldn't expect rust to be better here.
https://github.com/raymontag/rust-keepass/blob/2b7b701b69541...
unsafe { ptr::write_bytes(self.encrypted_string.as_ptr() as *mut c_void, 0u8, self.encrypted_string.len()) };
?I'm a bit surprised that there isn't currently a Linux distro that focuses on curses/ncurses apps. And if anyone is looking for the gap in the curses market there's no word processors. (Plenty of text editors though.)
Is there a need for one? You can use all distributions without a graphical UI.
> And if anyone is looking for the gap in the curses market there's no word processors
Yeah, I've been wondering about that. People (including not-so-casual writers like GRRM) still swoon about programs like Wordstar, but it seems all Linux terminal users are content with using vim/emacs/nano/… with TeX (or lately Markdown).
I doubt the niche for rich-UI text based apps like that and it's ilk (Lotus 123 anyone?) exists for enough people to make writing/maintaining one worth while - you'd either be happy with less (markdown and a post processor) or end up wanting more than such a UI could practically provide, I expect.
Though I'm sure you'll find a WordPerfect mode for emacs somewhere, if you are feeling nostagic!
I guess, OP posted the link to the blog post to highlight some reasoning behind the switch, not the code itself.
The "reimplement" links to the Rust repository in question.
I haven't looked at those 3rd party clients mentioned on their website but I would say a console based command isn't an option for most people when there are password managers that come with a simple management gui and a convenient keyboard shortcut that insert the right account and password information directly into html login forms in your browser.
As others mention, I wish there was a built in way of protecting the meta-data. I guess it wouldn't be that hard to just encrypt/decrypt the entire directory myself.