Introducing Remembear, new password manager
remembear.com
remembear.com
Meanwhile: they've got a crypto protocol tunneled over TLS "to avoid heartbleed" and some other convoluted stuff the auditors complain about. You really want to see a password manager get the basics right.
Notice also that the end of the Cure53 report complains about the project scope and the amount of time given. This is pretty unusual for Cure53, who have a reputation for being a bit effusive about the products they're paid to review. I'm not sure I've ever seen them throw shade before.
The problem is that they are going to keep adding code, but won't get a security audit with every update. So all it takes is a slight mistake for it to be vulnerable again. What you need is a strong in-house pentesting team to be sure about there not being any new vulnerabilities with each release. Or atleast a bug bounty starting with beta releases, and let them bake before releasing them publicly.
The fact that such serious vulnerabilities come up at the time of an audit shows that they don't have one.
> It can be observed that since the algorithm is removing up to two top level domains, it actually treats victim.co.uk, victim.com, victim.de and even test.victim.co.at as if they were identical
> it has been noticeable that the development process of the RememBear suite was affected by tight deadlines. Evidencing this was the fact that builds were generally provided only one or two days before actual testing started, leaving little room for in-depth reconnaissance
TunnelBear's pull-quote @ https://www.remembear.com/blog/remembear-security-audit/:
> we’re proud to share that no critical security issues were discovered
I'd consider putting credentials on an incorrect domain a showstopper for a password manager, but whatever.
It's not hard to figure out, but it's not a conversation I want to have on this thread. Thanks in advance!
I don't know you, so I guess you have a vested interest? Is that it?
> As far as the actual five security vulnerabilities discovered during testing are concerned, one important point to make is that not a single problem was deemed to be of a “Critical” severity or security implications. For the two issues ranked as “High”, the first problem had to do with a design flaw around the autofill functionality and incorrect handling of top level domains
> They are grounded in the deployment of libsodium, which is a state-of-the- art cryptographic library. While various notes and suggestions were collected during the cryptographic analysis, no severe implementation-related vulnerability was spotted. In other words, it is believed that a real-world attacker would remain powerless in face of the employed defense mechanisms
> All in all, the RememBear is a robust and promising project.
Yes, and it's getting really old. I'm tired of seeing security consulting firms wax poetic about how good the client's security is in their reports, then bend over backwards to frame obviously serious findings in the best possible light. That's not their job, their job is to report security vulnerabilities objectively, with sufficient coherence, context and reproduction steps so as to make the problem evident and motivate a solution.
Naturally, as soon as Cure53 decided to politely categorize what are clearly critical vulnerabilities as high severity, Remembear took to Twitter to crow about how much of a success the security audit was - "No critical findings!" I have serious reservations about the incentives at play between companies and the consultants paid to (security) review their products, especially when the report is publicized.
In my opinion, companies should not be using security consulting firms as a component in a press release. It encourages a mischaracterization of the state of the company's security and the severity of findings, and it puts a pressure on other security consulting firms to "play ball" and gush about their clients' products in publicized reports.
it's an industry secret that one of the reasons you do an audit is so you don't have to publish the "real" findings
I’m holding my breath...
"Schneier on Security: Security of Password Managers" https://www.schneier.com/blog/archives/2014/09/security_of_p...
But browser integration is the trickiest part in a modern password manager, yet what makes a password manager actually usable for most people.
So, give it some time before using the browsers (currently only Chrome) extension. Virtually all other password managers had security issues here.
Making these extensions smart (able to guess where login and password fields are, when passwords are being updated, etc) is also far from trivial. It's actually way more complex than password storage.
Gonna stick with Enpass for now, but that's definitely a project to watch.
Do you have a source for that? We are currently using teampasswordmanager.com and I was wondering if there are any known security issues I have not heard about.
Altgough the author refused to provide the sourcee, I had a look at the Chrome Extension anyway, but any additional info would be great.
https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
we will be introducing subscription-based pricing when RememBear leaves the public beta phase.
https://help.remembear.com/customer/en/portal/articles/28907...
A non-subscription product would be one thing that would get me to move off 1password.
This file could define the accepted password format. Password managers could retrieve that file and know exactly how to generate a password.
I can order a pizza via Twitter, but I'm still using passwords?
Instead they could create a "password complexity requirement specification" to allow sites to embed a universally machine readable description of their requirements, which all password managers and users could benefit from. I don't know if any such effort exists already.
Many ordinary people have no idea whatsoever of the relationships between clients and servers, and less still of that between different clients (what is a web app? Is gmail my search engine?). Throw in an interposing piece of software that not only manages but duplicates login credentials for these various mysterious entities, and they are completely and utterly despondent, hopeless and lost.
Their VPN software is apparently very easy to use (from reddit comments). The same will probably apply to the password manager. They also seem to have a good marketing and PR team since I see them around quite a bit in youtube videos (Linus' being the most prominent one) and ads thinly veiled as articles. These two points alone have the ability to make the difficult mainstream user market to use it.
If all your security tools had similar UX and only a single login (what we see as single point of failure is usually seen as convenience), then you'll get many people to use it.
I use it for very basic things, so I guess I wouldn't know.
Keepass (and keepassX and keepassC)
https://www.justwatch.com/gopass/ https://github.com/justwatchcom/gopass
https://discussion.enpass.io/index.php?/topic/210-open-sourc... https://www.enpass.io/legal-end-user-license-agreement/
It's primarily a password generator, rather than a password manager. It reproducibly generates difficult-to-guess passwords, using as input: the site's URL, your username and a master password. You save, sync and retrieve your passwords using your browser's built-in password manager.
I never previously used a password manager because I wanted to ensure I would always have access to my passwords. I started using LessPass because:
* When I need to log in on a non-synced device (such as someone else's computer), I can read the site's password from Firefox on my phone and transcribe it. * If I lose all of my devices, I can still retrieve my existing passwords, because the password generation algorithm uses only my master password as salt.
They're often recommended against, and it's dangerous to use one without a full understanding of the significant caveats.
See https://tonyarcieri.com/4-fatal-flaws-in-deterministic-passw..., the hacker news discussion, https://news.ycombinator.com/item?id=13016132, and notably the top comment there.
Let's hope they succeed, and inspire other companies to append a penultimate "a" after the penultimate "e", instead of just removing the penultimate "e".
This is not really an acceptable UI for OSX
There is also the Mac-first versiom, MacPass: https://github.com/mstarke/macpass
KeePassXC has a KeePassHTTP server built-in, so no plugins needed on that side.
A) No autofill. Copy and paste (but good simple shortcuts). Least attack vectors, but least convenient.
B) Autofill but only when user prompts (with shortcut). This avoids having to inject js into web pages. The web extension needs less overall permissions this way. It avoids certain attack vectors. Features would be less discoverable - you have to know to hit the shortcuts or click a browser icon.
C) Prompts to Autofill in the page. This is the most common technique, lastpass does it. Vulnerable against domain matching misparsing. It's a big attack vector but there are plenty of common password manager vulnerabilities that can be studied and mitigated against.
Or something else? Also what issues do you have with current open source password managers?
They seem to get their UI right at least. Plus, bears are cute.
Edit: No support for folders/categories it seems. That sucks a bit.
Jokes aside, this would be interesting to compare to 1Password once it matures a little. So far it looks very similar.
The Apple Keychain import needs some work though - it didn't pick up the vast majority of the logins I have stored in there.
1Pass X seems to be available on just Chrome? I'm actually quite interested to learn how it works - from my knowledge it's the only standalone PM extension right now.
When I saw "new password manager" in the headline, my first thought was "those guys are fucked". What people want with a password manager is trust and stability, two things not associated with startups. But these folks have millions of users, strong app store ratings, and solid reviews. Going from "trust us with your data and privacy" to "trust us with your passwords" is not a big step.
I'd give my current password manager, LastPass, a C- on usability, so I'll be keeping an eye on this. I'd love to have something better to recommend to novices, and might even switch myself.
>RememBear encrypts your passwords using both your Master Password and a unique device key generated by the application. It stores your passwords in an encrypted file on your device and on our secure servers for sync and backup purposes. However, RememBear will only encrypt and decrypt the items on your physical device. This means that your passwords and other items are always encrypted during syncing and remain encrypted when in storage on our secure servers. You and ONLY you are ever able to access your items as long as you keep your master password private.
Proprietary sync, no thanks.