Lockbox – A stand-alone password manager that works with Firefox for desktop
mozilla-lockbox.github.io
mozilla-lockbox.github.io
Anecdotally it seems like a lot of people are losing trust in Lastpass. Just curious if this describes you as well.
The main benefit of pass, for me, is that it's literally just gpg-encrypted text files. I can access my passwords even if I do not have pass installed, as long as I have my gpg private key. Using git to sync passwords makes it even better!
The android Password Store app (on f-droid) is a great graphical interface to my pass files, including handling git syncs.
1) I didn't like that its approach seemed overly complicated (e.g. its database format, client apps, etc)
2) I was having a really hard time synchronizing passwords, especially if there was a sync conflict. When they happened, the entire database was a 'conflict'. There were also issues I had with the actual sync mechanism, which at the time I had the database on a seafile instance and had to enable various 'hacks' in keepass to get it to play nicely (e.g. file locking, etc).
I've used LastPass for 7 years now. My Premium runs out next month, and I'm planning to switch away and not renew this time. Main reasons I'm switching:
* LastPass was acquired by LogMeIn. I don't know if this has had many major effects yet, but I don't trust them to be in charge of LastPass over the longer term.
* The browser extension (which is the main way to use it) has only gotten worse lately. Some of this is Firefox's fault, but not all of it. Some functions have disappeared, others have gotten harder to use, and both my wife and I have recently had it occasionally "lose" login info for new sites that we've signed up on. That may have been user error, but it never happened to either of us for years and we've both seen it in the last few months.
* They recently doubled the price of LastPass Premium.
https://git.zx2c4.com/password-store/about/
You create a .gpg-id file in the folder with a list of key ids.
[1] https://www.justwatch.com/gopass/ [2] https://news.ycombinator.com/item?id=13551692 [3] https://news.ycombinator.com/item?id=15864322
Keepass usage seems pretty widespread. Okay Keepass doesn't integrate too well into browsers. But then why not just fix Keepass?
There have been way too many products pushed out failed utterly and abandoned by mozilla in the last few years. Why should I care about this one, if it doesn't even tell me what it wants to do better than other products.
The text on the website reads like this is simply a POC for a new built-in password manager in firefox, is that correct? But then why standalone?
KeePass has a feature to sync two files, and can access a variety of network storages. That's not one turn-key solution, but it covers just about everything. Meanwhile I simply store the file in my Dropbox because I don't do concurrent edits and it's slightly more convenient that way
Honest question, but pushing your KeepassXC db into Dropbox shouldn't raise some red flags from a security perspective ? If "somebody" gets your encrypted db, they can rainbowtable the crap out of it to unlock it.
To me it seems by using Dropbox you just add another sizeable attack surface.
I would be comfortable hosting my password file publicly. Any benefits from Dropbox authentication are just defense in depth (and privacy benefits).
The DB attack surface is to some extend expected to be eventually obtained by an attacker. As long as your master password is nice and long, they "can't do shit" for a long long long while.
2. Browsers need to be trusted and secure. If you use Firefox, you are trusting Mozilla et. al. to have the policies, procedures, motivations, and expertise to create secure software that protects your privacy. If you can trust them to make your browser, you can trust them to make your password manager.
I do hope that Mozilla answers these questions directly when/before this moves out of beta.
2. I do trust Mozilla to have the technical expertise to build a secure password manager. But just because they can do it, still doesn't answer why they're doing it the way they're doing it.
I would just like to hear Mozillas thought process that went into this. I'm sure they have reasons for all decisions, but I can't read thoughts.
Knowing their thought process would help me evaluate my prediction of this being abandon-ware in half a year.
I'd like to see this discussion.
For me, I find Firefox's password manager the only one I can bother using, because it offers a good and seamless UX, right where I need it.
If they "fix" that by making it terrible like Lastpass, I honestly don't know what I'll do.
Concerning the "security standpoint", probably this news [0] is meant. Hashing the password with SHA-1 using 1 iteration may be referred to as "inadequate".
[0] https://www.bleepingcomputer.com/news/security/firefox-maste...
The article approaches this from an angle of an attacker with access to this hash bruteforcing it to obtain the original plaintext password. But as the hash is the encryption key, if an attacker were able to recover it from the encrypted password store blob, it would already be game over.
Applying a more costly hash algorithm would increase the cost of generating guessed encryption keys in a bruteforcing scenario, strengthening weak passwords somewhat. But using a single SHA-1 iteration here doesn't weaken the password security model. A strong password will remain strong.
Having a browser component that can be asked by other browser components to pretty please fill in some secrets seems like a way to increase your attack surface. With an external password manager and no integration there's no internal API to be exploited, short of compromising the whole user, or if you have some sort of application isolation, the whole system.
Have there? Off the top of my head there's Persona and Firefox OS, the latter of which Mozilla kept trying to push on with long after the rest of the world had concluded it was doomed. Meanwhile we got Rust and Focus out of Mozilla.
I'm sure there are more, but those come to mind imediately.
Not abandoned, i'm using it, i'm happy with it, thank you very much.
It's a community project now. So yes, is is abandoned by mozilla.
I'd love for them to do more, but I understand why local mail clients aren't a growth area.
https://blog.mozilla.org/thunderbird/2017/05/thunderbirds-fu...
Thunderbird has received continuous development and maintenance for coming up on 15 years since its public release.
[1] : https://keepassxc.org/
[2] : https://syncthing.net/
Until an open source project takes multi device seriously, they don’t get mainstream adoption.
[0] https://keepass.info/help/kb/trigger_examples.html#dbsync
Their recommended approach to syncing a database is [0]. It’s really counterintuitive, and not trivial, and interacts badly with other features (auto save on change for example).
[0] https://keepass.info/help/kb/trigger_examples.html#dbsync
I'm using Google Drive for syncing because on Android it allows me to add a shortcut to the file on my home screen. I've never tried syncthing before and just looking into it now, I love that it's open source, not cloud-based, and not using a proprietary protocol.
I'm watching this video[0] overview of it right now that seems to be going pretty in-depth.
Good luck Mozilla!
1. Why firefox only? 2. Why encryption is limited to Firefox account.
Such lock-in with firefox doesn't make sense to me with Mozilla's vision. If it's due to this being an experiment still that would make sense but that should be made clear I think.
Now I'm wondering if this is essentially doing the coding outside core firefox project with the later plan to just integrate it fully into the browser. Almost like an experimental build kind of workflow. I guess that kinda make sense.
So if you are resource constrain, testing a product, and an underdog again, I understand the idea.
But my guess is they will make it more generic and open later, mozilla being mozilla.
The only problem they might have is that they want to use the password from one's Firefox account to encrypt the DB, although surely that integration could be worked out somehow?
What would be the downsides of this approach?
[0]: https://keepass.info/help/kb/kdbx_4.html [1]: https://keepass.info/download.html
https://news.ycombinator.com/item?id=15992762 https://news.ycombinator.com/item?id=15997239 https://news.ycombinator.com/item?id=15832879 https://news.ycombinator.com/item?id=15596740
But what exactly is "stand-alone" supposed to mean in this context? At the moment it is distributed as a Firefox extension that replaces the Firefox password manager. This seems like the opposite of "stand-alone" to me, as you cannot use it without Firefox.
So it's stand-alone, but I need Firefox to use it?
That said, I enjoyed having a look at Mozilla's internal project management tool for this extension, https://waffle.io/mozilla-lockbox/lockbox-extension
I wish I could have the same kind of look into other company's projects.
Edit : I wasn't referring to this specific case, where encryption is done with the code sent by a server.
You enter your password on a page Mozilla serve[0]; they can change the source of that page at any time, and for a single user. They could for example, send your password in the clear back to their servers if they wished.
There old password-storage system really was secure, but they end-of-lifed it.
But in practice, the higher the visibility of the code you're relying on, the more likely it is that other people have caught something fishy. And POST is higher visibility than lockbox. This is also the reason why even though I trust Mozilla very much, I don't use Sync. It's lower visibility than the vanilla stuff.
Also, attack surface.
Not having a password manager opens up attack surfaces as well. Having a password manager integrated into my browser has prevented me from typing my password into a lookalike site from a different domain. It also means I don't use the same password for any two sites, and the password I use for each site is much stronger than it would otherwise be. There's the potential for the password manager to get compromised, but the benefits seem to outweigh that for now.
Given Firefox was only 2 years ago so insecure it wasn't even a valid target for most browser pwn competitions, and just in this year we find out important code is still held over from those days, I'm not sure why anyone should trust Firefox.
https://github.com/mozilla-lockbox/lockbox-extension/release...
It could make sense if Mozilla were to develop a standard interface for all password managers, so I could swap implementations under the hood without having to deal with their (occasionally half-baked) extensions.
But I guess this is just a Big Rewrite of the venerable utility we've been using since the dawn of Moz.
Lockbox being open source and integrating nicely with Firefox and Firefox Accounts makes me want to use it.
I am the target audience of Lockbox.
One day I will run my own Firefox Accounts server. For now I use the one that Mozilla is running.
https://mozilla-services.readthedocs.io/en/latest/howtos/run...
The 2015 security breach?
I'd love an open-source password manager with a modern ui and local storage.
is based on Keepass. Looks a bit more modern.