What is: Linux keyring, gnome-keyring, Secret Service, and D-Bus (2019)
rtfm.co.ua
rtfm.co.ua
With some more contributors we should be able to get there!
The big issue is that the protocol is synchronous (rather than async), so backends must reply immediately to the client, and can't wait too long for user input (otherwise the D-Bus request times out). The protocol seems to have been designed with a bit of an "everyone can ready everything" model.
It would also be great to see some browser integration with this protocol too -- so website passwords can also be saved in a `org.freedesktop.secrets.service` backend. The big difference with current browser password managers being, rather than the DB exist INSIDE the browser's sandbox, it exist in another service, and only passwords which one explicitly authorises are shared with the browser.
I believe the spec allows for this last item, but if there's no way to authorise individual items, I wouldn't be comfortable using it, since any browser security issue would allow access to ALL passwords in the system DB.
It's sad that more and more applications are unusable without systemd.
On Windows, there is the Data Protection API, which allows you to encrypt a secret tied to a user's login or a machine's key. That is managed by the OS and allows you to lean on the built-in facilities.
The only other potential cryptographically secure alternative might be a TPM chip, if a machine has this. However since a TPM stores secrets system wide, keyrings for each user seam unfeasible and it's likely less secure since you could just boot into single user mode and get the TPM secrets.
Additionally I tend to not trust the TPM (esp. on Linux), because if one firmware update somehow fails to apply properly, I'll have a far more nastier time (since all secrets are gone) than GNOME Shell promoting me to insert my old password.
Another option (in my case) would be using FreeIPA's vault service to stash the key. It would be pretty easy for malware to grab the key though. Perhaps some setup where both a key owned by the user and a key owned by the host, with access mediated by sssd could be designed...
(And admittedly for AD users it's no good since they can't use the vault service...)
It feels like AD is missing some kind of secret storage service for users to make use of.