Pa – a simple password manager based on age
github.com
github.com
My age+YubiKeys Password Management Solution — https://words.filippo.io/dispatches/passage/
The main feature is some protection against post-compromise exfiltration: even if an attacker fully compromises my laptop, they can't extract the whole vault.
[1]: https://github.com/FiloSottile/passage
I was waiting for a solution to store age keys on a security key, and it's great that it's now possible with YubiKeys.
I currently use smart cards to store my GPG keys, which works even on Android, as there are some that support NFC, so I can use them with the OpenKeychain and Password Store apps. I need to have passwords available on mobile, as often when I'm traveling I don't want to lug around a laptop. The QR code solution you suggest doesn't seem optimal.
Would it be possible to achieve the same workflow with age and NFC YubiKeys? I suppose it would need a native mobile app for that to work.
The Andorid password-store app is working on an implementation of age in Kotlin (https://github.com/android-password-store/kage) and I think they already support passage stores. Maybe you could open a feature request for age-plugin-yubikey compatibility? If you do, feel free to tag me, and I can help make sure the formats are well specified.
How disappointing and misleading! :->
AWS console has three fields (account, user, password), most websites will take your password and/or MFA code on a separate page, some apps will use Electron, some will use native widgets, some will use NON-native widgets (like GTK/Qt on Mac/Windows), some apps (like games) will be running in full screen...
It's a world of madness and I have huge respect for the password managers that actually try to solve these problems (even if most do it only half-decently).
What I need is:
show button on top bar if current website has stored passwords. At this point no logins/passwords are requested from the password manager, only website URLs (or even hashes).
After I click this button, request and show list of logins saved for this website. Let me choose login if there are multiple. Otherwise alter browser context menu.
Now when I right-click on text input, add items like "Insert login: vbezhenar" and "Insert password for vbezhenar".
And only when I choose "insert password" - actually request password from the password manager.
That's the only sane UI. Until I find it or write it myself, I'll continue to copy-paste passwords around.
It's a sad state of things where password managers are still not as usable as text file.
2. Web apps are wild and doing wild things. Even humans might find it hard to fill the form correctly. Extension can only observe DOM. Who knows which inputs it will fill with my passwords? I don't trust myself to write that kind of auto fill code which would work reliably. And if I don't trust myself, I definitely don't trust others to do so.
I don't claim that extensions are malicious. That would not make sense indeed. Just that extensions are things I don't trust to be implemented correctly, especially with convenient auto-pilot mode.
Some users may not even have a password. They'll be sent an email or sms with an authenticated link. So to put a password box in front of them may be confusing.
But it's definitely annoying to those of us with general passwords.
check out the contrib/ dir for some supported programs - get one of those in your $PATH, and set up a hotkey to launch it.
now, whenever you press the hotkey, a list of your passwords will show up, which you may type to filter. when you press return, the password you selected will be automatically typed into whatever you have highlighted, whether it's a password field in a browser, or vim. the neat thing is that the password never touches your clipboard since it's typed directly by either wtype or xdotool.
the workflow really only takes a second or two once you have it setup, and feels very nice, imo!
What's wrong with plain old copy-and-paste? (I know there are probably some security concerns under X11, but Keepass, for example, will automatically clear the clipboard after a few seconds at least.) I use Keepass and 1password.com, but I don't use any of their autofill features; I just copy a password when I need it and paste it to where I need it.
I think a user-friendly, secure, and reliable sync is the much more difficult part of implementing a good password manager.
Context awareness.
I currently have 429 items in my PM (it happens to be 1Password, specifically because it's extremely good at figuring this crap out). I almost never have to search for anything; even if I do, I can easily update the entry, so that it understands the context, in which a given credential can be valid; e.g. I can use my Blizzard login both on "https://battle.net", and in "app://sc2" (StarCraft 2). If I have a main+alt account, it will allow me to choose from the two, not 400+.
It's the same as with using contactless payments with a smartwatch, it saves you 10 seconds here, a minute there - and over the course of your day, day after day - it starts adding up.
> I think a user-friendly, secure, and reliable sync is the much more difficult part of implementing a good password manager.
CRDTs solve this problem quite generally. I've never tried actually implementing sync from scratch in a desktop/mobile app, but the theory behind CRDTs is quite easy to grasp and makes a lot of sense. I'd say it's quite a bit harder to sync plain, old files, because the only metadata you have available is things like names, access/modification times, etc and they tend to be huge binary blobs, like photos or music, so the problem of automatic conflict resolution gets quite interesting.
BTW look up Apple's CloudKit. I've done a "let's pretend we're on a 1990s Internet" challenge[1] a while ago, and it's amazing how reliably everything syncs, even if the devices are online for maybe 1% of the day.
The way I access it is via Blink app on iPad/iPhone, the terminal on mac, WSL on Windows. Copy and paste the password, clear the clipboard (done automatically when using the terminal). It takes a few extra seconds but works anywhere, and I can add password-specific notes for cases like your AWS example.
Putting the password in the clipboard is the least safe part, but I definitely prefer this over giving some random app full access to my browser / system.
That's specifically the part I was extremely unhappy with, as a former pass+dmenu user, who has migrated to 1Password. It's a cold, autumn evening, we're down from the mountain hike and running to catch the last train home to return from the trip, and I need to buy the ticket either before or as soon as I'm on board; my stiff fingers are trying to make things happen on a phone with a small screen, poor reception, and a slowly dying battery. I need that password *now*.
ppppp,,,,,,,,,,,
Bitwarden is significantly better, though it also occasionally does the thing where the prompt to save a new password disappears, because of redirects or something.
Yes, and I would add password device sync for multiple operating systems and browser extensions. Without sync, hundreds of unique, unmemorable passwords are not much value.
Initially, I had used the `gopass`. It is probably the most convenient way to start using the password-store. It is cross-platform, 100% compatible with pass & pass-otp. To copy the password, you basically type the part of the file you are looking for. If you type "gopass show github", it will display a TUI, where you can select the file you are looking for (let's say you have two files "personal/github.com.gpg" and "work/github.com.gpg"). Unfortunately, the search function was far from perfect, and it had a problem with typos like "gtihbu" at the time, when I was using it.
To get rid of this issue, I decided to adapt pass/gopass to use `fzf` [2]. In the same time, my .password-store/ dir was rapidly growing that made me think about implementing pass from scratch. I improved the implementation to have better caching, synchronization between machines/mobile, but more importantly - a simple `secret [arg]` command that will execute `fzf` to list all known creds and simplify selection of the password. Of course, it accepted an argument that was limiting the results, which is great when you need to get back to the previous credential to retype something.
The introduction of `fzf` made it really convenient, and I decided to add more commands with fuzzy search, such as:
- `otp` - limits results files containing TOTP/HOTP token, calculates and copies it to the clipboard.
- `secret-edit`, `secret-remove`, `secret-show`... aliases to sub-commands that open `fzf` command in multi-selection mode, so by utilizing space key I could select what files are meant to be modified, removed, displayed etc. Quite handy for mass-edit.
- `secret-qr` - similar to the gopass' feature, but it made a simplified way to create and display QR codes dedicated to share contacts, WiFI SSID+password combination (etc.) to someone who was asking for creds from me.
Awesome, but alt-tabbing to the terminal got me annoyed after a few years of using it that way. I started pursuing for more sophisticated interface. I decided to give `rofi` [3] a try. I managed to fork that repo and also adapt to my convention of using password-store, but I left i3 for a macOS.
Currently, I have started working on a browser extension that takes care of suggesting password-store creds (based on the path, input parameters, location on the website etc.) similarly to what uBlock Origin does. That configuration is passed to my pass implementation, so on the github.com, my browser have only "work" and "personal" auto-suggestion, when I am focusing the text input.
I plan to create a similar app to Shortcat [4], but it will preserve the information what credential has been asked for the focused app. I think, with VoiceOver assistance, it is more than possible to mitigate the need for alt-tabbing to the terminal for electron/native apps.
[0]: It is a private repository, maybe when it will be polished enough I will open-source it.
[1]: https://github.com/gopasspw/gopass
[2]: https://github.com/junegunn/fzf
[3]: https://github.com/alecdwm/pass-rofi-gui
Edit: About the AWS login form. I strongly recommend giving `aws-vault` (https://github.com/99designs/aws-vault) a try. It helps you skip the login form with a simple command e.g.: "aws-vault login acme-corp --duration 2h". I find it better than `aws-mfa` on my dev machine.
This is arguably a non-issue for most use cases (disk access is "game over" under most threat models), but it's nice to have e.g. for sharing configurations between multiple machines over a public channel (like a dotfiles repository). It would also bring this roughly up to "spec" with what other password managers do (i.e., in terms of requiring a "master" password that unlocks the vault).
it boils down to exactly what you noted - disk access is game over in most cases anyways, and i like the convenience of plaintext on the disk.
i will be exploring the yubikey model that filippo recently outlined though https://words.filippo.io/dispatches/passage/ - so stay tuned! :D
And since I forgot to say it earlier: excellent work!
It would be cool to see the other apps like Bitwarden adopt a CLI to use passwords with other command line tools. Kind of like the Apple Keychain API but easier to work with in a *nix environment.
git init --bare
Then I can sync it to multiple devices via pull or push.
I have thought about adding git support directly to pa, but I think it's out of scope.
Here's what I do now:
Encrypted volume synced with syncthing, everything basically stored as plain text and (like you, i think) a few shell scripts to throw passwords into the clipboard.
Would your thing work with a simple synced volume?
What? Call it "paw" then. No one is gonna see "pa" and think it's pronounced "paw", and no one is gonna hear you say "paw" and think the invocation is "pa"
Why the intentional confusion?
A dog limps into a bar. The barman looks at him and say "What can I do you for?" and
the dog replies "I'm a looking for the man that shot my pa"./pɑː/ — if I had to use "normal person's IPA", "pah" would be my attempt. This, to me, is the more common pronunciation. Should rhyme with "bra" … assuming you pronounce that like I do.
/pɔː/ — like "paw" or "awe". This is a region-specific dialect, to me. This appears to be the one you're familiar with.
See https://en.wikipedia.org/wiki/Help:IPA/English for a chart.
https://www.merriam-webster.com/dictionary/pa
Relevant for the US.
Well consider me a counter example.
https://github.com/alexlance/paw
It's a wrapper around gpg symmetric encryption that accesses a store of encrypted passwords sitting on a remote server accessible via ssh.
These are not far from one another here.
Pet usability peeve triggered here. If we create a system that completely depends on the strength of a password/passphrase we have to give the user concrete advice on how to create a password/passphrase that will be strong on that particular system.
However, generally speaking, age uses scrypt for password key derivation, with a default work factor of 2^18 (1 second on modern machines). Unlike GnuPG's S2K, scrypt is both CPU and memory hard.
This gets back to my original peeve. This sort of thing has to be worked out for the user. I looked through the available documentation. Was I as a user expected to look through the source code and figure it out for myself?
I managed to get two things wrong in one post. As a result I ended up disparaging the Age project for no reason and causing confusion about the Pa project. I continued the confusion in subsequent replies.
I will try to be better about this sort of thing in the future and am sorry.
So I really should of complained that this fact was not made very clear to the user... :)
how could i have made this more clear? what would you like to see?
Did you even bother to check?
https://github.com/FiloSottile/age/blob/main/scrypt.go
This isn't exactly hidden.
If anyone else (i.e. "a user") made this mistake, I'd be more sympathetic. But not for you.
You don't get to have your cake and eat it too. Are you a cryptography expert, or aren't you?
If yes, then failing to bother to check the source code is a faux pas.
If no, then I expect you to stop trying to argue as a cryptography expert the next time someone points out that PGP is bad cryptography.
I don't care which you choose. I only ask that you stick to it.