"brew install pass" -- the simple unix password manager now released for mac
zx2c4.com
zx2c4.com
1Password integrates with browsers, basically even avoiding the clipboard to autofill. It also prevents accidentally filling the wrong password as you can only autofill passwords that are for that domain. You can also sync to your iOS/Android devices.
Keepass is nearly as good (autofill isn't as refined), but it's free and available on linux too.
https://github.com/drakedevel/pyagilekeychain/blob/master/ag...
Not that standard (the encryption is standard AES, but not OpenPGP format) but it is certainly portable.
It sounds like pass has the potential to do these things as well, and I would prefer to use an open platform over a closed one, all things being equal. Just recognize that there are tradeoffs.
So stop whining, and write this component; it's easy.
You would get a lot further in convincing people to use and contribute to your app if you toned down the condescension. I like your app and support unix tools with open formats but you come across as someone who would be very difficult to work with.
Sorry you're put off by my dismissal. My inbox is filled with awesome patches and suggestions from people, and things have been going pretty smoothly with integrating these and fleshing out new features. You seem optimistic about the project (" I think it has the potential to be better than those other password managers"), and so if you've got the impetus to contribute some code or suggestions, by all means send me an email.
bash tab completion...
To do that someone would already have to have typed your OS password to unlock your screen, right? If you're in the habit of leaving your system unlocked when you're not around it, you're already inviting someone to install a keylogger.
Gpg-agent is super awesome and flexible. Google it -- you'll dig it.
But, for the moment, we ARE talking about simplicity. I'd like to simply encrypt a plaintext file. Then I'd have a decrypting version of cat (call it "dcat") that asks me for a password, doesn't echo it, and applies it to the file before cat'ing. It doesn't know if the password is right or wrong; it just passes the file through it before cat'ing. If I give it the wrong password, gibberish comes out.
I could then view a whole file (dcat my_secret_pancake_recipe.txt) or pipe it to grep (dcat my_logins.txt | grep -A 2 Netflix) to get just the lines I want---exactly what you'd do with any text file except that it starts with a decryption that asks for a password (which it doesn't echo).
What's the best way to do something this simple?
UPDATE: openssl essentially does this and comes already installed on Mac OS X. I'm a crypto noob, though, so I'd still welcome advice.
But GPG in general is the de facto unix way to go about crypting things. Straight up openssl is good for somethings, making little shell scripts like "dcat" is nice for others, but for general purpose encryption of files, nothing really beats GPG.
I guess GPG isn't simple. It's a big project, well-vetted, and has been under development for years. The usage of its tools, though, is very simple, and the file formats have now become an acceptable standard, widely adopted all over.
So really, give GPG another shot and a close look before you knock it. If it still doesn't meet what you're looking for, check out the man page for openssl-enc. Probably what you want is something like "openssl enc -aes-256-ofb -in infile -out outfile -salt", but likely there are other nuances to account for too. Be careful with crypto.
[1]: Switched to 1password a while back oddly enough, to achieve some simplicity.
Pass comes with integrated git support, for syncing and logging. This is what I use with my mobile phone and additional computers, and it works really well.
How do you use it on your mobile phone? Is there a git app that lets you browse files? How would you decrypt them? Can you update them?
Or do you just use a shell on your mobile phone?
Thank you, come again!
Honestly, people use what is best for them. That may be Windows, it may be Linux. Point is, don't knock it if it works for them.
Point is, I'm not wasting my time trying to wrestle cygwin into shape, let alone investigating cygwin on windows phone.
That said, this could probably be re-implemented pretty easily using native win32 or .net... or whatever.
However, it would be great if this could work with Chrome as an extension. You'd probably want to avoid writing a native plugin for it, because that would require compiling and would be a headache for managing the extension (and gpg versions, etc). Instead, one thing you could do is setup a daemon that the extension could talk to, bound to localhost. But then you'd have to manage authenticating Chrome to the client, etc... perhaps I found something to tinker with over the weekend.
"Macintosh" as a term to refer to a computer doesn't exist now. I can't find a link to support it, but I'm pretty certain Apple officially uses Mac, not Macintosh, even though the former was originally a shortened version of the latter.
p.s. Thanks for this software. Awesome to have choice in this area.
Alternatively, and perhaps this is cleaner and nicer, you put the password in Amazon/bookreader and the meta/additional data in Amazon/bookreader.meta. Or come up with your own scheme that works for you. The system is really flexible.
One possibility I listed before was: Put your password in Amazon/bookreader and the other account information in Amazon/bookreader.meta. Then, this would be the case:
$ pass Amazon/bookreader
23nauDSJ92*#@nb23b2
$ pass -c Amazon/bookreader
Amazon/bookreader copied to clipboard for 45 seconds.
$ pass Amazon/bookreader.meta
Secret Question 1: Dog's name? Oliver
Secret Question 2: Do you understand the concept here? I hope so.
The point is, you can organize things however you like. You don't have to use this scheme; you could use a different one.Thanks for solving another man's problem.
Change calls to "gpg" to "cat" in the source code. It's less than 300 lines of simple shell script. Poke around and it shouldn't take more than 2 minutes to alter.
Keep it simple. Single files are the way to go.
While in some cases the difference is moot (I'm sure I have a bunch of registrations on things like forums where membership is public anyway), there are cases where it's not.
I had thought that in 30+ years of Unix use, I had noticed all the standard Unix components. I was quite surprised to overlook that there was a standard Unix password manager!
That said, the design is pretty simple. There are gpg text files in folders. Decrypt them to reveal passwords, encrypt them to add passwords.
Is the filename cleartext or encrypted?
Filenames readable in cleartext is a security issue. This means whoever has access to your files knows you have accounts on certain websites they are looking for.
For instance, to store the password for www.example.com, the filename could be derived by encrypting the website name (www.example.com) with AES using the user's master password, base 64 encoding the output, and using that for the filename.
I really loathe 1Password, KeePass, LastPass etc. but what they do is provide me with a FAST way to get to my passwords.
If I could do this with Alfred and this app it would be killer:
pass find ycomb (and then it gives you results that match this and if you hit enter it copies the password to the clipboard) pass add [name/url] [password] pass rm [name/url]
etc. If only I knew how to code this. :)
Shoot me an email (posted bottom of the page) if you have any success with this.