Bluepass: an open trust no one password manager (fundraising)
bluepass.org
bluepass.org
I hadn't really looked at Indiegogo before I was too far along doing my own site. In the end it was relatively simple. I'll open source it at some point.
Why would Bluepass be any better than my current setup? I already have P2P secure synchronization (via git+ssh), full control over my data and everything is based on portable FOSS.
* Bluepass does push synchronization. So you wouldn't need to manually sync.
* It would work on smartphones / tables too.
* Are the remote git repos under your physical control? If not then your setup is vulnerable to a dictionary attack on your password / passphrase.
* The Bluepass database is set up such that it can resolve conflicts due to concurrent updates (actually it's an append-only graph of parent->child nodes with a algorithm that selects the most likely lineage in case of conflict).
[Edit: some clarifications]
This is not saying that this project isn't interesting, I've just found a solution that has solved these issues for me for the last several years.
However I wanted to bring the security to the next level after that, and this is what Bluepass is about.
Having said that, I'm currently storing my 1Password file in the unencrypted section of my DropBox storage, so my iOS devices can easily access it. (I've got EncFS/BoxCryptor working, but I don't think it's easy/possible to convince the DropBox app to read from the encrypted filesystem…)
This could be later addition. However it does decrease the security slightly because now you have to assume that others now have access to your encrypted data. It is still a lot better than the alternatives because still no dictionary attack is possible, you'd have to break RSA to get to it.
I'm working around that at the moment with a combination of Emacs, the Mac keychain and Alfred.app - it's not beautiful though.
What are your plans for this?
That _rocks_.
How do you activate the paste in your setup? Is there some kind of global key combo for this?
Also, please don't have text that looks like a hyperlink if it's not (even if it is a placeholder), specially if you then have hyperlinks that look the same.
Other than that, good luck on the project. It seems promising.
In your FAQ you say:
> "What do I get when I fund you? Once the software is ready, you will get unlock codes for the mobile versions for the amount you funded. As a special appreciation for being an early customer, these codes not expire and will unlock the mobile versions for life."
But you don't specify a price for the mobile versions. Also, will the mobile versions be GPL'ed?
Very happy to see you take Bitcoin as a funding option.
The mobile versions will be somewhere between $5 and $10. As a perk for funding Bluepass, whatever the price turns out to be, your version will include unlimited free upgrades.
The source of the mobile versions will be available, but for the success of a project, a recurring revenue stream is required to maintain them. The mobile platforms change a lot, and there are not many examples of open source projects that can successfully provide productized versions for these mass market consumer platforms. That is why I cannot commit at this point that the license will allow redistribution on an app store. This means it would not be an OSI style license.
As the copyright holder, that wouldn't affect you, of course, since you don't need a license to distribute the software yourself.
Why not use keepass format natively? IMO a keepass-compatible app with built in sync would make much more sense. The userbase is already there, and a user friendly keepass app with sync would be a hit.
What will this provide me over Firefox Sync, which has a built in encryption layer on their (admittedly cloud) service? I can pull their code and host my own Firefox sync server, and someone has written a special PHP-based version for inclusion into OwnCloud. So, what is so special here except the use of buzzword P2P? (See next question below.)
How will you do to P2P without some kind of centralized bootstrapping service with the prevalence of NAT and people who do not know how to port-forward? (I just saw the Github repos, so I will examine this myself in a bit.)
UPDATE: It would appear you are using mDNS and/or Zeroconf [1] to handle this? I am still not sure how this will ease the NAT and/or syncing over public Internet.
Why should I trust you? What have you done other than this project? Not to be increasingly blunt, but you are not the Mozilla Foundation and your Github repos do not show much other than work on co-routines and AD service wrappers. That is useful to me, but I would like to see more security work and knowledge of crypto libraries if I trust you with password manager code. What else do you work on? Your blog does not show me too much, and I cannot find much mention of you to warrant 60,000 USD for such a project. I am correct in seeing you a Marketing/Product Manager? Sorry to be harsh, but honestly I think most of HN would be worried about these points.
UPDATE: Ok, maybe I was a little too harsh; you do seem to have some more experience than I had previously estimated, given some Googling and your Linkedin profile, if legit. [2]
[0] http://docs.services.mozilla.com/sync/ [1] https://github.com/geertj/bluepass/blob/master/bluepass/loca... [2] it.linkedin.com/in/geertj
As far as trusting this project, it is GPL and you are free to inspect it. I don't think being part of the Mozilla Foundation somehow guarantees secure code. If the author wants $60,000, he is free to ask for it.
> How will you do to P2P without some kind of centralized bootstrapping service with the prevalence of NAT and people who do not know how to port-forward? (I just saw the Github repos, so I will examine this myself in a bit.)
The P2P is done over local networks only. It uses multicast DNS for service discovery. Bluepass syncs between your own devices only. As long as the devices occasionally share a (W)LAN, it will work.
> Why should I trust you? What have you done other than this project? Not to be increasingly blunt, but you are not the Mozilla Foundation and your Github repos do not show much other than work on co-routines and AD service wrappers. That is useful to me, but I would like to see more security work and knowledge of crypto libraries if I trust you with password manager code.
Well, everybody has to start somewhere. I do believe that I have enough experience with crypto to be qualified here. I've got a physics degree and did a lot of maths. And I read Schneier and Wenbo Mao's book cover to cover. Also note that I'm not using any proprietary algorithms. This is all OpenSSL wrapped algo's that I'm using from Python.
But in the end, what should give this the right credibility is that the source code is up on Github, together with my intention to grow a community that can review the crypto. If there is something not right, which can always happen of course, then it will get out sooner or later.
> What else do you work on? Your blog does not show me too much, and I cannot find much mention of you to warrant 60,000 USD for such a project. I am correct in seeing you a Marketing/Product Manager? Sorry to be harsh, but honestly I think most of HN would be worried about these points.
This is not related to my day job. I would say have a look at the code, and decide for yourself if you like the code. I don't think being a product marketing manager in the day is mutually exclusive with being able to write good code.
The calculation of the funds is rather straightforward: $10k for each of the platforms that need work: iOS, Android, Chrome, FF, Mac and Windows.
How about a VPN? I have a work laptop that is rarely (if ever) connected to my home network directly. -- However it is connected to my home network through a VPN daily.
If your VPN provider, you or otherwise, does not block the mDNS/Zeroconf network traffic and had a permissible DNS configuration (almost all commodity routers have mDNS/Zeroconf config available if not on by default), I am sure you will have this work. The author can answer you more clearly.
And I did look at the code. It looks Pythonic and clean, so I am impressed. Definitely above my capabilities.
* The physical security of your device. Unless someone gets access to your device, you are safe.
* The fact that the sync traffic goes over your local network only.
* Even if someone managed to sniff your local traffic, all synchronization requests are encrypted by each node's unique 2048-bit RSA key. No dictionary attack is possible - you'd have to break RSA.
One thing I particularly like about this setup, is that I can have encrypted data synced to a machine that doesn't have the decryption key (or even software) on it – my media server and a machine at work are "backing up" all that data without it being "exposed" even if a machine and disks get stolen/confiscated.
This is different to a truecrypt volume, in that the files are still discrete:
[Bigs-MacBook-Pro:~/Dropbox/BoxCryptor-DB.bc] bigiain% ls -l
total 7544
-rw-r--r--@ 1 bigiain admin 625 12 Jun 10:59 !IMPORTANT BoxCryptor Information.txt
-rw-r--r--@ 1 bigiain admin 0 12 Jun 11:07 Hmz6h72bplJbH1
drwxr-xr-x@ 3 bigiain admin 102 12 Jul 18:01 QY7,wBj6mQwGV7OyD3Qbll8
drwxr-xr-x 50 bigiain admin 1700 23 Jul 22:21 WoVrJB-gyKVMm0
-rw-r--r--@ 1 bigiain admin 3840262 6 Aug 09:40 Z8,UY5cp7Ux491OckZ9yXM2
-rw-r--r--@ 1 bigiain admin 15364 7 Aug 21:25 nMrARYb-KDbdDj2
individual files can get synced as the change, without needing to re-sync the entire volume. On the downside, that means I leak some metadata, file sizes and modification dates, but not names or contents. I also lose the tryecrypt option of hidden volumes, but perhaps that's a plus in that they wont hit me with the $5 wrench insisting that there's _another_ password - even if there isn't…The difficulty is that a P2P sync requires a completely difference design. Keepass is pretty much a frontend to an embedded database. A P2P node need to have its own network facing component that acts independently of the frontend, to relay messages, respond to pairing requests, etc. This is why Bluepass has a frontend/backend architecture. It is a lot easier to create such a different architecture from scratch.
I hope this project can become a suitable replacement.
The safest option is to prevent 3rd parties from having access to your encrypted data in the first place. This is the approach Bluepass is taking.
Obviously the token file would be something you don't put into cloud but instead store on each physical device.
You're at risk from the US government, but it's unclear that a government that can compel Dropbox to hand over your database and then crack some pretty heavy encryption can't access the accounts you're protecting with those passwords in some other way.
The main adversaries, IMO, you're protecting against are non-government actors, and your setup should be completely adequate for those.
FWIW, I have the same setup, but with Keepass.
http://www.theatlanticwire.com/technology/2013/06/prism-comp...
"What are you protecting,"
Freedom
"and who are you protecting it against?"
The US(UK) government.
The US / UK have imprisoned people without charge, trial or conviction, and based on flimsy evidence. Some of those people will have been tortured.
Feel free to suggest 1password on dropbox, or Bluepass, if you think either of them can protect against well funded government agencies. I hope you're also recommending better door locks, no windows on the ground floor, 5 metre fences, hardened computer running hardened OS, etc.
My god, the NSA has managed to turn "The Cloud" into a dirty word.