I'm working around that at the moment with a combination of Emacs, the Mac keychain and Alfred.app - it's not beautiful though.
What are your plans for this?
That _rocks_.
How do you activate the paste in your setup? Is there some kind of global key combo for this?
What will this provide me over Firefox Sync, which has a built in encryption layer on their (admittedly cloud) service? I can pull their code and host my own Firefox sync server, and someone has written a special PHP-based version for inclusion into OwnCloud. So, what is so special here except the use of buzzword P2P? (See next question below.)
How will you do to P2P without some kind of centralized bootstrapping service with the prevalence of NAT and people who do not know how to port-forward? (I just saw the Github repos, so I will examine this myself in a bit.)
UPDATE: It would appear you are using mDNS and/or Zeroconf [1] to handle this? I am still not sure how this will ease the NAT and/or syncing over public Internet.
Why should I trust you? What have you done other than this project? Not to be increasingly blunt, but you are not the Mozilla Foundation and your Github repos do not show much other than work on co-routines and AD service wrappers. That is useful to me, but I would like to see more security work and knowledge of crypto libraries if I trust you with password manager code. What else do you work on? Your blog does not show me too much, and I cannot find much mention of you to warrant 60,000 USD for such a project. I am correct in seeing you a Marketing/Product Manager? Sorry to be harsh, but honestly I think most of HN would be worried about these points.
UPDATE: Ok, maybe I was a little too harsh; you do seem to have some more experience than I had previously estimated, given some Googling and your Linkedin profile, if legit. [2]
[0] http://docs.services.mozilla.com/sync/ [1] https://github.com/geertj/bluepass/blob/master/bluepass/loca... [2] it.linkedin.com/in/geertj
As far as trusting this project, it is GPL and you are free to inspect it. I don't think being part of the Mozilla Foundation somehow guarantees secure code. If the author wants $60,000, he is free to ask for it.
> How will you do to P2P without some kind of centralized bootstrapping service with the prevalence of NAT and people who do not know how to port-forward? (I just saw the Github repos, so I will examine this myself in a bit.)
The P2P is done over local networks only. It uses multicast DNS for service discovery. Bluepass syncs between your own devices only. As long as the devices occasionally share a (W)LAN, it will work.
> Why should I trust you? What have you done other than this project? Not to be increasingly blunt, but you are not the Mozilla Foundation and your Github repos do not show much other than work on co-routines and AD service wrappers. That is useful to me, but I would like to see more security work and knowledge of crypto libraries if I trust you with password manager code.
Well, everybody has to start somewhere. I do believe that I have enough experience with crypto to be qualified here. I've got a physics degree and did a lot of maths. And I read Schneier and Wenbo Mao's book cover to cover. Also note that I'm not using any proprietary algorithms. This is all OpenSSL wrapped algo's that I'm using from Python.
But in the end, what should give this the right credibility is that the source code is up on Github, together with my intention to grow a community that can review the crypto. If there is something not right, which can always happen of course, then it will get out sooner or later.
> What else do you work on? Your blog does not show me too much, and I cannot find much mention of you to warrant 60,000 USD for such a project. I am correct in seeing you a Marketing/Product Manager? Sorry to be harsh, but honestly I think most of HN would be worried about these points.
This is not related to my day job. I would say have a look at the code, and decide for yourself if you like the code. I don't think being a product marketing manager in the day is mutually exclusive with being able to write good code.
The calculation of the funds is rather straightforward: $10k for each of the platforms that need work: iOS, Android, Chrome, FF, Mac and Windows.
How about a VPN? I have a work laptop that is rarely (if ever) connected to my home network directly. -- However it is connected to my home network through a VPN daily.
If your VPN provider, you or otherwise, does not block the mDNS/Zeroconf network traffic and had a permissible DNS configuration (almost all commodity routers have mDNS/Zeroconf config available if not on by default), I am sure you will have this work. The author can answer you more clearly.
And I did look at the code. It looks Pythonic and clean, so I am impressed. Definitely above my capabilities.
Why would Bluepass be any better than my current setup? I already have P2P secure synchronization (via git+ssh), full control over my data and everything is based on portable FOSS.
* Bluepass does push synchronization. So you wouldn't need to manually sync.
* It would work on smartphones / tables too.
* Are the remote git repos under your physical control? If not then your setup is vulnerable to a dictionary attack on your password / passphrase.
* The Bluepass database is set up such that it can resolve conflicts due to concurrent updates (actually it's an append-only graph of parent->child nodes with a algorithm that selects the most likely lineage in case of conflict).
[Edit: some clarifications]
This is not saying that this project isn't interesting, I've just found a solution that has solved these issues for me for the last several years.
However I wanted to bring the security to the next level after that, and this is what Bluepass is about.
Having said that, I'm currently storing my 1Password file in the unencrypted section of my DropBox storage, so my iOS devices can easily access it. (I've got EncFS/BoxCryptor working, but I don't think it's easy/possible to convince the DropBox app to read from the encrypted filesystem…)
In your FAQ you say:
> "What do I get when I fund you? Once the software is ready, you will get unlock codes for the mobile versions for the amount you funded. As a special appreciation for being an early customer, these codes not expire and will unlock the mobile versions for life."
But you don't specify a price for the mobile versions. Also, will the mobile versions be GPL'ed?
Very happy to see you take Bitcoin as a funding option.
The mobile versions will be somewhere between $5 and $10. As a perk for funding Bluepass, whatever the price turns out to be, your version will include unlimited free upgrades.
The source of the mobile versions will be available, but for the success of a project, a recurring revenue stream is required to maintain them. The mobile platforms change a lot, and there are not many examples of open source projects that can successfully provide productized versions for these mass market consumer platforms. That is why I cannot commit at this point that the license will allow redistribution on an app store. This means it would not be an OSI style license.
As the copyright holder, that wouldn't affect you, of course, since you don't need a license to distribute the software yourself.
Also, please don't have text that looks like a hyperlink if it's not (even if it is a placeholder), specially if you then have hyperlinks that look the same.
Other than that, good luck on the project. It seems promising.
I hadn't really looked at Indiegogo before I was too far along doing my own site. In the end it was relatively simple. I'll open source it at some point.
This could be later addition. However it does decrease the security slightly because now you have to assume that others now have access to your encrypted data. It is still a lot better than the alternatives because still no dictionary attack is possible, you'd have to break RSA to get to it.
Why not use keepass format natively? IMO a keepass-compatible app with built in sync would make much more sense. The userbase is already there, and a user friendly keepass app with sync would be a hit.