Pass: The standard unix password manager
zx2c4.com
zx2c4.com
I use a similar (and old) solution using GPG for password management, however it differs in one important way: it stores passwords in a database rather than a series of flat files. If I combine it with private browsing, I can simultaneously store passwords for particular websites while not letting a random trespasser know I even visit them.
I guess you could do something with pass's multiline option.
What database do you use?
You can see the commit activity for KeePassX, which would make it more obvious if a bug or malicious snippet might get inserted into it.
I use it with the great PassIFox (https://addons.mozilla.org/en-US/firefox/addon/passifox/) to get a nice "Fill user/password" in the contextual menu.
I also use it on my Android phone with Keepass2Android: https://keepass2android.codeplex.com/
KeePass is the program for linux I've found that fills in your details in the browser for you (short of LastPass, which I don't trust).
Those file names are arbitrary. While it's certainly easier to just name them after the site or resource you access with the password within, you can give them some cryptic identifiers.
$ pass insert mapping -m
:)https://github.com/abgoyal/password-store2
Take a look. I am using it personally, Its not in a release-able state yet, though. I have had no time to work on it.
So, for the last 20 years or so, I just have a single GPG encrypted file that contains the list of my passwords for various sites and services, ssh keys, and whatnot. I usually read and write that file in Emacs, or gpg -o - out to shell with an alias for quick read-only access.
The file is easy to backup and easy to distribute even carelessly: I even had it on my public www server at some point when I needed access to the passwords over the network.
I can't think of a simpler scheme than that.
Of course, the GPG keys themselves can lock and unlock my life completely. I have them in a separate backup file that is also encrypted using GPG but with a symmetric cipher. Thus, I don't depend on any extra files to decrypt my GPG keys.
As the passphrase for that symmetrically encrypted file is basically the master password to my life and because I've never needed it yet I store the password in a suitable physical location. But I can still distribute the backup file itself: even obtaining the passphrase to the symmetric cipher doesn't really expose my secrets yet. It will only give access to my GPG keys which in turn need my regularly-used private-key-passphrase to be useful at all.
-it's the same scheme, the only difference is that your passwords are broken into individual encrypted text files instead of just one (potential SPOF advantage).
-it's more secure because you can set it up so your passwords never reach stdout (or any human readable display at all for that matter) with pass -c.
-it's just as easy to backup:
gpg-zip --symmetric ~/.password-store
-pass itself is extremely portable.-pass is way more convenient:
pass -c my/password
is far quicker and several orders of magnitude less annoying than gpg -dao passwordfile.gpg
<unlock private key>
<copy password>
<kill terminal>
<use password>
<clear clipboard>
Speaking from experience, I would say you're better off using pass than a single gpg'd text file.I agree with your sentiment, but if you keep your passwordfile well-formed, say:
site.com username password
#assume no spaces in password or username -- or use tabs
You could throw something like: gpg -dao passwordfile.gpg|awk "/${1}/ { print \$3 }" | xclip &&
sleep 15 ; echo XXXXXXXXXXXXXXXXXXXXXXXXXX | xclip
In a script. With an agent managing your gpg passphrase (or not,
depending on your pranoia) such a scheme would get most of the way
there.Not sure why you would want to kill the terminal, but you could just <command-run> or whatever said script...
In fact, for clearing your clipboard, just selecting some text should be enough -- but I supppose it might be considered a feature to have it in the script, in case one forgets.
I just write them down at home with a mental rule for replacing char position.
In each of the txt-files, I use a shorthand for the passwords. So if the actual password was "theansweris42", I'd have something like t...s42. This is enough of a reminder for myself (especially when using a more modular password system), without giving the full password away. In another, external gpg-encrypted file, I have a simple txt-file that contains both the password for that truecrypt container and the "translation" for the long form, i.e. t...s = theansweris and so on. This allows me to also use this file as a kind of dead-man switch. Should I ever die unexpectedly and somebody close would need or should have access to my accounts, they will be able to open the GPG file (because they are in it as recipients), which essentially gives them access to everything important.
First, I created an automator action that grabs the current URL from Chrome and strips out the hostname. This gets passed to a new Terminal window that runs a shell script that calls "pass -c" for the hostname.[0] Then the script calls terminal-notifier [1] and a notification pops up that reminds me of the username and any other info for that site (but not the password). [2]
Then I bind that service to the "cmd+\" keyboard shortcut and I have something that ends up being more reliable than 1password's often flaky form filling functionality. It includes the extra work of entering username manually and pasting in a password, but so far I like this system a lot better. Also, for sites that use the same login from multiple hostnames, I just create symlinks to a "canonical" pass entry.
Hope this is useful to some people on a mac!
[0] I couldn't figure out how to have pass ask for a gpg pinentry window when it was getting run from a non-interactive shell. So I use automator to create a new terminal window, then destroy it at the end.
[1] https://github.com/alloy/terminal-notifier
[2] all of my pass entries are of the form:
password
---
username: user
other info: foo
other info 2: barThe reason I stuck with it so long was so that my passwords would easily sync to my iPad/iPhone, but with iCloud Keychain, I think I'm finally ready to give up on 1Password.
I have a folder, ~/pass. It contains gpg encrypted text files. They are named by category. So, a product key would be keys.ftl.gpg. A website would be sites.hackernews.gpg.
I create and edit files with emacs. It handles gpg files and lets you choose which key to use to encrypt.
For random password generation, I use pwgen.
That's it. Being files, you can ls and grep to see if you already have an account somewhere or find out the file name that belongs to a site. If you are concerned with "giving away" where you have accounts if the system is compromised, you can create larger generic files like "sites" and then use your text editor to search through them.
It's simple, easy to backup via rsync and cross platform because gpg, emacs and pwgen are on every platform. When the SSD in my Linux machine failed I was stuck using Windows for a month while the RMA went through. It was trivial to get up and running with cygwin.
I know emacs an do things like that, but I never bothered enough to find out if it's as smooth to use as keepass2.
pwgen has a bunch of options. They are fairly easy to learn, but you can always alias them out to something descriptive. Usually I have to specify some arbitrary length based on the "recommendation" of the site in question. Eg:
pwgen 10
Will poop out a bunch of passwords to the console in columns that are 10 characters long. Probably less then ideal. I usually like to use the secure option and make them as long as the site will allow. To make things easier, you can just make it generate a single password and pipe it to the clipboard. pwgen -s 20 1 | xclip -i
LSm4BfnGADLG0WAxStUW
Middle click (paste) into emacs and the web browser. Save the file in emacs and submit the browser registration form. Run the pwgen/xclip command again to put a different unused password in your clipboard just in case.I guess the use case is if you're a bit paranoid and want to use a strong/different password for everything.
Lots of us sign up for lots of sites to try out things, engage in one-off discussions, etc, so it's pretty necessary to have a password manager.
I'll point out that if you creates those passwords yourself, rather than using an entirely random generator, they likely have less entropy than you think, and so are more crackable. A password manager helps with that.
So true. I generate my passwords separately, for the simple reason that I haven't yet found a pssword manager that would fit me perfectly. Pass is getting relatively close.
In the meanwhile, I keep my passwords either on [LUKS] encrypted partition or a GPG protected file. I can even disclose the exact method I use for generating these passwords:
head -c 9 /dev/urandom | base64 -
For high-value targets or if I'm feeling a bit more paranoid than usual, I go for 12 octects instead.apg -a1 -n1 -m9 -x9
since it will have a greater alphabet
I try to use a different password for each new account. Since the password manager handles the credentials for me it's not much more effort than reusing the same login/password everywhere.
also if it starts using hashed versions of hostnames to store files, I don't see why a single file is better.
Here I've listed a few other password management options with pros and cons: http://ss64.com/docs/security.html
Known issues:
- If you're drunk, it's a bit difficult to remember anything
- If you're sick, probably won't work properly as well
- If you're dead, won't work, 100% sureFor quicker password access, one should try passmenu[0]. It's a dmenu-based menu with all the entries and selecting one copies password to your clipboard.
No mishaps so far. My default behavior with new sites now is to just let pass generate a secure pw and give up any hope of remembering it.
And yeah, I'd definitely use a mobile version.
No. Even the designer of Blowfish thinks you should not use it anymore: https://www.schneier.com/news-048.html
"There will be a nice password input dialog using the standard gpg-agent (which can be configured to stay authenticated for several minutes), since all passwords are encrypted."
When setting up the pass store, you also specify the identity of a GPG key to use (or set of keys which may be used).