Show HN: Manage passwords with GPG
github.com
github.com
* git integration.
* Separate file for each secret, so that I can store the password on the first line and then other sensitive account details on subsequent lines.
* -c flag for copying passwords to clipboard (but only copies the first line of the file, so it doesn't interfere with the usecase above)
* tab completion for user account names. However, this comes at a slight cost to security -- anyone with access to your machine (or git repo) can see all of the websites / accounts for which you have a password.
* Everything happens via the file system and secrets are just gpg encrypted text files. So it's really easy to implement new utilities on top of your password store. This is true for this solution as well, but somehow having separate files for each account makes it safer to implement utilities that do account management.
I've given up on it, but I'd like to know if anyone might have found something that I overlooked.
There's also the issue that if it does export something, you have to accept every exported item individually. If you search the internet, you'll find people who wrote scripts for "automatic accept-clicking."
But as I said, once I looked up what it exported, I noticed that it was far from complete.But maybe there's some command line option buried somewhere that will accomplish what I wanted to do...
The whole export thing is just terribly broken.
Some examples of using it: http://joshtronic.com/2014/02/17/using-keyring-access-on-the...
[edit] deleted paragraph that was supposed to be added to a different comment.
1. ./blah.sh | grep LookupKey exposes just as much information as pass -c LookupKey. If someone has access to your machine and you don't carefully prune your bash history file, then you're screwed. However, in the latter case, at least you get something at the cost of giving up security -- namely, the convenience of tab completion.
2. The only way to solve problem #1 in general is to have multi-stage authentication, where you authenticate to access to lookup keys and then authenticate again to access the passwords. That's achievable using pass and some Bash -- obfuscate file names and store a obfuscated -> actual mapping in a gpg-encrypted file, and write a bash script that does the ln -s'ing. And then the command that does that dumps you into a shell that doesn't record history.
I did this for a while but found it's a bit of PITA. Also, I can almost always come up with names that would be difficult to exploit without a lot of information about my life (bank_primary, bank_secondary; email/personal, email/business, email/spammy; server/personal, server/2011; and so on. I won't remember these verbatim, but once tab-completion reminds me of my options I typically recall which is which. And in case you're afraid in several years you'll forget which server you first purchased in 2011, you can always just pass -e server/2011 and explain which one you meant in subsequent lines.
edit: looks like there's an iPhone app as well. See http://www.passwordstore.org/
https://play.google.com/store/apps/details?id=com.zeapo.pwds...
There's a iPhone one I cannot comment on.
- https://github.com/gustaebel/passext (Chrome)
or
- https://github.com/jvenant/passff (firefox)
"This is pre-alpha quality software, the result of a three
day project. It will crash your browser, leak your
passwords and destroy your home. This is actually my first
Chrome extension and I am no expert javascript programmer."
YMMVIt actually works better (for me) than 1password which was always a little flaky at recognizing a website after any kind of site update.
$ tree .password-store
irc
├── efnet
└── freenodeFrankly, just encrypt the entire drive. Otherwise, there will always be a leak somewhere. If not in the file structure, then in the swap.
The downside is a lack of control over complexity and the issue of passwords being strictly dependent on the salt. So, if one set of credentials is compromised, you would need update them all.
I've seen software that does this, but there are subtle details to consider to actually get it correct.
Has anyone else here had the same thought? This guy seems to at least;
https://github.com/equivrel/password-store-encfs/blob/master...
Edit: spelling
Could use autofs to make it auto mount when pass accesses the mount point.
Thanks for the autofs hint, will try it and see how that works out re unlocking.
This works because Emacs can open .gpg files. It will decrypt them on opening (asking for your password) and encrypt on saving. This is very powerful in combination with Orgmode (.org), or any other module that provides auto-folding.
So I open my .org.gpg file and everything is folded. Then I search for what I need, and only that part (containing some secrets) is unfolded.
Of course, this is no substitute for a proper password manager, but proved to be useful a lot more often than I initially thought.
The obvious way of getting the password out of the Emacs buffer is copy and paste, which leaves the password on the clipboard where it is very easy to find. Manually removing it (by copying something else) can't be relied upon. (If you use Klipper you have an even bigger problem.)
I know all bets are off with any kind of password manager if the host is compromised, but password managers and browser plugins presumably at least try to scrub passwords from memory, which will save you if you forget to lock your screen or your window manager has a screen lock bypass bug (very common).
The Emacs solution will protect you if you don't use full-disk encryption and your disk falls into the wrong hands, but that applies (or should apply) to all password managers.
What am I missing?
Edit: The same applies to the solution in the article.
(defun cc () "Secrets File" (interactive) (find-file "/home/ajross/.cc.gpg"))
Launch with "M-x cc" (which is simple enough) or bind to a keystroke. Emacs will prompt you for the decryption cleanly, your distro will surely cache them with gpg-agent, and you can then just edit it and cut and paste as you like.I'm pretty sure it's "cc" because it was originally a list of credit card numbers, but quite frankly I've been doing this so long I've forgotten.
https://github.com/abgoyal/password-store2
Yes, it even has bash completion. Its fallen a bit behind the upstream as I have not had the time to port in the new features (nor felt the need :-/). Comments/patches welcome.
[edit] I see that the passphrase is passed as a command-line argument. Aren't those viewable to other users on linux?
If anyone gets hold of your master key/pwd, they would have access to all your usernames & pwds.
https://ssd.eff.org/en/module/how-use-keepassx
Best to keep them separate - in your brain!
I was also about to join the bandwagon of using a password manager.
>If anyone gets hold of your master key/pwd, they would have access to all your usernames & pwds. You would still need access to the physical storage medium. This is either a threat or not depending on your threat model, and for most people this is simply not a threat. And tbh, if someone got a hold of your unencrypted computer you got another problem.