124 karma · joined March 21, 2017
Hare tries to be simple, so that it's easier to reason about the code and hence maybe find/avoid such bugs more easily.
I would definitely use the browser password manager, if I could choose where to sync the data to. I think it's possible with firefox, but it's not straight forward.
I personally trust pfp, because the creator is doing audits of browser addons and publishes them on his blog. They are very well explained.
Also the code is quite compact compared to the other password managers. LastPass, 1Password and Bitwarden have more than 100,000 lines of code, including many third party dependencies. So an audit of PfP is more feasible.
Yes the pop-up could be faked, but not the button.
Actually Tavis Ormandy found a lot of security breaches in password managers that loaded GUI elements into the website. Not only that you can fake it, but also they are susceptible to clickjacking.
I've also spend a lot of time with understanding password managers in my master thesis. What I can recommend is: https://pfp.works/
The creator was auditing password managers like LastPass, found a lot of issues, and used his knowledge to create pfp, which does it right imho.
The only thing I'm not really fond of, is that the apps come from an opaque source (https://info.cleanapk.org/). I also found no information on how those apps are signed, and how this is checked. Upon asking them, someone pointed me to a git commit where an outdated public key of F-Droid was used.
I will consider changing the invert flag, but I'm not that happy with something like "--list=...". There will be only two modes with discard being the default one. So imho there should be only one flag to switch to the non-default mode.
https://paragonie.com/blog/2018/01/our-ambitious-plan-make-i...
It was a real eye opener for me.