6

!rant
Anyone interested in testing a password manager?

Comments
  • 0
  • 1
    @darksideplease how can I contact you?
  • 7
    And by password manager you mean your new phishing malware? :P
  • 1
    @Grundeir no I mean a cloud password manager like lastpass.
  • 0
    I think this is something for a "Collaborations" post. Passwords is a particularly sensitive thing to randomly trust an online stranger with. I totally get it that temporary accounts is the way to go, but seems like a lot of hassle.
  • 1
    @CrankyOldDev my intention for this post was, that some devs could give me advice on some security related things and also things I should change.
  • 4
    Oh i didn't know it's cloud based. Sorry! I would never endorse that.
  • 2
    @Scrumplex OK. First piece of advice - don't use SHA-1 for encryption.
  • 1
    @CrankyOldDev ah thanks. I think AES-256 with SHA256 will do it
  • 0
    @Scrumplex Yeah. I attempted a topical "joke". Failed miserably. 🙁
  • 1
  • 1
    @uniquesmash the post is about real help, but most of the comments are jokes :)
  • 2
    I honestly wouldn't mind testing it if the server part is self-hostable.
    And if it's not self-hostable, here's some advice: make it self-hostable. A cloud-only password manager is probably the scariest thing I can imagine.
  • 1
    @franga2000 I understand your point. And setting the password manager up yourself would not be a big challenge. If you just change the mysql password in one file you are ready to go. But I am unsure if I should go open source for this project. I probably will but I am not sure.
  • 4
    @Scrumplex For anything handling passwords, your only choice is going open source, since the only people who would even dream of using a closed source password manager are complete and utter idiots.
  • 1
    @Scrumplex the only way to sell a closed-source security program is to have a reputable security firm audit it, which would cost you more than you could ever earn with it.
    A good open-source self-hosted password manager is exactly what the people need. Maybe you can be the one to finally make it.
  • 4
    @Grumpy @franga2000 I think you both are right. I will try to make the installation as user friendly as possible. But first of all sleep.
  • 1
    It is open source now. It does not have an installer but a config.php

    https://github.com/Scrumplex/PASSY

    Have fun and I would appreciate if you would contribute (bug reports or even with code)
  • 0
    @Scrumplex Not saying I'm the best or anything but I'm in the security world myself so I could take a look at your code and give some advice/feedback if you'd like?
  • 1
    @linuxxx y not? Thanks for the help :) you can find the github link in the comment above
  • 0
    @Scrumplex Well I'm still pretty young I guess haha
  • 1
    @linuxxx I will get 16 this year but yeah.
  • 0
    @Scrumplex I'm only 21 myself haha
Add Comment