Password managers

Hi sko,
SSH logins, email signing/encrypting and passwords (and other) encryption is since done with the keys on the yubikey, which needs its own password for unlocking (the only one I can and have to remember by now...).

As there is unreliable cell signal at my location, I had been doing some research for alternatives to 2FA via SMS and found a recommendation of Yubikey But from your quote, it seems that Yubikey can be used for other purposes than only 2FA.

As a former user of pass (https://www.passwordstore.org/) could you please explain the use of Yubikey for what you are doing, it it is not too off-topic?

Kindest regards,

M
 
As a former user of pass (https://www.passwordstore.org/) could you please explain the use of Yubikey for what you are doing, it it is not too off-topic?
basically, I'm using the yubikey purely as a smartcard to store my private GPG-keys on it.

I never really had any interest in using U2F, FIDO or whatnot, because it always relies on some external (and sometimes even proprietary) service and working internet connection. I deliberately chose password-store because it uses gpg and nothing "exotic" and I absolutely want/need to access my credentials etc if there is no internet connection available - it wouldn't make any sense for me to add something that requires an external service.
IMHO it's stupid to store credentials (or second factors) for infrastructure like router/gateway systems, switches, BMC etc in a service that relies on the infrastructure to work - if that goes down you are essentially unable to access anything to fix the situation. Also I often have my laptop connected to completely locked-down VLANs where I still need to access credentials or log in via SSH.
By only using its smartcard capabilities, I hold everything I need in my hand with the yubikey - either for decrypting credentials or for SSH logins via the gnupg ssh agent.

For 2FA I only use TOTP - I always refused to use SMS as it is insecure by design anyways. there's a TOTP plugin for password store, so that's fully covered.
 
Hi sko,
basically, I'm using the yubikey purely as a smartcard to store my private GPG-keys on it.
Thank you for the clarification.

Regarding the 2FA, in my understanding, the protocol that one can/must use is dependent on what the web-site supports.

Kindest regards,

M
 
I feel like we should have several good threads about password storage/security pulled together AND refreshed. Some things don't change, of course, but maybe there are some latest and greatest things or updated infos. (And in general, this is the biggest bug about most forums - no 3D organization/aggregation between threads and topics...I feel tags don't work).


I feel like openssl is the correct approach but with a must of modern options that weren't mentioned here, I think.
openssl enc -aes-256-cbc -salt -pbkdf2 -iter 2000000. 👨‍🏫
 
I use security/keepass. What makes me stick to the application is that it has synchronizing of kbdx file feature. I share a kbdx file by OneDrive, and on each FreeBSD or Windows PC, use another kbdx file outside OneDrive and synchronize the file with the one under OneDrive from time to time. Thus, I can edit the kbdx file on several host and keep it synchronized across them. As I use both FreeBSD and Windows PC , I need an application that support both operating systems. (And for Android smartphone, I download the kbdx file from OneDrive and use KeePassDroid. I need to be careful not to edit kbdx file on Android.)
The problem is that its copy and paste feature and autotype feature do not work on Wayland. There is a plugin that say to have enabled autotype on Wayland, but I could not get it to work properly. So I wrote a small patch (PR 291869) to make copy and paste of user name and password possible on Wayland (not autotype, as I could not imagine how to realize it). I should report it to upstream, but did not yet.
 
I do not know what synchronize feature is. it has auto-type feature mentioned in topic but apparently it works only on x11. i do not use either one do its not a problem for me.
 
Back
Top