Everything posted by My1
-
Store Attachments in the Vault
well some clouds do delta uploads, but the problem is that not all clouds support that, also for delta uploads you have to make the encryption in a way that delta works because depending on the encryption algorithm, the parts that come later may be heavily influenced by what came before so changing an early attachment would instantly change pretty much everything else making delta uploads impossible
- Store Attachments in the Vault
-
Store Attachments in the Vault
I would be VERY careful with passports and similar gov-issued documents, depending where you live, storing these can be illegal, especially in print-quality. and for other things like a credit card it might be that it's against the contract especially since the check number on the back is supposed to make sure that the card is "present" during the transaction. also you can get an application that's made for storing files, like veracrypt, steganos or similar solutions. Enpass is supposed to be a password manager and not a file safe.
-
Store Attachments in the Vault
well true, regarding the PS, well total, meaning that it's for all posts, and as far as I know IPBoard correctly this is a shared limit among all users, meang if I would attach 19MB now, you could just attach about half an MB. Forum aside, the intresting part is whether the 200kb limit is total or per file is something I dont know, but if it would be peer file you could archive the file into a split archive.
-
Store Attachments in the Vault
yes the limitation is artifical but reasonable, as of now, enpass stores the attachments in the same file as the password DB meaning that if you use sync, that the whole files with everything, has to be bounced around all the time as soon as anything changes. If/when they make it so the database and attachments can get split, this problem will solve itself.
-
Support for U2F
it can be quite a real life scenario, especially with the nano-sized yubikeys. also instead of making 2 different passwords and accept both, you could just set whatever you want as the static pass for the yubi and use that as decryption
-
Third-party audit deleted
now we are talking epic stuff. thanks @Hemant Kumar
- Importing existing Firefox passwords
- Open multiple vaults
-
Some features from a new user
https://github.com/steffen9000/enpass-decryptor
-
Enpass does not support the browser Cyberfox
but why does the check fail if the browser is signed? clearly indicated by the error report.
-
Fingerprint authentication
wait a sec, dont google's guidelines Marshmallow iirc enforce the use of the Android native API for fingerprinting on devices with it?
- Cannot sync with NextCloud (non-SSL)
-
enpass pro downgrade
shouldnt you be able to get into the enpass upgrade dialog and upon selecting to purchase the upgrade select the account and then it should throw you back with a statement that you already bought it?
-
Open multiple vaults
small reminder, this is an offline database, you can forget permissions on that. the only Idea would be a hosted server which manages those permissions the only Problem is that if whoever has control of the server has the decryption password they can completely circumvent the permissions. partially a good Idea but throwing out milti-vault because of this is a bad Idea. while it is helpful to say that group PWs and per-user PWs should be split, truly personal passwords should not be stored in the company DB at all. not a good Idea, or at least not a good default, if we have seperate vaults e.g. for coorperate and personal use or whatever there should be seperate passwords, I mean otherwise, what's the point of having multiple vaults?
-
sync with sync.com
kinda sad since there's quite little here with just Google Drive, icloud (Apple devices only), Dropbox and box iirc, and EVERY ONE of those is US based. okay we have webdav but there are very few clouds that actually support it (the main I know are owncloud and nextcloud, but these are generally self-hosted)
-
not giving me iCloud as a sync option
well I made myself a box account to have my passwords as far away from anything other personal. sadly box doesnt do a standard TOTP 2 factor (well apple doesnt either) they just do SMS but well better then nothing and I prefer having my PWDB somewhere else then my general use cloud.
-
Secure desktop
one of the best things newer windows versions (iirc vista and above) have is the secure desktop, where an application (usually the UAC dialog) can go into its own secure environment where nothing that doesnt have admin rights (especially your average keylogger) can spy in to see any passwords typed in, or interact with it in any way. one feature I really would love would be allowing DB unlock on the secure desktop
-
Launch Enpass without the UI on boot (by splitting Enpass into two executables)
I have enpass as auto start on windows and iirc it always goes quietly right into the tray.
- Support HTTP Auth
-
Some features from a new user
the problem of a self-hosted web app is that it's open source, and well enpass surely isnt, but it may be possible to code something yourself. on github there is an enpass opener which could be used to open the DB and then read it somehow.
-
sync with sync.com
sync being a canadian company is FAR (well at least from a standpoint of law) away from all those US Cloud Services which have fairly annoying laws regarding surveillance and stuff, it would be really great to add it to the list.
-
Hardware token support
although there is just one problem. if you use enpass with mobile you have the problem that most probably those cant really deal with smartcards. the only way I see this happening is as a possible replacement for the master password with still allowing one to be set and used for mobile usage.
-
Couple of sites in which autofill does not work...
how about you go disable automatic sumbission and check whether anything gets filled in in the first place?
-
Opera v39.0.2256.30 with Enpass Beta v5.2.4 for Mac
why not just check the signature and be happy in general, although a self-set trust would be epic. but one thing I would really appreciate would be showing it in a better way. i just got the signature error once by random, all the other times it just shows a connection error with no further details as if enpass wouldnt even have been launched.