Jump to content

abhibeckert

Members
  • Content Count

    7
  • Joined

  • Last visited

  • Days Won

    1

Posts posted by abhibeckert


  1. On 9/17/2019 at 7:01 AM, Fabian1 said:

    1Password will delete the masterpassword. there is a timeout. even, if you turn off your phone, you have enter the masterpassword again. why this is a problem for enpass? 

    I use 1Password and Enpass. They both store your master password in the keychain and 1Password definitely doesn't require entering it after a restart.

    Both 1Password and Enpass allow you to configure a timeout. The shortest timeout in 1Password is an hour - they store it in your keychain on flash memory exactly the same as Enpass (and probably for longer than an hour).

    If your passwords are sensitive enough for keychain's security model to be unacceptable then they shouldn't be stored in *any* password manager. Switch to something simple like a plain text file encrypted with AES for those specific passwords. If you want to be worried about anything, you should worry about browser plugins creating a significant attack surface. That's far more likely to result in a compromise than Apple's keychain database.


  2. The Enpass app icon - a blue circle with a white symbol - is very similar to other popular apps. See screenshot.

    Can you please work on a new icon that isn't based on a blue circle? Perhaps a blue border around the white angled rectangle for example?

    I have to stop and think whenever I switch to an app, especially with Enpass and SourceTree. I can't imagine they will change theirs (being a large company) but hopefully you're open to it? That would be awesome.

    Screen Shot 2019-08-20 at 09.50.24.png

    • Sad 1

  3. Ultimately, Enpass stores all of your passwords on the device. Therefore if you don't trust the device, you shouldn't install Enpass on it at all.

    The iOS keychain is designed to store things privately. Yes there are ways to dump the keychian, but especially if your device isn't jail broken and you have a strong password to lock the phone the Keychain is very secure.

    Also there really is no alternative other than to make the user type the master password every time they need to auto-fill a password or do a background sync operation - and the entire point of Enpass is to let users avoid typing passwords.


  4. Exclude the Enpass vault from entirely from your QRecall backups and backup the Auto Backups directory (you can find the location in Enpass settings).

    Auto Backups are only written when changes have been made, and it's not immediate so you're given a chance to roll several changes into a single backup. For me, there have only been seven backups in the last month.

    Wearing out your SSD isn't a concern - a good quality SSD can handle around 150GB of writes per day and still last a decade or so. It's only a concern for old or cheap drives.

    Also... it's a good policy to have a local backup, perhaps to an external HDD, in addition to your cloud backup. Since it's faster and cheaper, you can backup more frequently and include things like your Enpass vault. Also, restoring from a local disk is a lot quicker than restoring from the cloud.


  5. With Enpass 5.6, I can configure a system-wide hotkey to open the Enpass Helper, type a search term, then use arrow keys followed by the return key to copy a password.

    On the new beta version this doesn't work:

    1. There's no setting for a system-wide hotkey to open the helper
    2. After opening the helper by clicking the menu item, the search box doesn't always have keyboard focus (it does occasionally have focus. I haven't been able to reproduce reliably)
    3. Once I've typed a search term, I'm unable to use arrow keys to select a result - I have to click the tiny "info" button
    4. With the entry details open, again it's not possible to navigate with arrow keys or hit return to copy a password

    I hope this can be resolved soon. I've been waiting a very long time for multiple vaults, and now I have it this new issue is preventing me from fully switching to Enpass from 1Password (I currently use Enpass 5 for one of my vaults, and 1Password for two other Vaults).

    PS: It would be really nice if, when using an arrow key to open an entry, it highlighted the password automatically. On Enpass 5.6 nothing is highlighted and I typically need to hit the Down Key three or four times before Enter to copy the password.

    (I'm using the macOS version of the beta)

    • Thanks 1
×
×
  • Create New...