Jump to content
Enpass Discussion Forum

Ivarson

Members
  • Posts

    227
  • Joined

  • Last visited

  • Days Won

    47

Everything posted by Ivarson

  1. Verified as solved in Beta 6.8.3.
  2. Ivarson

    Security

    I think any password manager does just that, almost by definition password managers does two things; A. Requires at least a password to read secrets B. Encrypts the database in such way that it's impossible or impractible to read the secrets without that first password. You need to have a good password on your laptop, and also a strong password in Enpass. Your computers harddrive should be encrypted which is the default on modern devices. If your laptop is stolen, those are your asurances, as the data of Enpass resides locally, and you can't just call Enpass and have them "flush" the saved passwords on your stolen laptop.
  3. What is "desync"? You have to authenticate on all cloud-providers? Have you checked date, time and timezones on all devices?
  4. On Desktops, the arrow that allows user to expand a tag's sub-tags is very small and hard to hit. Either make the droparrow bigger, or allow user to doubleclick a tag to have it's subtags expanded or imploded. thanks.
  5. Mkay. There's no beta 6.8.3 for android thought.
  6. If you only need the passwords on your phone, there's no point involving another pc or phone. You install Enpass where ever you need it?
  7. It implements the Autofill-API's on iOS and Android, for websites and apps. But on Desktop OS's there are no generic API's for that, so only autofill in websites via the plugins. Some password managers like keepass, keepassxc, keeweb have AutoTyping-functionality but this isnt implemented in Enpass which is ashame.
  8. If youre used to Enpass and want to pay ahead you should go for https://stacksocial.com/sales/enpass-plan-lifetime-subscriptions which a lifetime premium. Don't be too stressed about the decrementing timer, the deal seems to reset once expired, but of course you never know.
  9. isn't that an inoffical and old packing of Enpass?
  10. Ivarson

    Backup

    Enpass isn't associated with the backup-files if you just double click them. And Word can't open them for sure. You can (and should occasionally) do a restore to verify them. That could be done either on another device (with no other Enpass data) or by creating a new, empty vault and choose Restore from backup during creation
  11. - https://www.enpass.io/ Very few people use Enpass in a strictly offline fashion, it's mostly a slogan to indicate that the user isn't dependent on Enpass to store the items such as many other pwmanagers. the sellingpoint for Enpass is that, if they where to be breached none of their customers store their data at Enpass, but scattered on various public clouds. And they don't have to provide infrastructure for it. for the customer, it's also meant to sense of security that the destination of your cloudprovider (google, icloud) is merely a storage facility for your data, it has no idea of it's content or the password. if you have a laptop or desktop you can also choose to sync internally within you home LAN leaving out public clouds entirely.
  12. It's not clear whether youre referring to the keyfile, the actual vault or the backup-files? the vault can be moved on some platforms, but should probably only be moved if it's neccesary. the optional keyfile that complements the password should not be too visible as you state it, for instance should it be placed on your Desktop it could be noticed via "shoulder surfing" and stolen if you left your computer unattended for few seconds. A USB-key in your keychain could be good, as long as you have a copy of the file in case it gets lost. the location for backup-files can also be moved, a good strategy would be to copy it regularly to safe place, preferable offline media like a USB-drive to safeguard against ransomware, harddrive failures or other thefts. If you were referring to the keyfile, it's worth mentioning that on some platforms, the keyfile doesn't have to be present during decryption since it's stored in the secure storage, this applies to at least iOS, Android, Windows (not all computers supports that)
  13. No, people have been nagging for that for many years (including me). There's an advanced section for the vault password where you can generate a Keyfile to use in addition to your password. While that isn't comparable to fido2 / challenge-response using a hardware token, it adds some complexity to your password. If using a Keyfile you have to both store the file safely but also not to exposed.
  14. You'll soon have to strike out _offline_ in the description, while you can opt out manually from some if it, Enpass dials out alot to check news, license subscription, favicons. But essentially one aren't tied to use Google Chrome when using a standalone password manager like Enpass.
  15. On a Google Chromebook, when tapping the link next to a URL-field in a Item , the browser isn't launched as in Android ChromeOS up 2 date and latest beta
  16. On ios 15.6.1 using Enpass 6.8.1. 2 vaults. If you create an item in a custom category in a secondary vault, the category counter is incremented, but the item doesn't show up if one shows all vaults. If the view is changed to show only the secondary vault the item shows up.
  17. Please tell me if you need more data from me regarding the slowness of the Windows apps. I currently use Portable version 6.6.1 since that's still quick, but it lacks plugin Pop-up support in the browser plugins as well as Windows Hello-support. I'm surprised there aren't more voices about it. The Linux-app is still quick and responsive so it's nothing in the Core-part of Enpass..
  18. 1. Always open to: All vaults 2. Facing problem during fresh launch off app (the icon is incorrect before the sync starts or completes, and continues to be wrong after, until one re-selects All vaults). However it's not happening every time and I don't know how to reproduce it
  19. Implement a new fieldtype checkbox ✅. It can be checked or unchecked (directly from the item view, not in the edit items view. This simple field would greatly enhance the use of Enpass, like shopping lists or todos. Not at least for shared vaults.
  20. I thnk the way those stealers operate is that they steal the tokens that various apps and extensions have stored locally. Even if Enpass extension even stores a token somewhere once being authorized, the vault is local (loopback). in that sense it's not vulnerable. if the stealer were to steal files in general in the OS (extensions are heaviliy sandboxed), reaching for the walletx/db-files of Enpass, they would never be in a decrypted / plaintext state like @Redeemer said.
  21. On all platforms, Enpass has a setting that's on by default, that copies and maintains the TOTP if the corresponding item has been chosen for autofill. So you should never have to copy, only paste, which isn't that time consuming. if you're into fiddeling (and depending on the platform) you can also setup different shortcuts to the Paste command, like the middle button of the mouse.. having that said, I don't if the developers actively try to improve autofill for TOTP as the do with username+password. They'll have to answer for that. frankly i just wish they implemented Autotype-functionality as an option which would make Enpass be able to autofill native applications and break the dependency of a browser plugin all in all. but thats another fairytale.. (your question is a bit misplaced though, it belong in this category)
  22. Any response from them devs for Windows?
  23. Enpass should be farely safe in a quantum computing era as it uses SQLCipher with AES. As long as you use atleast 256 of keysize which is the informal industry standard which Enpass also does. Cryptos that are at risk are RSA and with that public key implementations https://en.wikipedia.org/wiki/Post-quantum_cryptography https://www.enpass.io/security/
  24. Used 6.8.2 build 1084 from Microsoft Store for a while and it's still slow. Since you claim that Enpass shares the same core across OS:es, and the Linux nor Mac-versions aren't slugish, It has to be something in the GUI.. although there's no difference for me in modern versus classic theme. I've got 4 vaults atm. with 408 items in total. Windows 11 21h2. Further more, I have credential guard, bitlocker and a EDR running. Never the less, prior to 6.8 the performance was way better and Enpass Portable still runs smothly. Now when I launch the Enpass Helper from systray or a browser plugin, it takes between 1-3 seconds to load the list, and also general navigation within Enpass mainwindow takes noticable time. Unless you've intentionally put lots of extra checks in for Windows, it feels like your codelogic does something too many times in the app's Eventhandlers..
  25. When a vault is being changed from another device and hence reloaded on the phone in question; categories, tags and 'others'-sections in the "Browse"-view are being duplicated. That is, Creditcard, Misc appears twice etc. The duplicates disappear when one switches views between All items, browse and audit It doesnt affect items so just a gui glitch during reload after a database merge has occured. Enpass: 6.8.2.666 Device: OnePlus 7T Android: 11
×
×
  • Create New...