Jump to content
View in the app

A better way to browse. Learn more.

Enpass Discussion Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Featured Replies

I understand that you do not wish to open-source your product, but I am reluctant to use it because of the fact it is closed-source, the company is based in India (yes, this matters) and there is no information about the development team.

Have you considered having an independent 3rd-party audit your source-code on a regular basis as a way to gain credibility without open-sourcing your product?

Thanks,
Gili

  • Replies 181
  • Views 278.9k
  • Created
  • Last Reply

Top Posters In This Topic

Most Popular Posts

  • Amandeep Kumar
    Amandeep Kumar

    We completely agree that security, transparency, and regular audit practices are of utmost importance especially for a product like Enpass that is built around protecting sensitive data. As part

Posted Images

On 1. 9. 2016 at 1:29 AM, Gili said:

I understand that you do not wish to open-source your product, but I am reluctant to use it because of the fact it is closed-source, the company is based in India (yes, this matters) and there is no information about the development team.

Have you considered having an independent 3rd-party audit your source-code on a regular basis as a way to gain credibility without open-sourcing your product?

Thanks,
Gili

+1

I totally agree! That would boost up your reputation!

  • 3 weeks later...
  • 1 month later...
  • 3 weeks later...

At least an answer please? AFAIK "Security of our data is your utmost priority." We have questions and thoughts, yet there is not even an answer from the maintainers. This itself means a serious security concern.

Hi @Mark

Thanks for posting your query on our Forums. From a consumer point of view, we do respect your concern about security.

17 hours ago, Mark said:

"Security of our data is your utmost priority."

 Yes. it's true.

On 9/2/2016 at 4:59 AM, Gili said:

Have you considered having an independent 3rd-party audit your source-code on a regular basis as a way to gain credibility without open-sourcing your product?

1

We also thought of getting a third party audit of Enpass but eventually had to drop this idea for some time (so far). All this because Enpass supports so many platforms with a high frequency of updates (all together) and it is not possible for us to get every update audited because every successive update will invalidate the last audit done. Also getting the source code audited is very hefty in terms of time and expense.

I hope that helps answer your question.

  • Author

Hemant,

Thank you for your response.

I don't think anyone is expecting frequent audits. Once a year or every 3 years should be enough. As to the cost... that's the cost of doing business. The primary reason I skipped over this product was because it was both close-sourced and unaudited. Otherwise, I would have purchased a copy.

Gili

On 2016-12-01 at 5:48 PM, Gili said:

Hemant,

Thank you for your response.

I don't think anyone is expecting frequent audits. Once a year or every 3 years should be enough. As to the cost... that's the cost of doing business. The primary reason I skipped over this product was because it was both close-sourced and unaudited. Otherwise, I would have purchased a copy.

Gili

+1

If you choose not to share the source, its sorta up to you to pay some third party to review the code with NDA.

And as Gili said, no one expects reoccuring audits. Its mostly, or at least about customers needing to know that you've implemented cryptography in a acceptable way and of course that there are no additional ways in to a running process of Enpass.

 

Edited by Ivarson

Hermant,

I didn't say it's not true, just wanted to point that if it is then some response to these topics might help.

Actually I am not that concerned about anyone stealing the credentials to my favourite restaurant's website (I don't keep sensitive data in these programs), but nevertheless I am doing my homework in form of a "security audit". I am no security expert nor have access to the source code, but can still find the obvious things (database, encryption, cloud sync, communication, etc) which might make people a little bit less afraid of your software.

Even then, these days it's quite common that people are afraid of anything when it comes to their privacy. This is something that you should keep in mind when choosing not to do a third-party audit because <insert any reason here>.

+1

It's funny to hear that ensuring that your cryptographic product is in fact secure is not worth the effort.
Other apps come to mind: Signal, Telegram, Veracrypt.

All cross-platform, all frequently updated, all audited.
Oh, and they're all free.

Edited by gammy

  • 3 weeks later...

+1

  • 4 weeks later...

Hello, everybody!

I truly understand your concern for a software holding critcal information and not being open sourced or audited by any credible third party agency. 
Well guys, thanks for all your comments and we've decided to get third party audit of Enpass. But all we need is just some more time as after the upcoming release of Attachments (beta is already there), we'll work on some key features like multiple-vaults with a need of refactoring the core engine, and I think that would be that best time to go for audit, all at once.

Till then, please bear with us and all I ask for is your co-operation.

Cheers!

Create an account or sign in to comment

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.