Re: Thoughts on TOTP/HOTP support in PasswordSafe?
"pwsafe.org" <[email protected]> Fri, 4 Oct 2019 08:13:07 +0300
| Newsgroups | gmane.comp.security.passwordsafe.devel |
|---|---|
| Message-ID | <CAKUoDdL3xKE3KEHQCjaXCqw19WuK-ORm3vSQR6G=nDCPJtfMdA@mail.gmail.com> |
--===============1101301991643193656== Content-Type: multipart/alternative; boundary="00000000000073a9a705940ec2dd" --00000000000073a9a705940ec2dd Content-Type: text/plain; charset="UTF-8" A few thoughts: - This will require format changes - at least one new field to indicate the entry is for a OTP, and not a "regular" password. - Are the specs for the various authenticators out there (Authy, Google Authenticator, etc.) publicly available and usable to implement a clone in pwsafe? - The biggest challenge for implementing this is to do so in a way that won't "penalize" the users of "classic" passwords. By "penalize" I mean require extra clicks/keystrokes over what's required today to create and use a given entry. Discussion? On Fri, Oct 4, 2019 at 6:18 AM Bill Blough via Passwordsafe-devel < [email protected]> wrote: > Hi all, > > I've been considering implementing TOTP/HOTP support in PasswordSafe. > The idea is that you would be able to store the seed for a given > account, then have PasswordSafe generate the TOTP/HOTP code as needed > (instead of using something like Google Authenticator). > > However, I've had some people (unrelated to this project) suggest that > this is a Bad Idea^TM. Since I'm writing this email, it's probably obvious > that I disagree. I'd be happy to explain my rationale if anyone wants to > discuss it. > > I do think it would be convenient functionality to have for those of use > that would use it, and I'm willing to do the work. Well, at least for > core and wx. I could probably do the Windows implementation too, but I > haven't done Windows GUI programming in something like 20 years. As > such, if someone else wanted to handle that piece, I'd be grateful. > > That said, I don't want to spend the time and effort needed to implement > it only to find out that everyone thinks I'm completely bonkers and that > it will never get merged. > > So is this something I should pursue, or should I skip it? > > Regards, > Bill > > -- > GPG: 5CDD 0C9C F446 BC1B 2509 8791 1762 E022 7034 CF84 > > > _______________________________________________ > Passwordsafe-devel mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel > -- Ubi dubium, ibi libertas (where there is doubt, there is freedom) --00000000000073a9a705940ec2dd Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">A f= ew thoughts:</div><div class=3D"gmail_default" style=3D"font-size:small"><b= r></div><div class=3D"gmail_default" style=3D"font-size:small">- This will = require format changes - at least one new field to indicate the entry is fo= r a OTP, and not a "regular" password.</div><div class=3D"gmail_d= efault" style=3D"font-size:small">- Are the specs for the various authentic= ators out there (Authy, Google Authenticator, etc.) publicly available and = usable to implement a clone in pwsafe?</div><div class=3D"gmail_default" st= yle=3D"font-size:small">- The biggest challenge for implementing this is to= do so in a way that won't "penalize" the users of "clas= sic" passwords. By "penalize" I mean require extra clicks/ke= ystrokes over what's required today to create and use a given entry.</d= iv><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div cl= ass=3D"gmail_default" style=3D"font-size:small">Discussion?</div></div><br>= <div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Oc= t 4, 2019 at 6:18 AM Bill Blough via Passwordsafe-devel <<a href=3D"mail= to:[email protected]">[email protected]= eforge.net</a>> wrote:<br></div><blockquote class=3D"gmail_quote" style= =3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding= -left:1ex">Hi all,<br> <br> I've been considering implementing TOTP/HOTP support in PasswordSafe.<b= r> The idea is that you would be able to store the seed for a given<br> account, then have PasswordSafe generate the TOTP/HOTP code as needed<br> (instead of using something like Google Authenticator).<br> <br> However, I've had some people (unrelated to this project) suggest that<= br> this is a Bad Idea^TM.=C2=A0 Since I'm writing this email, it's pro= bably obvious<br> that I disagree.=C2=A0 I'd be happy to explain my rationale if anyone w= ants to<br> discuss it.<br> <br> I do think it would be convenient functionality to have for those of use<br= > that would use it, and I'm willing to do the work.=C2=A0 Well, at least= for<br> core and wx.=C2=A0 I could probably do the Windows implementation too, but = I<br> haven't done Windows GUI programming in something like 20 years. As<br> such, if someone else wanted to handle that piece, I'd be grateful.<br> <br> That said, I don't want to spend the time and effort needed to implemen= t<br> it only to find out that everyone thinks I'm completely bonkers and tha= t<br> it will never get merged.<br> <br> So is this something I should pursue, or should I skip it?<br> <br> Regards,<br> Bill<br> <br> -- <br> GPG: 5CDD 0C9C F446 BC1B 2509=C2=A0 8791 1762 E022 7034 CF84<br> <br> <br> _______________________________________________<br> Passwordsafe-devel mailing list<br> <a href=3D"mailto:[email protected]" target=3D"_blan= k">[email protected]</a><br> <a href=3D"https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel"= rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l= istinfo/passwordsafe-devel</a><br> </blockquote></div><br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"= class=3D"gmail_signature"><div dir=3D"ltr"><span style=3D"font-size:12.8px= ">Ubi dubium, ibi libertas (where there is doubt, there is freedom)</span><= br></div></div> --00000000000073a9a705940ec2dd-- --===============1101301991643193656== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1101301991643193656== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Passwordsafe-devel mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel --===============1101301991643193656==--