Re: Thoughts on TOTP/HOTP support in PasswordSafe?

"pwsafe.org" <[email protected]> Fri, 4 Oct 2019 08:13:07 +0300
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <CAKUoDdL3xKE3KEHQCjaXCqw19WuK-ORm3vSQR6G=nDCPJtfMdA@mail.gmail.com>
--===============1101301991643193656==
Content-Type: multipart/alternative; boundary="00000000000073a9a705940ec2dd"

--00000000000073a9a705940ec2dd
Content-Type: text/plain; charset="UTF-8"

A few thoughts:

- This will require format changes - at least one new field to indicate the
entry is for a OTP, and not a "regular" password.
- Are the specs for the various authenticators out there (Authy, Google
Authenticator, etc.) publicly available and usable to implement a clone in
pwsafe?
- The biggest challenge for implementing this is to do so in a way that
won't "penalize" the users of "classic" passwords. By "penalize" I mean
require extra clicks/keystrokes over what's required today to create and
use a given entry.

Discussion?

On Fri, Oct 4, 2019 at 6:18 AM Bill Blough via Passwordsafe-devel <
[email protected]> wrote:

> Hi all,
>
> I've been considering implementing TOTP/HOTP support in PasswordSafe.
> The idea is that you would be able to store the seed for a given
> account, then have PasswordSafe generate the TOTP/HOTP code as needed
> (instead of using something like Google Authenticator).
>
> However, I've had some people (unrelated to this project) suggest that
> this is a Bad Idea^TM.  Since I'm writing this email, it's probably obvious
> that I disagree.  I'd be happy to explain my rationale if anyone wants to
> discuss it.
>
> I do think it would be convenient functionality to have for those of use
> that would use it, and I'm willing to do the work.  Well, at least for
> core and wx.  I could probably do the Windows implementation too, but I
> haven't done Windows GUI programming in something like 20 years. As
> such, if someone else wanted to handle that piece, I'd be grateful.
>
> That said, I don't want to spend the time and effort needed to implement
> it only to find out that everyone thinks I'm completely bonkers and that
> it will never get merged.
>
> So is this something I should pursue, or should I skip it?
>
> Regards,
> Bill
>
> --
> GPG: 5CDD 0C9C F446 BC1B 2509  8791 1762 E022 7034 CF84
>
>
> _______________________________________________
> Passwordsafe-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel
>


-- 
Ubi dubium, ibi libertas (where there is doubt, there is freedom)

--00000000000073a9a705940ec2dd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">A f=
ew thoughts:</div><div class=3D"gmail_default" style=3D"font-size:small"><b=
r></div><div class=3D"gmail_default" style=3D"font-size:small">- This will =
require format changes - at least one new field to indicate the entry is fo=
r a OTP, and not a &quot;regular&quot; password.</div><div class=3D"gmail_d=
efault" style=3D"font-size:small">- Are the specs for the various authentic=
ators out there (Authy, Google Authenticator, etc.) publicly available and =
usable to implement a clone in pwsafe?</div><div class=3D"gmail_default" st=
yle=3D"font-size:small">- The biggest challenge for implementing this is to=
 do so in a way that won&#39;t &quot;penalize&quot; the users of &quot;clas=
sic&quot; passwords. By &quot;penalize&quot; I mean require extra clicks/ke=
ystrokes over what&#39;s required today to create and use a given entry.</d=
iv><div class=3D"gmail_default" style=3D"font-size:small"><br></div><div cl=
ass=3D"gmail_default" style=3D"font-size:small">Discussion?</div></div><br>=
<div class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Oc=
t 4, 2019 at 6:18 AM Bill Blough via Passwordsafe-devel &lt;<a href=3D"mail=
to:[email protected]">[email protected]=
eforge.net</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=
=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding=
-left:1ex">Hi all,<br>
<br>
I&#39;ve been considering implementing TOTP/HOTP support in PasswordSafe.<b=
r>
The idea is that you would be able to store the seed for a given<br>
account, then have PasswordSafe generate the TOTP/HOTP code as needed<br>
(instead of using something like Google Authenticator).<br>
<br>
However, I&#39;ve had some people (unrelated to this project) suggest that<=
br>
this is a Bad Idea^TM.=C2=A0 Since I&#39;m writing this email, it&#39;s pro=
bably obvious<br>
that I disagree.=C2=A0 I&#39;d be happy to explain my rationale if anyone w=
ants to<br>
discuss it.<br>
<br>
I do think it would be convenient functionality to have for those of use<br=
>
that would use it, and I&#39;m willing to do the work.=C2=A0 Well, at least=
 for<br>
core and wx.=C2=A0 I could probably do the Windows implementation too, but =
I<br>
haven&#39;t done Windows GUI programming in something like 20 years. As<br>
such, if someone else wanted to handle that piece, I&#39;d be grateful.<br>
<br>
That said, I don&#39;t want to spend the time and effort needed to implemen=
t<br>
it only to find out that everyone thinks I&#39;m completely bonkers and tha=
t<br>
it will never get merged.<br>
<br>
So is this something I should pursue, or should I skip it?<br>
<br>
Regards,<br>
Bill<br>
<br>
-- <br>
GPG: 5CDD 0C9C F446 BC1B 2509=C2=A0 8791 1762 E022 7034 CF84<br>
<br>
<br>
_______________________________________________<br>
Passwordsafe-devel mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel"=
 rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/passwordsafe-devel</a><br>
</blockquote></div><br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"=
 class=3D"gmail_signature"><div dir=3D"ltr"><span style=3D"font-size:12.8px=
">Ubi dubium, ibi libertas (where there is doubt, there is freedom)</span><=
br></div></div>

--00000000000073a9a705940ec2dd--


--===============1101301991643193656==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============1101301991643193656==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Passwordsafe-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel

--===============1101301991643193656==--