Re: [Passwordsafe-linux] Thoughts on TOTP/HOTP support in PasswordSafe?

"pwsafe.org" <[email protected]> Fri, 4 Oct 2019 11:06:56 +0300
Newsgroups gmane.comp.security.passwordsafe.devel
Message-ID <CAKUoDdJGf0BA_4RsK-7SS-TR8fg9KvD7VbL-vVxNU=xpTBHmHg@mail.gmail.com>
--===============2535897626667772028==
Content-Type: multipart/alternative; boundary="0000000000001dade3059411309a"

--0000000000001dade3059411309a
Content-Type: text/plain; charset="UTF-8"

Hi Tom,

I think that Bill meant adding one time password support for
different sites, not for authenticating PasswordSafe itself using TOTP/HOTP.

Yubikey is currently supported, including the ability to configure a backup
device as you described.

Rony

On Fri, Oct 4, 2019 at 7:38 AM Tom Mitchell <[email protected]> wrote:

> On Thu, Oct 3, 2019 at 8:55 PM Bill Blough via Passwordsafe-linux
> <[email protected]> wrote:
> >
> > Hi all,
> >
> > I've been considering implementing TOTP/HOTP support in PasswordSafe.
>
> It seems possible and interesting but I would rather add YubiKey  support
> first.
> One weakness with password managers is key management for the password
> manger
> software itself.  Two YubiKey device support please.   A pair of
> YubiKey  devices allows a second device to be
> kept in a sealed tamper evident envelop of the managers or company
> office safe. The encrypted password-safe file
> can be replicated as needed for portability.
>
> One problem with the Google and Microsoft Authentication  is they are
> tied to devices that
> are easy to misplace and also have fragile to strong unlock features.
> They are useful.
>
>
>
> --
>           T o m    M i t c h e l l ( o n   N i f t y E g g )
>
>
> _______________________________________________
> Passwordsafe-linux mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/passwordsafe-linux
>


-- 
Ubi dubium, ibi libertas (where there is doubt, there is freedom)

--0000000000001dade3059411309a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size:small">Hi =
Tom,</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div>=
<div class=3D"gmail_default" style=3D"font-size:small">I think that Bill me=
ant adding one time password support for different=C2=A0sites, not for auth=
enticating PasswordSafe itself using TOTP/HOTP.</div><div class=3D"gmail_de=
fault" style=3D"font-size:small"><br></div><div class=3D"gmail_default" sty=
le=3D"font-size:small">Yubikey is currently supported, including the abilit=
y to configure a backup device as you described.</div><div class=3D"gmail_d=
efault" style=3D"font-size:small"><br></div><div class=3D"gmail_default" st=
yle=3D"font-size:small">Rony</div></div><br><div class=3D"gmail_quote"><div=
 dir=3D"ltr" class=3D"gmail_attr">On Fri, Oct 4, 2019 at 7:38 AM Tom Mitche=
ll &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wro=
te:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On Thu, Oct =
3, 2019 at 8:55 PM Bill Blough via Passwordsafe-linux<br>
&lt;<a href=3D"mailto:[email protected]" target=3D"_=
blank">[email protected]</a>&gt; wrote:<br>
&gt;<br>
&gt; Hi all,<br>
&gt;<br>
&gt; I&#39;ve been considering implementing TOTP/HOTP support in PasswordSa=
fe.<br>
<br>
It seems possible and interesting but I would rather add YubiKey=C2=A0 supp=
ort first.<br>
One weakness with password managers is key management for the password mang=
er<br>
software itself.=C2=A0 Two YubiKey device support please.=C2=A0 =C2=A0A pai=
r of<br>
YubiKey=C2=A0 devices allows a second device to be<br>
kept in a sealed tamper evident envelop of the managers or company<br>
office safe. The encrypted password-safe file<br>
can be replicated as needed for portability.<br>
<br>
One problem with the Google and Microsoft Authentication=C2=A0 is they are<=
br>
tied to devices that<br>
are easy to misplace and also have fragile to strong unlock features.<br>
They are useful.<br>
<br>
<br>
<br>
-- <br>
=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 T o m=C2=A0 =C2=A0 M i t c h e l l ( o n=
=C2=A0 =C2=A0N i f t y E g g )<br>
<br>
<br>
_______________________________________________<br>
Passwordsafe-linux mailing list<br>
<a href=3D"mailto:[email protected]" target=3D"_blan=
k">[email protected]</a><br>
<a href=3D"https://lists.sourceforge.net/lists/listinfo/passwordsafe-linux"=
 rel=3D"noreferrer" target=3D"_blank">https://lists.sourceforge.net/lists/l=
istinfo/passwordsafe-linux</a><br>
</blockquote></div><br clear=3D"all"><div><br></div>-- <br><div dir=3D"ltr"=
 class=3D"gmail_signature"><div dir=3D"ltr"><span style=3D"font-size:12.8px=
">Ubi dubium, ibi libertas (where there is doubt, there is freedom)</span><=
br></div></div>

--0000000000001dade3059411309a--


--===============2535897626667772028==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2535897626667772028==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Passwordsafe-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel

--===============2535897626667772028==--