home.social

#vaultwarden — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #vaultwarden, aggregated by home.social.

  1. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  2. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  3. @monniele The two closest actual production initiatives, or perhaps, production grade proof of concepts, at least in my mind, were/are Keybase and KeyOxide, respectively - not that #Keybase is gone, but just a scroll back a couple of days I quote posted a post linked to @simontatham 's Fedi post two weeks ago about Zoom privacy mining one of your clipboards.

    You can find my post just scrolling back 4 days until you see Kewl Hand Luke, finally pretending to relent to the Captain's perverse requirement of total and complete subjugation.

    Anyway, Keybase has been a modern day ghost town since Chris Coyne abrubtly announced he had sold it to Zoom and then rode off into the sunset. The underlying issue is indeed trust, and Zoom could and may have introduced new keys at anytime w/o notification.

    I'm getting off the point a bit, I think. The concept of both Keybase and #KeyOxide is that of an ever increasing cross-convoluted web of signed cryptographic proofs that atest that "I am who I say I am".

    Certainly, There's no way to certify my:

    client side attestation that verifies the user's intent rather than just their device ID.

    ... After all, I might be psychotically afflicted with bi-polar disorder twice a week (I'm not, but still), but I do believe that mal-intents, for the most part, aren't going to go through weeks and years of building cross-connects showcasing their personalities and presence, like the everyday schmoes like you and I might because we, as people, typically like to share essentially who we are... or at least, who we see ourselves as :)

    I do think that FOSS based community managed services can go a long way towards at least assuring, if not certifying, with a great degree of confidence that we are who we say [we think] we are though.

    There's an elephant in the room though that no one has pointed at. Even Simon mentions it so matter-of-factly that I don't believe the emphasis that we need to place on this is being ascribed to the problem - Zoom is (almost certainly) privacy mining password vaults via the clipboard - VaultWarden, KeypassXC, Pass, Ente Auth, Etc., if not ubiquitous, are certainly increasingly commonplace utilities in everyday use on Androids and Desktops globally. Industrial password farming from the clipboard is a very real threat.

    Well at the risk of already having bored you to death, or maybe just preaching to the choir, I'll close now, thanking you for your thoughtful reply :)

    #tallship #OpenSource #FOSS #KeepassXC #KeepassDX #kdbx #VaultWarden #pass #passwordstore #OpenKeyChain #Identity #Privacy

  4. just tested a full functional restore of my #Vaultwarden setup on a different machine. Confirmed I'm able to login to my vault and see my content in there. Now documenting this for myself and will eventually also write a blog post about this.

  5. just tested a full functional restore of my #Vaultwarden setup on a different machine. Confirmed I'm able to login to my vault and see my content in there. Now documenting this for myself and will eventually also write a blog post about this.

  6. just tested a full functional restore of my #Vaultwarden setup on a different machine. Confirmed I'm able to login to my vault and see my content in there. Now documenting this for myself and will eventually also write a blog post about this.

  7. just tested a full functional restore of my #Vaultwarden setup on a different machine. Confirmed I'm able to login to my vault and see my content in there. Now documenting this for myself and will eventually also write a blog post about this.

  8. just tested a full functional restore of my #Vaultwarden setup on a different machine. Confirmed I'm able to login to my vault and see my content in there. Now documenting this for myself and will eventually also write a blog post about this.