So, I’ve been using keepassxc for some time now, but I wanted a viable alternative for command line usage (there is keepassxc-cli, that I use, but it is really a pain in the ass). So, I searched and found pass and gopass.

However, I’ve seen that they store each entry in a gpg encrypted file, inside a plain directory hierarchy. And, don’t get me wrong, I believe that there are use cases for this, but if someone got their hands in your password_store, they would know every single login that you have (the only information that is protected is the password, or whatever is in the gpg file).

So, my question is, there is a password manager, cli based, that encrypts the whole database, and not the single entries?

Update: there is a pass extension made specifically to address this issue

  • Prunebutt@slrpnk.net
    link
    fedilink
    arrow-up
    3
    arrow-down
    1
    ·
    edit-2
    3 days ago

    Sorry, homie. I’m not gonna keep arguing with you if you obviously can’t argue without moving the goal posts, if your life depends on it.

    My point still stands: Encrypting metadata can be sensible/necessary for your threat model and does not count as security through obscurity. You have failed to explain how it would be and then started to attack me, personally.

    Have fun misrepresenting this comment as well, bye.

    • Xanza@lemm.ee
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      2
      ·
      3 days ago

      Encrypting metadata can be sensible/necessary for your threat model and does not count as security through obscurity. You have failed to explain how it would be.

      I mean, your scenarios here are predicated on the idea that you’re so concerned about privacy and security that you use PGP to protect your passwords, but leave your PC totally unencrypted and not password protected for “the police” to just come in and take and discover metdata about your proclivities.

      It’s absurd to the n^th degree and how you don’t see that is astonishing.