On Tue, 3 Mar 2015 00:32:05 -0500 Dylan Mikus <[email protected]> wrote:
> Has there been any thought into encrypting the actual directory tree
> so that no one would be able to view what accounts you have? Is that
> something people are interested in, or was there a conscious decision
> against it for design reasons?

Encrypting the entire directory tree makes it a lot harder to process
things with plain UNIX tools if you for some reason don't want to or
can't use pass to access the store.

Conversely, if you really think the minor metadata leak is a problem,
tar up and gpg-encrypt your $PASSWORD_STORE_DIR and write a wrapper for
pass that decrypts/untars it to /dev/shm and sets $PASSWORD_STORE_DIR
appropriately, then cleans up after itself.

-- 
Patrick Burroughs (Celti) <[email protected]>

Attachment: pgpAB9Y_BpqUP.pgp
Description: PGP signature

_______________________________________________
Password-Store mailing list
[email protected]
http://lists.zx2c4.com/mailman/listinfo/password-store

Reply via email to