On Monday, November 13, 2017 at 2:05:02 AM UTC, Patrick Schleizer wrote:
> Eric Shelton:
> > I am curious how people are making effective use of Keepass in a vault 
> > domain.  It seems like with a browser plugin, you might be able to take a 
> > Split GPG type of approach, and avoid all of the cutting and pasting across 
> > domains.  Any comments or suggestions?
> > 
> > - Eric
> > 
> 
> 
> An inter-VM password manager for Qubes OS based on pass (
> https://www.passwordstore.org/ )
> 
> https://github.com/Rudd-O/qubes-pass
> 
> https://groups.google.com/forum/#!topic/qubes-users/amry7Shb94o
> 
> (Adding this here since search for "Keepass" "Qubes" leads to this old
> thread which claims there is no solution at all.)

Doesn't this automation increase possible surface attacks on the keys 
themselves though? Even if using existing Qubes tools, not re-inventing the 
wheel, and keeping Qubes itself safe as it was before using the tool, but the 
automated policy can still be tricked into giving over the password though?

If true, then manual copy/paste between Qubes is supposedly more safe? Because 
the initiation is started from the isolated dom0 ps/2 keyboard (or USB qubed 
keyboard), and not initiated from within the internet exposed Qube itself.  

I imagine this might be good for less important passwords, daily ones that can 
be annoying to type in, but also aren't too important. But regarding important 
passwords, perhaps use the manual method instead?

Having to use manual password copy/paste is a bit slow, takes up at the very 
least several seconds, if not half a minute, to open it up and navigate to find 
your password, and then copy/paste it over. 

So it becomes a question between speed/convenience/insecure vs. 
slow/inconvenience/secure?

Maybe we can make a hybrid here? Like for example have a hardware key, 
requiring you to press it before it accepts the automated process. Or even just 
a popup from the isolated offline password-manager VM, before proceeding. It's 
not fully automated, but it's also not as intensively manual either.

Maybe the inter-VM password manager for Qubes already does something akin to 
requiring a single quick action from inside the offline isolated password 
manager VM before fulfulling the request of the online VM. If I missed it, then 
I apolgize, but I can't see it anywhere.

Thoughts on using a hybrid method though? 

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/d7ab6f86-67cf-4783-9e05-33b3d914acb1%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to