Re: [Passwordsafe-linux] [Passwordsafe-devel] Thoughts on TOTP/HOTP support in PasswordSafe?
Popular easy-to-use and secure password manager
Brought to you by:
ronys
From: pwsafe.org <ro...@pw...> - 2019-10-04 05:13:30
|
A few thoughts: - This will require format changes - at least one new field to indicate the entry is for a OTP, and not a "regular" password. - Are the specs for the various authenticators out there (Authy, Google Authenticator, etc.) publicly available and usable to implement a clone in pwsafe? - The biggest challenge for implementing this is to do so in a way that won't "penalize" the users of "classic" passwords. By "penalize" I mean require extra clicks/keystrokes over what's required today to create and use a given entry. Discussion? On Fri, Oct 4, 2019 at 6:18 AM Bill Blough via Passwordsafe-devel < pas...@li...> wrote: > Hi all, > > I've been considering implementing TOTP/HOTP support in PasswordSafe. > The idea is that you would be able to store the seed for a given > account, then have PasswordSafe generate the TOTP/HOTP code as needed > (instead of using something like Google Authenticator). > > However, I've had some people (unrelated to this project) suggest that > this is a Bad Idea^TM. Since I'm writing this email, it's probably obvious > that I disagree. I'd be happy to explain my rationale if anyone wants to > discuss it. > > I do think it would be convenient functionality to have for those of use > that would use it, and I'm willing to do the work. Well, at least for > core and wx. I could probably do the Windows implementation too, but I > haven't done Windows GUI programming in something like 20 years. As > such, if someone else wanted to handle that piece, I'd be grateful. > > That said, I don't want to spend the time and effort needed to implement > it only to find out that everyone thinks I'm completely bonkers and that > it will never get merged. > > So is this something I should pursue, or should I skip it? > > Regards, > Bill > > -- > GPG: 5CDD 0C9C F446 BC1B 2509 8791 1762 E022 7034 CF84 > > > _______________________________________________ > Passwordsafe-devel mailing list > Pas...@li... > https://lists.sourceforge.net/lists/listinfo/passwordsafe-devel > -- Ubi dubium, ibi libertas (where there is doubt, there is freedom) |