Re: [Passwordsafe-linux] Thoughts on TOTP/HOTP support in PasswordSafe?
Popular easy-to-use and secure password manager
Brought to you by:
ronys
From: Bill B. <de...@bl...> - 2019-10-04 20:55:37
|
Hi again, Someone contacted me privately and suggested that HOTP might be problematic, since the counter must be kept in sync with the server. If the user has their database set to read-only, then that creates an issue, as does recovering an older database from backup. If we can find a way around those issues, then great. If not, then it would probably be better to only provide TOTP support. (HTOP would still need to be implemented because TOTP relies upon it, but we could not expose it and keep it internal-only) Bill On Thu, Oct 03, 2019 at 11:18:02PM -0400, Bill Blough via Passwordsafe-linux wrote: > Hi all, > > I've been considering implementing TOTP/HOTP support in PasswordSafe. > The idea is that you would be able to store the seed for a given > account, then have PasswordSafe generate the TOTP/HOTP code as needed > (instead of using something like Google Authenticator). > > However, I've had some people (unrelated to this project) suggest that > this is a Bad Idea^TM. Since I'm writing this email, it's probably obvious > that I disagree. I'd be happy to explain my rationale if anyone wants to > discuss it. > > I do think it would be convenient functionality to have for those of use > that would use it, and I'm willing to do the work. Well, at least for > core and wx. I could probably do the Windows implementation too, but I > haven't done Windows GUI programming in something like 20 years. As > such, if someone else wanted to handle that piece, I'd be grateful. > > That said, I don't want to spend the time and effort needed to implement > it only to find out that everyone thinks I'm completely bonkers and that > it will never get merged. > > So is this something I should pursue, or should I skip it? > > Regards, > Bill > > -- > GPG: 5CDD 0C9C F446 BC1B 2509 8791 1762 E022 7034 CF84 > > > _______________________________________________ > Passwordsafe-linux mailing list > Pas...@li... > https://lists.sourceforge.net/lists/listinfo/passwordsafe-linux -- GPG: 5CDD 0C9C F446 BC1B 2509 8791 1762 E022 7034 CF84 |