Post B4Lq3lyaJixzCkXS1w by lumi@snug.moe
(DIR) More posts by lumi@snug.moe
(DIR) Post #B4Lodcyd3OnJoJWoro by violet@corteximplant.com
1 likes, 1 repeats
I'm really disappointed to see #bitwarden falling into the slop hole. Can anyone recommend a #passwordmanager , ideally #selfhosted , that doesn't use LLM slop in its core product, OR in its contributing commits?#askfedi
(DIR) Post #B4LpO9pVEwi91SRlgG by navi@social.vlhl.dev
1 likes, 0 repeats
@violet i use `pass`[1], though it's very non-traditional so it might not be what you wanta directory structure encrypted with pgp and synced with `git`, implemented as a shell scriptextensions like pass-otp also add support for totp, and there's an android app/client and browser extension for autocomplete on those platforms as well(for folks that hate pgp, `passage`[2] exists that uses `age` instead, but no android app for that one, not sure if it works with the browser ext)1: https://www.passwordstore.org/2: https://github.com/FiloSottile/passage
(DIR) Post #B4LpPYJFi5bjEd1jzU by 2something@transfem.social
1 likes, 0 repeats
@violet@corteximplant.com I use Gnome Secrets on desktop and KeepassDX on Android, and I use Nextcloud to sync them. I did a big comparison of password managers in the quoted post.The Gnome Secrets developer recently said they do not use LLMs.https://gitlab.gnome.org/World/secrets/-/issues?sort=created_date&state=closed&first_page_size=20&show=eyJpaWQiOiI2NTYiLCJmdWxsX3BhdGgiOiJXb3JsZC9zZWNyZXRzIiwiaWQiOjIzNjk2MH0%3DUnfortunately, Nextcloud does use AI, and I don't know of a way to sync password between Linux and Android that doesn't involve software using AI.RE: https://transfem.social/notes/aa2w3yuz3tfz0hdp
(DIR) Post #B4Lq3lpMrzaskAE5fE by Beckydog@hydaelyn.coerthansnowstorm.online
0 likes, 0 repeats
@violet @astraluma 1Password has been awesome, my polycule’s resident techspert has had it running locally for ages (well, locally in the cloud, but eh. Not through another server)
(DIR) Post #B4Lq3lyaJixzCkXS1w by lumi@snug.moe
0 likes, 0 repeats
@Beckydog @violet @astraluma isn't it proprietary software? i would argue against using proprietary software for anything, especially anything security-sensitivealso, if you go to 1password.com
(DIR) Post #B4LqM1QLcaC8KNE5pI by violet@corteximplant.com
0 likes, 0 repeats
@lumi @Beckydog @astraluma you are working better than I can this morning. Even researching adjacent to the slop is melting my brain 😭😭😭Thanks Lumi
(DIR) Post #B4LqNGCWANssRmLdSa by lumi@snug.moe
0 likes, 0 repeats
@violet @Beckydog @astraluma ofc :neocat_snuggle:
(DIR) Post #B4LqvCt8zM8o1GTO0e by natty@astolfo.social
0 likes, 0 repeats
@violet@corteximplant.com there is the:- noWe're currently using Chrome's password manager with a custom E2EE passphrase (so it's not signed with a key Google owns (well, encrypted but it probably takes only like your unlock pattern to get it out of their HSMs and TLS can be added and removed :)), probably overkill as a random creature but who knows it might come handy) because:- Bitwarden literally doesn't work- 1Password is probably to follow with their business plan of providing credential storage to agents- LastPass (lmao)- KeePassXC doesn't sync and would fail your requirements- Proton Pass (feds)- ...?- Firefox' password manager we used before Bitwarden
(DIR) Post #B4LrU3CezRBc7IDTJQ by Beckydog@hydaelyn.coerthansnowstorm.online
1 likes, 0 repeats
@lumi @violet @astraluma I can only speak from a user point of things, but there’s no Ai in it afaik!
(DIR) Post #B4LrU3Ru4lNasZLe4W by lumi@snug.moe
0 likes, 0 repeats
@Beckydog @violet @astraluma sadly, it's not like you can check, as it is proprietary software. and from their website, it seems like they do embrace it, so i think there is a high likelihood there is genai-generated code in it
(DIR) Post #B4LrjrLkpOl9zI0ZXs by sammy@cherrykitten.gay
1 likes, 0 repeats
@Beckydog @lumi @violet @astraluma isn't the screenshot above direct proof of the opposite
(DIR) Post #B4LrqKCOTsXVCNiG80 by astraluma@tacobelllabs.net
1 likes, 0 repeats
@lumi @Beckydog @violet i wouldn't equate "shipping features or solutions for AI" to "going all-in on genAI"in the context of this bubble and having investors, having some kind of AI thing is pretty much a requirement for a tech company.But 1pass has always been big on developer, automation, servers, etc, so them re-spinning those existing features for AI would have low impact on their product.
(DIR) Post #B4LrqKNjnhc5lZ1JoG by lumi@snug.moe
0 likes, 0 repeats
@astraluma @Beckydog @violet if we assume that 1password cares about ethics, this is a good argumentbut they're proprietary software, so i don't buy it
(DIR) Post #B4LrwyZhHFz09xmgeO by sammy@cherrykitten.gay
1 likes, 0 repeats
@violet i think vaultwarden is still untainted, even if it still required the official bitwarden apps to use properly at least the server isn't slopware
(DIR) Post #B4Ls5rT14b28intdEe by astraluma@tacobelllabs.net
1 likes, 0 repeats
@lumi @Beckydog @violet you don't need ethics to be against AI?You can be against on the basis of "new hype technologies have a history of being immature and risky" or "genAI code tends to lack nuance and be kinda crap, and we're a security product" or "we use a B-list tech stack, and the AI just isn't very good at it"
(DIR) Post #B4Ls5rfQKSxTLHhXZg by lumi@snug.moe
0 likes, 0 repeats
@astraluma @Beckydog @violet i guess i'm less optimistic about it
(DIR) Post #B4LsbYJ1qhc4YrKtyi by astraluma@tacobelllabs.net
1 likes, 0 repeats
@lumi @Beckydog @violet that's validbut no situation has been improved by overestimating the risksand yes, ultimately, it is all proprietary code and we can only speculate.but so far, all I'm seeing is that 1password is only shipping AI integrations. Which is basically the same as Just's MCP server https://just.systems/man/en/model-context-protocol.html
(DIR) Post #B4LsbYUNAWgf82dxey by astraluma@tacobelllabs.net
1 likes, 0 repeats
@lumi @Beckydog @violet if your goal is nothing that even acknowledges AI, yeah, 1pass does that.but like i said elsethread, it's going to be real hard to do non-trivial computing with that standard in this moment
(DIR) Post #B4LsbYcAhWvRWEIBoe by lumi@snug.moe
0 likes, 0 repeats
@astraluma @Beckydog @violet that is definitely fair. it being proprietary is a much bigger no-no to me
(DIR) Post #B4Lsq9CbSxCz30I36m by zaire@fedi.absturztau.be
0 likes, 0 repeats
@natty @violet you use chrome??????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
(DIR) Post #B4Lsq9Oek8qjeNvftY by zaire@fedi.absturztau.be
0 likes, 0 repeats
@natty @violet not using chrome is like. digital hygiene 101. bweh
(DIR) Post #B4Lsq9ZI6bMABMuATI by natty@astolfo.social
0 likes, 0 repeats
@zaire@fedi.absturztau.be @violet@corteximplant.com :neofox_woozy: is it really? The only thing we don't get is uBO I've been a Firefox user 99% of my life, autofill literally doesn't work for me on mobile, at work I have no choice (I'll let you think about that one for a while), and on Android you don't need to use the same browser as you're using for autofill. On desktop we have no choice unless we wanna painstakingly copy/paste stuff (yes we tried figuring out if we can do autofill but not really)
(DIR) Post #B4LttDdhWdofdDzePA by zaire@fedi.absturztau.be
0 likes, 0 repeats
@natty @violet not using firefox is digital hygiene 102use a fork of either where you’re able
(DIR) Post #B4LttDp2qStGCPIi5Q by natty@astolfo.social
0 likes, 0 repeats
@zaire@fedi.absturztau.be @violet@corteximplant.com You do realize most forks actually increase your fingerprint area right?
(DIR) Post #B4Lw8PH4kTVry9mRHc by Jes@labyrinth.zone
0 likes, 0 repeats
@natty @zaire @violet that's where fingerprint noising comes in Every respected privacy browser should do this
(DIR) Post #B4LwD1BHkqokh1Gqxs by Jes@labyrinth.zone
0 likes, 0 repeats
@natty @violet @zaire also syncthing exists
(DIR) Post #B4Lxn3acNQWSXfruHw by Jes@labyrinth.zone
0 likes, 0 repeats
@violet I use syncthing to sync my keepass database around. It's encrypted on transport so even though it passes through community nodes if you're away from your other devices it is still syncing away from home (it is optional).There's also the option of using nextcloud, there's both using the web dav service with keepass or the passwords app, though I don't recommend the app.Personally I use floccus for bookmarks with the nextcloud and keepassxc via syncthing.The cool thing about keepassdx is that there's an autofill keyboard so even if the app doesn't support it you can do it manually
(DIR) Post #B4LyrIshZ4IN54uqAa by Jes@labyrinth.zone
0 likes, 0 repeats
@violet the best part about the way I have it setup is that it doesn't matter what browser I use, the sync is the exact same. so like if you have a browser that does 90% of the things, but you need another browser every once in a while, you keep sync with them. and I never ended up using any of the features that sync provides other than passwords and bookmarks so it's everything I need.though one downside to using a third party password manager is that they can cut the speed of your browser by about a third, so if you're on chromium, the extension extensity lets you quickly toggle the extension off, but you can also press alt+F E(on vivaldi it's ctrl+shift+E, and sometimes it's Alt+F L E), or if you're on firefox, you press ctrl+shift+A to bring up the extensions page.