Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
remy_
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
remy_
5y ago
No inspiration, only work!
2.
▲
by
remy_
5y ago
Not the same budget.
3.
▲
by
remy_
6y ago
Thanks for the report
4.
▲
by
remy_
6y ago
Yes the repository was forked from CakePHP v2, before the framework was moved as a composer dependency, so v2 contributors are shown as Passbolt contributors.
5.
▲
by
remy_
6y ago
It's the same model than redhat, you buy a subscription, and the software checks if you have a valid subscription. Nothing is stopping you from modifying the source to remove that check, re-build and re-distribute for free (or for a fe
6.
▲
by
remy_
6y ago
Hi passbolt developer here, the reason for building on top of CakePHP was mostly: - it's been audited multiple time (last in date was by Cure53, financed by mozilla foundation) - convention over configuration - good versatility for hos
7.
▲
by
remy_
6y ago
The paid version is also distributed under Open Source license, but is not free (as in free beer).
8.
▲
Latest News About – Covid-19 Cyber Threats
(media.cert.europa.eu)
1 points
by
remy_
6y ago
|
0 comments
9.
▲
Skin-On Interfaces Artificial Skin for Mobile Devices
(marcteyssier.com)
1 points
by
remy_
7y ago
|
0 comments
10.
▲
by
remy_
7y ago
Passbolt team was actually part of the Mailvelope project that did this. Integration setup is not easy / very user friendly, that's why it's not the default on Mailvelope.
11.
▲
by
remy_
8y ago
mariadb / mysql? matomo / piwik.pro? It seems mostly done by the original developers however and not a new 3rd party.
12.
▲
by
remy_
8y ago
That may be true for gitlab, but it's not the case for all the development tools. Like good luck running a selenium grid with 10min of maintenance per month.
13.
▲
by
remy_
8y ago
In practice it's more than "ends-justify-the-means", it's a matter of how much time free software developers have and what they want to spend time on. For every alternative tools to github, CI, test grid, audit tools, et
14.
▲
Passbolt Tags Functionality Design Discussions
(medium.com)
5 points
by
remy_
9y ago
|
0 comments
15.
▲
Passbolt Step by Step Install on CentOS with NGINX, PHP7, MariaDB
(medium.com)
1 points
by
remy_
9y ago
|
0 comments
16.
▲
by
remy_
9y ago
Passbolt, give it a try! https://www.passbolt.com/
17.
▲
Show HN: Passbolt v1.5.0 now with groups support
(passbolt.com)
1 points
by
remy_
9y ago
|
0 comments
18.
▲
Show HN: How passbolt will implement groups
(medium.com)
3 points
by
remy_
10y ago
|
0 comments
19.
▲
Show HN: Passbolt open source password manager chrome extension
(chrome.google.com)
3 points
by
remy_
10y ago
|
0 comments
20.
▲
Passbolt open source password manager available on chrome
(passbolt.com)
3 points
by
remy_
10y ago
|
0 comments
21.
▲
by
remy_
10y ago
Because the binary is served from a marketplace that works with an app that you trust and that will verify the package signature. Or, the web browser does not behave like a package manager.
22.
▲
by
remy_
10y ago
Fair enough, whatever is the easiest for the attacker :). I'm checking Cyph and its "Trust On First Use" concept. Very interesting.
23.
▲
by
remy_
10y ago
Because if you serve the library responsible for the encryption from the server, an attacker can perform a man in the middle attack and change that library. This will change when browsers will start implementing the web crypto api. https:&
24.
▲
by
remy_
10y ago
> - Do you have programmer APIs other than JS? He probably means SOAP, Corba, etc. not just REST/JSON.
25.
▲
by
remy_
10y ago
Thanks for the suggestions. We'll definitely come up with a feature/roadmap page shortly. As for the demo account it is a bit more complicated, but we'll look into it.
26.
▲
by
remy_
10y ago
Fair play! We will propose something with less dependencies and more native support.
27.
▲
by
remy_
10y ago
> Is passbolt able to pull gpg keys of a user from some external source automatically. Not yet, same as key signing and manual keyring management. But hopefully we'll get there. Thanks for the positive feedback!
28.
▲
by
remy_
10y ago
The authentication token follows a very specific pattern to prevent this type of attacks. For example an authentication token would look like this: gpgauthv1.3.0|36|8661be60-23df-11e5-b16c-0002a5d5c51b|gpgauthv1.3.0. Both the server and cli
29.
▲
by
remy_
10y ago
Passwords are not stored in the firefox extension, they are stored encrypted server side. The firefox extension is there make sure the cryptographic library (openpgp.js) cannot be tampered with (via MiM/XSS for example).
30.
▲
Show HN: Passbolt – open-source password manager for teams
(passbolt.com)
62 points
by
remy_
10y ago
|
38 comments
More ›