Below is in reply to the exceedingly forward-thinking and nice creator / owner (Marco Barulli) of the online password management web app, Clipperz

I have not used clipperz as much as I had originally foreseen. I do use it as a central location for most new accounts that I create (even stock broker sites), but I have not had time to import in anything else, nor am I sure if I want to. It is an EXCELLENT program for everyday non-technical users, but for the IT professional like myself it is not what I am looking for.

Basically, it is too slow for me for everyday office and home use. It is yet another web program that I would have to keep up in the background constantly, to really use effectively. This kind of program, I cannot just keep running/decrypted because someone could come by and discover all of my passwords or various other bad scenarios.

I just timed a clipperz password look up, and from time of opening the application to getting the password into my copied buffer, it took approximately 1min 10seconds. That is with the applications web pages likely cached in Firefox from having it opened just beforehand. This is wayyy too long for me from a permanent work/home machine that I have pre setup. It is a decent time for a remote, unknown computer (library, friends computer). My prior method of secure-VNC’ing to my home computer, and utilizing a simple always running password storing program on it, took around 20 seconds with everything “in line” (ready, running).

I think that a different method utilizing secure server-side decryption on a trusted server (my own), could reduce this time to shorter, and from ANY computer. Basically, a web page / app that I setup or run on my own home server, access over the internet via a secure channel (https, etc), login, type the first few letters of the account/card that I am looking for, press enter, and receive all of its info. Decryption done instantly on server side, sent much faster, because all that is sent over the secure internet channel is the lean web page with the acct info in it. Of course this type of solution is only for the do-it-yourself crowd, which clipperz knowingly do not serve. A users of the above explained system also has to know their shit, even if just using some prewritten code. I have yet to find or build this code/platform.

A possibly even better solution for permanent machines (work, home), reducing the time even more, would be to integrate existing local password managers (1passwd, roboform, firefox’s built in password storage) with an Internet-saved / secured database. The local password program and remotely stored database / program could synchronize acct/card/password info on a schedule, or when new stuff is added or edited, etc. With this method, as soon as you visit a site, these local password managers log you in with NO EFFORT. Of course this only works on permanent machines, but it could be an option to the above paragraph, or clipperz solution. I would think this method would reduce the wait to seconds, if not faster. Firefox “instantly” suggests account names and passwords for forms filled out and saved. There is 0 wait time. This, for me, would be the ultimate. Of course, ease-of-use often comes with more security concerns.

For now, VNC and clipperz suffice. :-)

 
personal/blog/online_password_management_thoughts.txt · Last modified: 05.10.2007 13:03 by 130.85.181.135
 
Recent changes RSS feed Creative Commons License Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki