So, I’ve been using keepassxc for some time now, but I wanted a viable alternative for command line usage (there is keepassxc-cli, that I use, but it is really a pain in the ass). So, I searched and found pass and gopass.

However, I’ve seen that they store each entry in a gpg encrypted file, inside a plain directory hierarchy. And, don’t get me wrong, I believe that there are use cases for this, but if someone got their hands in your password_store, they would know every single login that you have (the only information that is protected is the password, or whatever is in the gpg file).

So, my question is, there is a password manager, cli based, that encrypts the whole database, and not the single entries?

Update: there is a pass extension made specifically to address this issue

  • communism@lemmy.ml
    link
    fedilink
    arrow-up
    1
    arrow-down
    1
    ·
    1 day ago

    Cops confiscate devices all the time without good reason lmao. It’s commonplace to seize devices on a person upon arrest. Judges also grant search warrants upon very little evidence too. Cops absolutely don’t need to “prove” anything to a judge to get a warrant; there is no standard of proof at all; it’s a standard of evidence, which is not the same thing as proof, and a low standard of evidence at that.