Pass (software)
pass is a password manager inspired by the Unix philosophy. It has a command-line interface, and uses GnuPG for encryption and decryption of stored passwords.[2][3]
Developer(s) | Jason A. Donenfeld |
---|---|
Stable release | 1.7.3[1]
/ 3 August 2018 |
Repository | |
Written in | Bash |
Operating system | FreeBSD, Linux, OpenBSD, OS X |
Available in | English |
Type | Password manager |
License | GPLv2+ |
Website | www |
The passwords are encrypted and stored in separate files, and can be organized via the operating system's filesystem. A password file can contain additional text, such as the username, the email address, comments, or anything the user would like, since the password files are nothing more than encrypted text files.
There are several graphical user interfaces (GUIs) available, such as QtPass for Linux/Windows/MacOS or Password Store for Android operating systems. A syncing system is not implemented, but syncing can be achieved by using the Git version control system. The built in Git functionality also allows for automated version history tracking of the password store.
Vulnerabilities
In June 2018, pass was found to be vulnerable to a variant of the SigSpoof attack.[4][5] The issue was patched the same day that the vulnerability was disclosed.[4]
References
- https://git.zx2c4.com/password-store/tag/?h=1.7.3; retrieved: 21 May 2020.
- Bruce Byfield (January 2014). "Remembrance of Things Pass". Linux Magazine.
- Joe Brockmeier (24 June 2014). "Using pass to Manage Your Passwords on Fedora". Fedora Magazine.
- "Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug".
- "Decades-old PGP bug allowed hackers to spoof just about anyone's signature". 14 June 2018.