• kepix@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    ·
    24 minutes ago

    been the number 2 recommendation after shitass proton on alternativeto.net. ui is a bit weird, but works. password generstion def needs more options tho, some sites need more number or more special characters.

  • SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    5
    ·
    3 hours ago

    Looks like an interesting project, but I just don’t understand it’s use case.

    I use Keepass and I just copy the (different) email address I used to register for a site into the username field and I’m done.

    No hosting required, no additional email server, etc. just credentials in a fully portable file.

    Is this trying to automate email based 2FA ?

  • DevoidWisdom@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    45
    ·
    1 day ago

    Per the github page “With the API stabilized, we aim to have AliasVault undergo a thorough security audit this stage. We have already initiated conversations with renowned cyber security companies who have taken interest in taking this on.”

    • filcuk@lemmy.zip
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 hours ago

      I hope it doesn’t say as I didn’t bother to check - how do free projects get money for audits like this?

  • Mugita Sokio@lemmy.today
    link
    fedilink
    English
    arrow-up
    1
    ·
    16 hours ago

    I actually happened to use AliasVault. It’s Free Software from the Netherlands for those who are unaware.

  • SavvyWolf@pawb.social
    link
    fedilink
    English
    arrow-up
    37
    ·
    1 day ago

    One thing that jumps out at me reading the readme is the fact that it has a built in email server. Email is hard to get right, and I’m surprised a relatively young(?) project is working on getting all the moving pieces together rather than declaring it out of scope.

    It’ll be interesting to see how it develops.

    • Coolkat@slrpnk.net
      link
      fedilink
      English
      arrow-up
      5
      ·
      1 day ago

      I’m no expert but as i understood, it’s the sending part that’s tricky to get right. Lots of handshake to handle, all to probably end up in a spam folder or blocked along the way. But receiving from a publicly acknowledged address ? I think it’s fairly simple

      • cron@feddit.org
        link
        fedilink
        English
        arrow-up
        1
        ·
        15 hours ago

        Even then, there are lots of edge cases with e-mail that are easy to get wrong and might become security risks.

        I‘m not saying this applies to this project, this is more of a general concern.

    • zr0@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      1
      ·
      1 day ago

      I would never trust a newly written email server and there is absolutely no reason not to use an already existing as a dependency to this project.

    • prenatal_confusion@feddit.org
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 day ago

      Do You know more about the email server part? I understand +addressing but this seems to be more? Do You hand a domain over and it is actually a full MX or is it just an imap client?

  • AllNewTypeFace@leminal.space
    link
    fedilink
    English
    arrow-up
    43
    ·
    1 day ago

    Has this been audited? It’s easy to claim that something is secure, but there have been products that made such claims and were trivially exploitable.

  • Courant d'air 🍃@jlai.lu
    link
    fedilink
    English
    arrow-up
    16
    ·
    1 day ago

    Looks promising! And it’s refreshing to see something that doesn’t look vibecoded in a week. Couldn’t find any AGENTS.md or other AI crap so I could actually try it

    • kepix@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      35 minutes ago

      we used to use it at work. i hated it, cause it did not recognise any non english european character during search. i wonder what happens if someone with a full cyrillic alphabet starts to use a mess like this.

    • Cethin@lemmy.zip
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 hours ago

      I don’t know why people use these services that charge you. Just use Keepass. It’s free and open source. The only disadvantage is syncthing across devices, but syncthing makes that trivial.

    • OpenAltFinder@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      I recently started migrating away from 1Password. I was on the individual plan for almost 5 years, but this year they would raise the price. I would happily keep paying, but I just find that the quality has just gone downhill. The Firefox extension seems to freeze up quite often, or unlocking doesn’t work, or sometimes it takes 10 seconds +…

      The browser extension was also feeling a bit intrusive. It would often pop up for non-login fields. There’s also no way to disable it for specific sites.

      All in all, I just grew frustrated with it, and decided to switch to Bitwarden. I’m just on the free one, so I am missing quite a bit of functionality.

      • robocall@lemmy.world
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        1 day ago

        Aren’t both of them password managers? I guess I wonder if someone has a preference for one over the other.

        • KairuByte@lemmy.dbzer0.com
          link
          fedilink
          English
          arrow-up
          2
          arrow-down
          1
          ·
          1 day ago

          They are, it’s just odd to bring up an unrelated software.

          I do use 1Password and like it, but I couldn’t compare it to this one.