Jump to content

Pass (software)

From Wikipedia, the free encyclopedia

This is an old revision of this page, as edited by 191.8.84.43 (talk) at 22:17, 2 July 2020. The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

pass
Developer(s)Jason A. Donenfeld
Repository
Written inBash
Operating systemFreeBSD, Linux, OpenBSD, OS X
Available inEnglish
TypePassword manager
LicenseGPLv2+
Websitewww.passwordstore.org

pass is a password manager inspired by the Unix philosophy. It has a command-line interface, and uses GnuPG for encryption and decryption of stored passwords.[1][2]

The passwords are encrypted and stored in separate files, and can be organized via the operating system's filesystem. A password file can contain additional text, such as the username, the email address, comments, or anything the user would like, since the password files are nothing more than encrypted text files.

There are several graphical user interfaces (GUIs) available, such as QtPass for Linux/Windows/MacOS or Password Store for Android operating systems. A syncing system is not implemented, but syncing can be achieved by using the Git version control system. The built in Git functionality also allows for automated version history tracking of the password store.

Vulnerabilities

In June 2018, pass was found to be vulnerable to a variant of the SigSpoof attack.[3][4] The issue was patched the same day that the vulnerability was disclosed.[3]

See also

References

  1. ^ Bruce Byfield (January 2014). "Remembrance of Things Pass". Linux Magazine.
  2. ^ Joe Brockmeier (24 June 2014). "Using pass to Manage Your Passwords on Fedora". Fedora Magazine.
  3. ^ a b "Pass gets a fail: Simple Password Store suffers GnuPG spoofing bug".
  4. ^ "Decades-old PGP bug allowed hackers to spoof just about anyone's signature". 14 June 2018.