tag:help.masterpassword.app,2014-09-03:/help/discussions/suggestions/110-sites-profile-syncingMaster Password: Discussion 2018-09-07T18:52:47Ztag:help.masterpassword.app,2014-09-03:Comment/444278532018-01-03T14:01:56Z2018-01-03T14:01:56Zsites profile syncing<div><p>Apart from being unnecessary, I think your idea is superfluous and defeats the main purpose of this unique system.</p>
<p>Do you fully understand how it works?</p>
<p>Sent from ProtonMail Mobile</p></div>Tuq Sagagotag:help.masterpassword.app,2014-09-03:Comment/444278532018-01-03T15:18:41Z2018-01-03T15:18:42Zsites profile syncing<div><p>I belive I do, but I am not entirely sure you understood my question. Apologies for the bad wording.</p>
<p>What I am saying here is say you have 200 entries, with a mixture of Maximum Security, Long, Medium, PIN password types and want to export the sites configuration, the only way is to actually export the file and import. Unless you remember the password requirements are for every single ones ( characters allowed, max password length, etc... )</p>
<p>Given the secure export file looks like this :</p>
<h1><a name="master-password-site-export" class="anchor" href="#master-password-site-export"></a>Master Password site export</h1>
<h1><a name="export-of-site-names-and-stored-passwords-unless-device-private-encrypted-with-the-master-key-" class="anchor" href="#export-of-site-names-and-stored-passwords-unless-device-private-encrypted-with-the-master-key-"></a>Export of site names and stored passwords (unless device-private) encrypted with the master key.</h1>
<p>##</p>
<h1><a name="user-name-bla-bla" class="anchor" href="#user-name-bla-bla"></a>User Name: bla bla</h1>
<h1><a name="avatar-0" class="anchor" href="#avatar-0"></a>Avatar: 0</h1>
<h1><a name="key-id-blablablabla" class="anchor" href="#key-id-blablablabla"></a>Key ID: blablablabla</h1>
<h1><a name="date-2018-01-03t15-09-10z" class="anchor" href="#date-2018-01-03t15-09-10z"></a>Date: 2018-01-03T15:09:10Z</h1>
<h1><a name="version-22222222222222-5-2" class="anchor" href="#version-22222222222222-5-2"></a>Version: 22222222222222.5.2</h1>
<h1><a name="format-1" class="anchor" href="#format-1"></a>Format: 1</h1>
<h1><a name="passwords-protected" class="anchor" href="#passwords-protected"></a>Passwords: PROTECTED</h1>
<p>## #</p>
<h1><a name="last-times-password-login-site-site" class="anchor" href="#last-times-password-login-site-site"></a>Last Times Password Login Site Site</h1>
<h1><a name="used-used-type-name-name-password" class="anchor" href="#used-used-type-name-name-password"></a>used used type name name password</h1>
<p>2018-01-03T14:55:15Z 0 17:3:1 user1 blue<br>
2018-01-03T14:55:28Z 0 16:3:1 user1 orange</p>
<p>I see little to worry about if this file possibly gets stolen. It's indeed not ideal, as login name together with other fields is used to generate the password ( along with the masterkey ), but I am not sure the burden of having to export and import again whenever you want to add a new site is much more appealing. Unless of course you do it manually on all of your devices.</p></div>gettonstag:help.masterpassword.app,2014-09-03:Comment/444278532018-01-04T13:35:05Z2018-01-04T13:35:05Zsites profile syncing<div><p>Personally, I don't see such a feature as a priority - given the speed and convenience of the current configuration together with the security benefits of it being off-line.</p>
<p>Are the risks of third party cloud integration worth it? It may harm the reputation of mpw's USP which, for me, is its off-line nature.</p>
<p>Have you considered using something like <a href="http://www.noodlesoft.com/hazel.php">Hazel</a> or <a href="https://github.com/benjaminoakes/maid">Maid</a>?</p>
<p>Sent with <a href="https://protonmail.com">ProtonMail</a> Secure Email.</p></div>Tuq Sagagotag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T15:04:02Z2018-04-16T15:04:03Zsites profile syncing<div><p>Hi<br>
I have the same wish&problem. I have some hundred accounts to manage.<br>
Some systems force you to use a certain login name (or your preferred is already taken - ok i can use the name@url notation).<br>
Some „clever“ admins force you to change passwords every 3 months.<br>
And some sites have annoying limits on password lengths or charactersets.<br>
The latter two aspects makes it really impossible to remember for 200 entries.<br>
And how can i transfer a list of 200 to another device? There is an export feature, but i couldn’t find an import function.<br>
If there were an export & import function, i could transfer it while inside a secure network.</p></div>Stefan Bühlmanntag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T15:22:11Z2018-04-16T15:22:11Zsites profile syncing<div><p>It's important to be conscious of the fact that Master Password is not supposed to be an app that keeps track of things for you.</p>
<p>It is supposed to be a calculator. Calculators don't sync things.</p>
<p>As soon as you start using Master Password to keep track of things for you, you're falling into the pit that we're trying to save you from. You become dependent upon state. If the state ever disappears due to loss or corruption, you are in the same bad spot as you would have been with a regular vault-based password manager.</p>
<p>It's my recommendation that you try to simplify instead of trying to keep track of your complexity.</p>
<p>Pick a default password template that best supports your use case. For rotating passwords, use the password counters. If passwords rotate based on chronology, use a counter that encodes the chronology so you don't need to remember the counter value itself. (eg. every year, increment by 10, every quarter of the year, increment by 1)</p></div>Maarten Billemonttag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T15:52:29Z2018-04-16T15:52:33Zsites profile syncing<div><p>Hi Marteen<br>
But why not an import function when you offer an export?</p></div>Stefan Bühlmanntag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T15:58:15Z2018-04-16T15:58:15Zsites profile syncing<div><p>There is an import function. Which app are you referring to?</p></div>Maarten Billemonttag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T16:01:35Z2018-04-16T16:01:35Zsites profile syncing<div><p>On the iPhone App</p>
<p>Viele Grüße, Stefan Bühlmann, +41 76 41 41 824 Gesendet mit ProtonMail</p>
<p>Sent from ProtonMail Mobile</p>
<p>AN Mo., Apr. 16, 2018 bei 17:58, Maarten Billemont <a href="mailto:tender2+dc5980044f@tenderapp.com">tender2+dc5980044f@tenderapp.com</a> Schrieb:</p></div>Stefan Bühlmanntag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T16:02:29Z2018-04-16T16:02:29Zsites profile syncing<div><p>You simply open the export file, hit the share button and select Master Password from the options.</p></div>Maarten Billemonttag:help.masterpassword.app,2014-09-03:Comment/444278532018-04-16T16:09:53Z2018-04-16T16:09:54Zsites profile syncing<div><p>Oh, thx</p>
<p>Viele Grüße, Stefan Bühlmann, +41 76 41 41 824 Gesendet mit ProtonMail</p>
<p>Sent from ProtonMail Mobile</p>
<p>AN Mo., Apr. 16, 2018 bei 18:02, Maarten Billemont <a href="mailto:tender2+dc5980044f@tenderapp.com">tender2+dc5980044f@tenderapp.com</a> Schrieb:</p></div>Stefan Bühlmanntag:help.masterpassword.app,2014-09-03:Comment/444278532018-09-07T18:36:33Z2018-09-07T18:36:35Zsites profile syncing<div><blockquote>
<p>As soon as you start using Master Password to keep track of things for you, you're falling into the pit that we're trying to save you from. You become dependent upon state.</p>
</blockquote>
<p>In a way, you are always dependent on a state. The site you are tying to log in requires not only your password, but user name as well. Here is your state. You can chose to remember it (together with all other metadata to hundreds of sites), or you can save and sync it using one of the numerous cloud solutions (I prefer chrome extension, and just synching chrome extension state).<br>
And yes, sites use ridiculous password rules that users have to dance around by choosing weaker patterns*, and sometimes sites force you to come up with a new password as well. It's a burden for user to carry that a good MPA implementation can help with.</p>
<p>Specifically on default templates: there is a way to solve a situation when site doesn't support specific characters without weakening the template. Consider an option to let user specify what special characters site explicitly rejects, and generate new passwords with the same template (maximum, long) increasing the counter until the requirement is met. Remember that counter in the metadata - and you are good!</p></div>Denistag:help.masterpassword.app,2014-09-03:Comment/444278532018-09-07T18:52:46Z2018-09-07T18:52:46Zsites profile syncing<div><p>Note that you can also generate usernames, so you could avoid having to remember a username.</p>
<p>In terms of allowing custom templates: I'd rather avoid this, since that means you need to reconstruct the rules you used for a site when you generated your password for it when you want to regenerate the password later (ie. the site-specific rules become state). Further, password rules can change.</p>
<p>Ideally, I'd prefer to look into getting one or two templates that are maximally accepted by sites all over the net. Key here will likely be: keep the character set as basic as possible and gain entropy through password length.</p>
<p>— Maarten Billemont (lhunath) — <a href="https://www.lhunath.com">https://www.lhunath.com</a> <a href="https://www.lhunath.com/">https://www.lhunath.com/</a> – <a href="https://masterpassword.app">https://masterpassword.app</a> <a href="https://masterpassword.app/">https://masterpassword.app/</a></p></div>Maarten Billemont