mastodon.world is one of the many independent Mastodon servers you can use to participate in the fediverse.
Generic Mastodon server for anyone to use.

Server stats:

8.2K
active users

#PasswordManager

5 posts5 participants1 post today

Guess what cybersecurity expert Alexandre Blanc appreciates most about passbolt?
It's all about owning your stack! Alexandre loves open source solutions, advocating for data ownership and transparency for decades. Being a Linux enthusiast and security advocate, he's keen on maintaining full control through self-hosting.

Check out his insights in this post: linkedin.com/posts/alexandre-b

www.linkedin.comGuess what I really like in this picture for a password manager like Passbolt ? | Alexandre BLANC Cyber SecurityGuess what I really like in this picture for a password manager like Passbolt ? It has to do with the fact that I love to own my things ! 😁 It has to do that I'm an open source guys for decades, a Linux guy and a security person. 🐧 I'm sure you got it ! "Keep full data ownership" ! Self-host, OWN YOUR STACK ! 🎯 When passbolt came to me asking for a brand partnership, I was really excited, because what they do, is so well aligned with what I advocate for ! #privacy, #cybersecurity or #security, #confidentiality, accountability and transparency. More about it here https://lnkd.in/etbfHY-X I've been told by an insider that a version 5.3 is soon to be released, and it brings bunch of enhancement. Not changes that jeopardize your skills, just enhancements, which is great !

Passbolt 5 series introduced encrypted metadata, the foundation on which the new resource types and capabilities like multiple URIs, custom icons, custom fields, etc. are built.

Ready to test-drive the beta? The latest blog post walks through enabling the feature set, migrating safely and more: hubs.li/Q03xCMwG0

PassboltThe road to Passbolt version 5 - Getting started with the new resource types (beta)Learn how to enable encrypted metadata in Passbolt v5 to benefit from advanced resource types and improved security.

Passbolt 5.3 is now available, introducing custom fields that allow users to attach additional key–value pairs to a password entry or even create standalone entries. This release also includes performance enhancements and bug fixes.

Check out the details in this blog post and see what's coming in the next releases: hubs.li/Q03xr0MR0

PassboltPassbolt 5.3 Introduces Custom Fields and Performance ImprovementsPassbolt 5.3 introduces custom fields, allowing structured key-value data alongside credentials and includes performance enhancements.

📄 Passbolt docs now cover clear admin guidance on resource metadata encryption. This section includes how to generate a shared key, enabling encrypted and legacy formats, and migrating existing resources. The section is a work in progress and will expand as the feature matures.

Read the admin steps here → passbolt.com/docs/admin/metada

www.passbolt.comMetadata Encryption | Passbolt documentation.

Does pass by Jason A. Donenfeld of zx2c4 and wireguard fame support passkeys or have an extension that supports passkeys? And does anyone have experience using a non-internet addressable private git server (local host served from a desktop) to sync to a pass mobile phone client?

I am thinking passkeys are a dead end but the I definitely need a copy of the passwords on my phone.

www.passwordstore.orgPass: The Standard Unix Password ManagerPass is the standard unix password manager, a lightweight password manager that uses GPG and Git for Linux, BSD, and Mac OS X.
Continued thread

(Linux news in previous posts of thread)

FOSS NEWS

Mozilla VPN Linux app is now available on Flathub:
omgubuntu.co.uk/2025/07/mozill

Bluesky introduces improved notification management:
alternativeto.net/news/2025/7/

OBS Studio 31.1 released with multitrack video support on Linux and macOS, preview zoom controls, support for additional canvases for Multitrack Video output, AV1 B-frame support for AMF, support for color format/space/range GPU conversion, new UI settings, etc.:
9to5linux.com/obs-studio-31-1-

LibreOffice Writer Markdown import support is merged, will be available in LibreOffice 26.2 next year:
phoronix.com/news/LibreOffice-
(That will be really useful for me when creating downloadable versions of programming cheatsheets for FosseryWeb, because I can just export the Markdown from Joplin, import it to Writer.)

Geany 2.1 released with improved UI and file type support:
9to5linux.com/geany-2-1-open-s

KeePass 2.59 released with native Windows 11 support, faster encryption, enhanced security, improved database portability, browser integration:
alternativeto.net/news/2025/7/

Ardour drops GTK+ support in favor of its fork, YTK:
phoronix.com/news/Ardour-Remov

Calibre 8.6 released with improved database restore performance, support for the La Presse news source, 'Search "not in"' and 'Filter "not in"' buttons for the Manage Authors and Manage Items options, etc.:
9to5linux.com/calibre-8-6-open

OMG! Ubuntu · Mozilla VPN Linux App is Now Available on FlathubThe Mozilla VPN Client can now be installed on Linux distributions from Flathub, a change that will allow more users to access the paid VPN service.

Well, great. Now @bitwarden is going to ad AI bullshit to their services. I left Bitwarden a few months back for different reasons but I'm kind of glad that I did. I switched to @1password@1password.social. If they add AI to their services (are they already?), I'm just going to call it quits on all of them and just move completely to @keepassxc@fosstodon.org. I can simply just host my own with Keepassxc and not have to worry about any AI crap. I'm using Keepassxc now but not for everything. That might change in the very near future.

https://nerds.xyz/2025/07/bitwarden-mcp-server-secure-ai/

#passwordmanager #privacy #security

Bitwarden launches MCP server to securely connect AI agents with your passwords
NERDS.xyz · Bitwarden MCP server secures AI access to your passwordsBitwarden releases local first MCP server so AI agents can securely manage passwords without compromising encryption

Researchers in the article “ShieldFlow: A Security Framework for OT Systems” (International Journal of Information Security, Springer 2025) highlight passbolt’s role in helping industries securely manage credentials, demonstrating the relevance of open source tools in operational technology (p. 18).

Check out the book here: link.springer.com/article/10.1

SpringerLinkShieldFlow: a novel framework for OT cybersecurity in the context of industry 4.0 - International Journal of Information SecurityThe increase in cyber-attacks impacts the performance of organizations in the industrial sector by exploiting vulnerabilities in interconnected machines and systems. These attacks result in operational disruptions, compromised safety, and financial losses, affecting industrial operations' overall efficiency and security. This article presents a framework for integrating OT (Operational Technology) cybersecurity into organizational strategy. The framework includes a dynamic risk assessment methodology and guidance on incorporating governance into this process. The proposed framework treats OT cybersecurity as a vital element that supports and enhances enterprise security rather than an isolated issue. The methodology is based on four pillars—People, Process, Technology, and Suppliers—each contributing to a balanced and resilient OT environment. A robust governance approach supports this framework, ensuring coordination among departments and aligning security efforts with business objectives. This comprehensive framework allows companies to manage security risks effectively, adopt collaborative practices, and support digital transformation initiatives, including Industry 4.0. This Framework strengthens OT security and improves the organization's ability to adapt and succeed in a connected digital landscape.

Apparently it is utterly impossible to program an app to automatically fill in a password based on subdomain or port.

example.com vs site1.example.com vs example.com:9993

Would love a password manager that recognize those as having different logins. People have been asking for this from 1Password since at least 2013, and their reply is basically, you don’t really want that. Apple Passwords, same issue.

Anyone know of an app that can do this on macOS?

Is there a term for the class of "credential storage confusion" #security issues, where the user accidentally saves a password or passkey in a vault they don't actively use (browser, #SSO IdP, #passwordManager, OS)?

One thing that made me think of this is having to go through a separate step (like "use a different device") on Android to avoid enrolling the phone as passkey.

I can see how users spread active credentials across multiple services which seems like a massive #infosec issue to me...