Our feedback on implementing passbolt

Hi @eddie4,

Thanks for your feedback, it’s really helpful for us to understand where the pain points are. Here are some thoughts bellow.

It’s secure even when the server gets hacked.

This is not exactly correct. If an attacker can modify the user/group data, they can trick somebody into sharing a password. They won’t have access to all passwords in clear right away, but if the attack is sustained for a long period of time potentially they could. We’ll do more to mitigate these type of risk scenario this year (like by introducing signatures to verify users and groups members).

Ability to add people to group while they never created a private key. Notify the group admin to share the passwords when they actually create there key pair.

This is something we want to do and that have been requested by multiple users.

Resend activation mail button

In the v2 we fixed this, you can resend an activation email by going to /recover, you can receive the email even if you didn’t complete the setup.

Compliance would really like it if we could change the requirements for the password strength on the cert.

Could you explain how this would work a little bit more? Like you’d like to see the strength summary of each passwords? You would like to have a minimum password strength based on groups?

Allow a single password to be used in multiple URI’s

This one i’m not understanding, can you explain a bit more?

Ability to share multiple private passwords with group on one action.

This is something we want to do. As a user I want to select multiple records and perform a bulk action these entries

Ability to copy the username/email in the main overview.

This is possible using right click. You mean you want it be one click?

The ability to hide/delete shared passwords from personal view

We were discussing this with @kevin the other day, we’ll update the filters at some point to allow this.