Techlore Talks brings you in-depth conversations with the experts at the forefront of privacy, security, and digital rights. Hosted by Henry Fisher, founder of Techlore and long-time digital rights educator, each episode features meaningful discussions with the people building, researching, and advocating for digital freedom.
From cybersecurity researchers and privacy tool developers to open-source advocates and digital rights activists—if they're shaping how we protect ourselves online, they're on this show.
Topics include: privacy tools and technologies, cybersecurity threats and defenses, open-source software, surveillance and digital rights, encryption, tech policy, and digital sovereignty.
New episodes released regularly. Subscribe and join the community at techlore.tech.
Your password for your computer, you just have to remember.
But your password for your bank, if it's something you can remember, probably isn't good enough.
If you've been hanging around the digital rights space long enough, you probably have heard about password managers and that they are a commonly suggested tool to keep you safer online.
But which one should you use? Why does the underlying format matter? And how does it impact your safety?
Today, I'm sitting down with Alex, the VP of Engineering at Strongbox, which is one of my favorite KeePass clients out there,
to dig into what makes KeePass-based password management different, how Strongbox thinks about the tension between security and convenience.
We talk about also the acquisition of Strongbox and what that looks like.
Whether you're already a KeePass nerd or just trying to make a smarter choice about where your credentials live, this one's worth your time.
Let's get into it.
I'm Alex, the VP of Engineering over at Applause, who look after Strongbox.
And if you're anything to do with Strongbox or you've been in our community, you'll probably
seen Alex at Strongbox signing off most public facing things.
I tend to look after the design of things, not just technically, but also the actual way
it looks and feels.
So all things Strongbox generally go via me.
So I look after that.
But also beyond that, I'm a massive fitness guy.
I'm constantly trying to cram in runs and rowing whenever I can.
And then I have a lot of my own apps.
I make an app where you can just make your coffee experience better.
So you can have like the absolute best coffee experience at home and a couple of others.
And I speak at conferences too sometimes about usually things that aren't super technical.
There's the odd technical thing about, you know, I spoke about foundational models last year.
But I also prefer to talk about things like how can you actually get started doing iOS stuff?
the name of the talk was something I probably shouldn't say without a sensor button but
the whole concept was you know you can just build things and I did that before AI so I feel like I
should probably do that one again now and try and say you can really build whatever you want now
so I built a whole bunch of stuff and you know my main thing is just I really love making things
for Apple platforms there's a little bit of Android here and there but generally all I want
to do is make the best possible thing for Apple devices, whether that's a Vision Pro or a Mac.
Yeah, it's funny. I've been recently getting more into coffee.
And my starting point entryway has been the AeroPress. And so I've been doing some very,
as more the advanced side of things of trying to do espresso, I know it's not really real espresso
because it doesn't get anywhere near nine bars of pressure, but it's been something I've been
doing a lot of things with, and it's been fun. And now I'm getting into more of the Espresso
machines. Now, to get more into the password management side of things, which is why we're
really here, I want to start by just kind of, you know, for somebody who has never heard of
KeePass, which is kind of what enables Strongbox to exist. And I'm sure you're going to touch on
that. What is a password manager to start off with? Why do you recommend it? Do you recommend
it to everybody? And what are kind of the nuances and how you view password managers as a whole
before we dive into your approach? Yeah. So I think the one-liner or probably a few more than
that on what a password manager is, it's just the place where you store the important things that let
you into other important things. So your password for your computer is something that you kind of
just have to remember. But your password for your bank, if it's something you can remember,
probably isn't good enough. So you probably want to keep that somewhere safe.
And apps like Strongbox, OnePassword, there's dozens of these things.
They help you do that.
They make sure that your passwords are not only kept safe and you won't forget them,
but that they're also good enough so that you don't have to worry about someone breaking in really quickly.
There's plenty of password managers that will tell you don't use the same password across every different app that you have.
But then you can go further and simple things like, you know, don't put your name in the password
or don't make sure it's super short.
Just put the work in to keep things safe
because it's pretty common now to see a password get leaked
or even just a whole company have a massive data breach.
So it's more important than ever
that you actually look after your passwords.
It's happened to me multiple times in the past month
where it's been some random old account I forgot about.
And if I didn't have a password manager
with unique passwords for everything
that I can effectively not have to remember,
I'd be in a lot of trouble and changing a lot of passwords.
So it's a very useful tool that keeps you safe.
And also nowadays probably saves you a lot more time
than you'd think with changing passwords all the time.
Yeah, and then I think maybe the three ways
that people maybe see password management right now,
we have kind of a browser-based password manager,
which is maybe one of the most common,
if not the most common way for still a lot of people to do it.
So maybe we can speak to that.
Also, maybe a more typical password manager, not to single anyone out, but something like LastPass, Dashlane, 1Password, etc.
And then Strongbox.
How do those three kind of all compare?
Because they all take pretty fundamental approaches that are quite different from one another.
Yeah, so I think the main thing people think about with a password manager is the surface they use to interact with it.
So for me, generally, I'm auto-filling in Safari all day, every day.
That's where I see it.
It's very, very rare. I actually have to open my password manager.
But I know for a lot of other people, that's absolutely not true.
Their general way of working is that they open the password manager, grab the password of a two-factor code and copy and paste it in.
And that's the way they prefer to do things.
And most apps now, at least I guess the ones that most people can name, have covered all those surfaces.
So they've gone out of their way to make sure there's browser extensions for Safari, Chrome, whatever it is.
and then there's actual password managers that you can run on your phone or your Mac and everything
syncs up really nicely. There's another branch of password managers which is a little bit more
locked down in a way which is your browser generally will have one built in. For people on
the Apple ecosystem if you're someone like me who refuses to use anything but Safari then you'll
probably be using the same password manager that's also built into macOS and your phone and everything
and it will feel really easy and intuitive.
Whenever people use Chrome, Firefox,
or any number of forks that kind of appear these days,
they also have their own built-in thing.
A lot of people don't actually realize
they're using the one built into Chrome.
They just see, you know, last used password,
click it, and it goes in
without realizing Chrome has a password manager built in.
So there's our kind of branch of password manager,
which is you own an app, you have all your passwords in it,
and you can see them in multiple places.
And then there are the other branches,
like the ones built into Chrome and other browsers.
And Strongbox is one of the ones that lives on your Mac or your phone
or Vision Pro, if you fancy it.
And you can still get to those passwords through Safari, Chrome, Firefox.
The reason I like that approach,
and why I generally recommend people pick a password manager like that,
is it's something you can move all over the place.
You're not locked down to a given browser.
so if you're someone who uses the Chrome password manager a lot that's great but if you're using that
and then you switch to an iPhone that experience gets really clunky really quickly whereas something
like 1Password or Strongbox you just download the app and you're good to go you can get all your
passwords everywhere. I'm a firm believer that your password shouldn't be tied to one thing that you
use which is kind of where the key pass format comes in for us. If you use Strongbox your best
experience, I believe, on Apple platforms is to stick with Strongbox and have your database in
there. But say if you ditch Apple and you say, I want that pixel fold, I'm going to go grab myself
a new Snapdragon laptop, then you can also move that database somewhere else. You can use a
different KeePass compatible app, which means you're not stuck anywhere. And your passwords are,
you know, they're your passwords. You own them. They live in a vault that is yours. And you're
not stuck with clunky export processes or anything. You just open the vault somewhere else and you're
good to go. I guess to kind of summarize a little bit of what you said there, the KeePass format is
open source. It's meant to give you ownership of your passwords via a KDBX file format, kind of like
a.zip on your computer, a.whatever. It's just a file. You can take it wherever. And then Strongbox
would be the client in this case for Apple devices. Let's start with syncing. Contact Strongbox
to this day is my favorite password manager.
You guys hands down have the best UX UI
that I've used for any password manager,
especially on Apple devices.
But I'm not using you anymore
because I moved away from KeePass.
So I still have that respect for you all,
but I'm using ProtonPass recently
just because I prefer the way that
it just instantly syncs across all my devices.
So can you speak to what syncing looks like
and how you guys handle sync
compared to what a traditional password manager might do,
which is quite a bit different?
Yeah, so sort of the key advantage of the key pass format can also be a bit of a drawback in a way,
especially when it comes to syncing.
With something like 1Password or ProtonPass, the way they work is,
this is a best guess, but I built a lot of stuff, so I think I'm kind of on the right track.
You have an account with them and they store your passwords in the cloud.
So you're a user and you add in a password for apple.com
and they have a record of your password for apple.com.
If you change that password, if you edit the two factor, if you delete it, whatever you do,
all they have to do is sync that one single password up and down.
There's probably a local copy somewhere just to make sure it feels fast,
but generally everything lives up here in the cloud and they just sync one thing at a time.
Whereas something like Strongbox or other KeePass clients, generally the format is one file.
And if you change one password, then we sync the file.
You can do some clever stuff to make that a bit faster, but the difference is we have to sync the database.
So the way we handle that in Strongbox to try and make it as easy as possible is we built our own system that uses iCloud in the background.
And we handle all of that for you.
And we get an experience in the end that is as close as we can get to the services where everything lives in the cloud.
because we just handle the push and pull for you when you make a change or an edit or a delete or
whatever you do. So it gets as close as we can to that. But it's one of the differences with,
you know, a fully cloud-based option and something like this. Whilst we can let you export your
entire database in one go or let you store it wherever you want with the other ones,
they might have slightly faster syncing, but, you know, exporting a key pass file afterwards might be
a bit of a pain. So there's definitely upsides and downsides to both. I quite like having an open
format, but we think we've got pretty close on syncing to the other ones. And I'm sure there's
a little bit more we can do, but Strongbox Sync is super reliable and we're super proud of it.
Yeah. So I guess just to clarify what you're saying, because for those who aren't in the
Apple ecosystem, Apple has its iCloud behind the scenes, which I think is something very underrated.
Regardless if you're using advanced data protection, you're using end-to-end encryption.
On any other ecosystem out there, I think Apple deserves more praise for this.
If you're a developer, you have to spin up your own infrastructure.
You have to have a server to handle syncing.
There's no back end that you can easily hook into
unless you build in third-party integrations through Google Drive
or something like this.
But with Apple, there's this world and ecosystem of applications
that are completely serverless.
We have really top-tier apps like Flighty that don't have a server.
Really, they don't hold your data.
It's just synced through iCloud.
And so it's this really nice funnel to get away from maybe,
it's kind of like a lot of things I guess Apple does
of raises the baseline, but it's never maybe going to be the best thing ever. Like it's not going to
be better than like an end to end encrypted proton drive maybe from like a privacy security angle,
but it's nice. So that's a bit of a side tangent. Where I'm headed with this is...
No, I was just going to quickly say, I actually think it's not necessarily a side thing. It's
actually quite important that the way we use it and the way basically every app uses it means we
We can't see your stuff. We can see how many records are in our like global database, but we can't see anything about them.
We can't like download the file. We don't have access to that. That's still your private database.
So even though iCloud is linked to you and using your usage, we can't do anything with it.
It's all yours and you're locked in. Whereas with another cloud solution.
I assume you guys are serverless when it comes to user data.
Yeah, we have one tiny serverless function, which is open source, which we use to send requests to the have I been pwned API.
Otherwise, nothing is on a back end tied to us whatsoever.
It's all just straight through iCloud.
Yeah.
So can you expand on syncing?
So this actually gets to the core of why I eventually stopped using Strunkbox.
And it's nothing that you guys are doing wrong.
It's actually the standard you set for key pass clients is higher than any other key pass client.
And I'm not only in the Apple ecosystem.
I'm using Android devices, I do review devices,
sometimes I'm on Linux.
And so for me, what I started to find was,
okay, I love Strongbox when I'm on an Apple device.
It's actually my favorite password manager.
But then I move over to something else
and I have to deal with a really crappy KeyPass client
that doesn't work well.
Is that a gap that you guys are trying to close?
And also, there is still syncing that you can do.
So do you mind speaking about syncing away
from an Apple ecosystem with Strongbox?
And also, how do people juggle with that inconsistency between keypass clients?
So there's kind of two parts to it.
The first thing is syncing when we do it on Apple is we have our own custom system to sync to iCloud.
And we do that because the old way of doing it was you would just store your keypass file in iCloud Drive.
And if you've ever used iCloud Drive and tried to sync stuff between devices and wanted that kind of instant update,
you very quickly realize that doesn't always happen.
There's a lot more going on there.
It's not like, you know, I save a file
and it's instantly available on another computer.
There's like more of a delay than you'd like.
Or sometimes my battery's low
and it doesn't sync properly and things like that.
So we built our own wrapper to use iCloud
and CloudKit directly so that we don't have to
handle those issues.
We fix them all for people.
So it's seamless.
Now we've recreated that same experience
for Dropbox and Google Drive.
And there's other third-party options, like you can use WebDAV if you have your own server somewhere.
And a lot of cloud places are WebDAV compatible.
So you can use other solutions.
And we've made that as seamless as we can with other places.
The sort of downside is we can do all the work we want to make sure that Strongbox always keeps up to date, pushes and pulls the latest version as fast as possible.
But we're also then dependent on third-party people.
You know, if we ask, say, Dropbox to sync, we're not as in control on making sure that actually happens as we expect.
So we've tested it a heck of a lot.
We know it works really well, but there's an extra party involved there.
And we don't see any issues with iCloud sync.
But every now and again, there'll be someone who says that the Dropbox is a little slow or something.
And the sort of the next part in that pipeline where things can change is we have, whilst KeePass is a common open format,
it defines how you open a database and how stuff looks inside it.
It's not really a standard for how the app has to be.
Once you've opened that file, you can kind of just do what you want and still be, you know, KeePass compatible.
So people write in, I'd say I'm up to like a dozen times a day asking if I'm going to do Android or Windows
because they say like they love it.
They have cross-platform sync working and they think it's great.
But then the experience falls apart when they use another app that, say, doesn't save the
databases frequently.
So the database gets out of sync or it doesn't handle syncing conflicts, which, you know,
in the real world, syncing conflicts are going to happen.
One of your databases will be offline for a bit.
You might be on a train or something.
It just happens.
So that's where things can sometimes fall apart a bit.
And it's something that we want to improve.
The challenge there is trying to make sure we give people the best possible experience on our side
and try to work around issues with other password managers that we might be able to see coming.
So if we find out there's a bug in a really popular Android client,
we can try and work around that and build some UX for, you know, maybe we need to improve syncing
or just give people a warning that it was last updated and it doesn't look like anything changed.
There's a couple of things we can do to improve that.
But the end game thing would be to run on Windows and Android.
But it's a really big task.
One I'd love to do, but it's...
Strongbox was a labor of love for many years.
A Windows and Android client would be exactly the same.
Especially because it's a native app.
So you'd probably have to build other native apps for every other platform and then maintain those.
I assume you couldn't move over to a framework.
I think that's the main thing that stops it being something where I can just say,
yeah, we'll kick this off next week is because we're fully native,
which is part of why Strongbox feels so great on your phone and on your Mac.
We stay true to how Apple does things.
We use their components as much as we can.
Some things we have to do custom,
but we try and make sure it feels at home on your device.
And that then means not too much is reusable
if we port it over to a different platform.
We have a little bit here and there,
and the format itself is transformable,
But all the things we have around it that make Strongbox feel great is something that would have to be fully redone for another app.
And I think getting to the level of craft we want with a cross-platform tool would be quite a challenge.
So, yeah, definitely the old school way, I think.
And also never say never.
It's something that comes up a lot.
And I'm noticing it's starting to ramp up a lot since recent changes to other password managers.
So I'm sure that space will improve.
I'd like to hope we might be the ones who kind of push it forward a little bit or, you know, even people see what we've done on iOS and take that as a direction to be like, OK, this is the standard.
We have to at least be this.
But I'm hopeful something springs up, whether it's us or someone else.
I want the ecosystem to thrive as best as possible.
And a Windows Android client that looks great and feels great is kind of the next step, I think.
Yeah, I agree.
And, you know, I'm a big fan of KeePassXC.
Like, they're on our resources.
So it's not to say I don't appreciate these projects,
but I do think just the UI, UX between the different services
is just different.
I think some people that are listening to this
might actually prefer KeePassXC.
But the fact that there aren't options to pick
a Strongbox-esque UI, even if it's not from you guys,
I think that's what needs to happen,
is filling in those gaps to those different styles of users.
A couple of more technical things on the syncing,
and then I have more technical questions
that are not syncing-related.
I assume because you allow any kind of third-party cloud provider,
you could sync like Nextcloud so you can use Strongbox and then use it with Nextcloud with
any other keypass? Yep, Nextcloud is super common. It's one of the things I get asked about quite
often. It seems like people are using it for syncing cross-platform, especially when they don't want to
offload to other services. You know, a really common thing that comes up recently is people,
they love Google Drive and Dropbox, but they're trying to move away from those providers. So they
then ask, you know, how can I use like WebDAB, SFTP, and so on. And Nextcloud seems to be sort of
the most popular option right now.
Shortly followed by people requesting
that we support ProtonDrive,
which we are looking at right now,
which I think will be super cool.
Wow, that'd be really awesome.
And then another question,
you guys released a phone,
like this was on the tail end
of when I was still using Strongbox,
you guys released a Wi-Fi sync feature.
Do you mind expanding on why and how that works?
So I think Wi-Fi sync is the sort of useful solution
for people who want to keep things in sync
between their Mac and their iPhone and their iPad
but they don't really want any of this stuff to live on the cloud.
So the way Wi-Fi sync works is you pick a host device,
which is usually your Mac that stays on,
and then everything else pushes and pulls to that central computer.
So it gives you a cloud-feeling experience
without having to put anything on the cloud.
So if you're worried about that, you don't have to think about it.
You just have it all locally, and then it's completely up to you what you do.
Very nice.
Is there a way to somehow integrate a NAS into this workflow at any point?
So usually the way people use NAS is they just set up WebDAB or SFTP.
So part of the reason we have those is most NASs will support that.
So you can just hook that up and point it to the file and go from there.
I help a lot of people who grab some random NAS from Amazon get up and running.
And it can be quite a cool way to do it where you don't have to rely on having a Mac or an iPad or something that's on all the time.
you can still have that really nice sync experience at home.
Very nice.
This is a more technical question,
and I'm actually still not clear on the details here.
So Apple released Advanced Data Protection ADP.
It's opt-in and encryption in the iCloud ecosystem
for everything except calendar, email, and contacts.
But apparently there's this nuance
that third-party developers have to actually opt into
somehow using ADP for users who have it enabled.
So theoretically, even if you have ADP enabled
iCloud account. It doesn't mean that every app developer who's publishing data to iCloud Drive
is going to be utilizing ADP. A, I don't know if you know anything about this, if it's true,
and then how you guys handle that. So there is some nuance to it, especially more so because
it's not a feature that necessarily came on and then stayed on. Some countries said no to it,
and then some apps supported it. I think I would quite like end-to-end encryption in my iCloud,
but I'm not allowed it, sadly.
So we do have file protection enabled locally.
And my understanding is that we don't have to do anything different on the cloud to enable that.
But I'm sure there is some nuance with this.
The part that might be a bit different with apps you've looked at is we're using CloudKit for everything,
for Strongbox Sync anyway.
So it might not have the same, I guess, nuance to it.
it's probably okay.
I see.
And either way, I think the database file itself is encrypted.
So this is more of a very nitpicky nuance
that I was just curious about.
It's definitely, you know, it's a question people,
people come to us with these things quite often.
Like I think it's important to check.
Yeah.
Now I want to get a little bit more technical now
in this section on features itself inside of Strongbox.
So moving away from the syncing.
You mentioned people are moving away
from other password managers,
or even you have requests for Nextcloud, ProtonDrive.
So I want to ask, what's kind of the target demographic that you see?
I know it's probably more than one person,
but do you have a general list of people that you feel like are drawn to what you're doing?
I think we're trying to change that at the moment.
So Strongbox is super well known within the KeePass community
and people who even just know what KeePass is.
And that's kind of been our user base.
We get a lot of people who come to us from the app store
who just search password manager and find us and they don't know what KeePass is and they're just
like this looks great I'll give it a go but I'd say our primary audience generally has been just
people who care about KeePass or they just want a great password manager. Now the thing that I'm
trying to kind of change right now is how do I get the experience to be fantastic for people who don't
care about keypests. And that doesn't mean I don't care about keypests, but I mean that some people
probably don't want to see vault file names and where it's stored. There's a good amount of people
who just open an app like this and they want to just start putting passwords in, which is the
experience you get with cloud-based password managers a lot of the time. You make an account,
you download some sort of secret PDF to break you back in if you need to, and then you just get going.
and there's not really any complexity to it.
So I'm trying to broaden our horizons
and get more people involved in Strongbox
by improving that experience of people who want it,
which kind of gets me to the audience
or just anyone in the Apple ecosystem
who wants a good password manager,
which sounds crazy broad, but that's the ambition,
is we think we are up there
with the best password managers in the Apple space.
And I just want more people to find us
and have a great experience when they get here,
even if you're not technical.
Yeah, again, I'm biased,
but I really meant what I said earlier.
Of all the password managers I've used,
it's my favorite UI UX experience.
Everything, it was just really well designed.
Very simple, but you can still find
all the complexity and advanced features.
The only thing I didn't like, actually,
also, now thinking about it,
which is an important thing, Autofill.
So on iOS, Autofill is just phenomenal.
Something else Apple doesn't get enough credit for,
because on Android, Autofill is just a complete mess.
To get a password manager going on Android,
you have to give three really critical permissions
like accessibility that lets the password manager do literally anything on your phone.
On iOS, it's all the same access that Apple has.
It's one of the rare scenarios where Apple chose not to use their crazy ecosystem leverage.
And so you're going to work through the same ecosystem that Apple uses for their own password
manager keychain, and I guess now passwords.
But on macOS, it's a little bit different, especially if you're not using Safari.
I struggled a little bit using Strongbox with something like Brave, Firefox, etc.
So do you mind speaking a little bit to Autofill, how you guys handle this, and how this looks
like on third-party browsers?
There's some notice in the settings about like bug Apple to allow this in third party browsers or something.
But I don't remember if I'm remembering that right.
If we did have a warning, it's definitely not in there now.
Now we have a Chrome extension.
But to give a bit of context, I guess the thing that makes Autofill so great on iPhone and Mac is they both use the same system where we can just tell Apple locally.
hey we have a password for this website. So you go to apple.com and that little box comes up and
this is the reason you see if you have multiple password managers installed or the Apple one set
up you'll see a bunch of stuff in there and it's not just Apple's password manager. Any app that
can write to this can say hey I have a password for this. Now that is really great if you stick to
Apple. The downside is that's not something Chrome gets exposed to. I'm honestly not super sure whose
fault that is because I'm pretty sure if certain browsers tagged fields a certain way it would
actually work but I don't think they want to do that. But there's a way around it which is to build
your own equivalent to what Apple has. So Apple's system where we tell it hey we have a password for
this. We can do the same thing ourselves. There's a lot more work involved but that's why we are
usable on Chrome, Firefox and so on is that we built our own version of that system and a custom
extension. There's a little bit more nuance to how it works in that Safari's is very light touch. We
don't say anything like present a little pop-up on this text field. What we do in Safari is just
tell it we have passwords whereas in Chrome it's a little bit more complex we have to check is there
a password field on the page where is it do we have a password for this domain and it's a bit more
of us proactively doing something than the system just taking over so a little bit more complicated
and also then results in interesting things like certain websites might decide to tweak their UI
and potentially break autofill for like every password manager which I've seen reasonably often
where I've been told that a website doesn't work.
And then I check a bunch of different providers
and realize that a website has broken it for everyone.
And then I'll open it in Safari
and it'll work perfectly fine.
So it's a little bit more complex
and all very, very custom,
but it's a part of the experience
that we're right now trying to improve quite dramatically.
So our Chrome extension works pretty well,
but I think it can also look a lot better
and more importantly, feel a lot better.
I think it can be way slicker. And at the same time as that, we can also make it a little bit
more reliable on websites that do things a bit differently. So places where the password field
doesn't get exposed as a password field, we can work around that. A good example would be there's
a couple of login forms on Reddit where the password field doesn't show up as a password
field. It's just not tagged correctly at all. And some very strange things happen all across the web
with how people embed signup forms
or whatever crazy tech they're using.
And we can work around all of that.
And it's something that we're working on now
because we're quite aware that the Chrome extension is good,
but it's a part where the experience can fall down.
If that's your only touch point of Strongbox,
it's not quite as good as the rest of the app.
So definitely some work to do there, I think.
But it is something we're aware of.
Got it.
So I'm going to ask,
because I know a lot of people listening probably are not.
Safari exclusive, nor like Chrome. So when you say Chrome, I assume it'll work in Brave and other
Chromium based browsers. And then also what about Firefox based browsers? Yeah. So for Chrome and
Firefox based browsers, we will work in most of them. We do have to add periodically support for
a new one. It's just a really simple thing on our side where we put a file in a certain spot so that
the browser knows that Strongbox is open because we don't just want any arbitrary thing to be able
to start talking to Strongbox.
So we effectively have an approved list, if you will.
So we have to add to that sometimes.
I think the most recent one I added,
which should be going live pretty soon,
is Zen, which has become crazy popular recently.
But other than that,
as long as the browser is compatible
with Chromium and its extensions
or Firefox and its extensions,
then it should be good to go.
And the experience should be
just about identical across the board.
Very nice.
Yeah, I'm a big fan of Zen browser.
It's a good browser.
If somebody's wondering, maybe someone has a higher security posture
and they just care a little bit more about this,
does using the extension open them up to any other threats?
Is it safer to only use the desktop client and manually copy and paste?
Or do you think that something like the autofill
is actually good phishing protection in the extension?
How do you view this nuance between using the tools?
Yeah, so generally we think the extension is just as secure as the app.
However, the main difference is you're adding an extra touchpoint with an ecosystem that changes wildly every day.
And not too long ago, there was a reasonably serious exploit that affected almost every password manager that has an extension.
And that was something that would only affect you if you use a browser extension.
Because of how Strongbox locks and unlocks your database, it didn't actually affect us.
But for any password manager that just left your database open, that was a problem.
And it could take passwords away.
We added a fix in to make sure we protected against that anyway.
But browsers are a bit of a wild west.
And so is the web.
There's always more coming out.
And it's a very popular attack vector.
If you get into someone's password manager, then you have everything.
You have the keys to the kingdom.
So it's always something to think about.
And the ultimate security would be don't use any kind of extension whatsoever.
But the actual answer that I'd normally tell people is you can just make your database in Strongbox.
I'm sure you can do this in other password managers.
Only unlock for like 10 seconds.
So if you open your browser and you want to autofill something, you unlock your database with touch ID or a password or whatever you choose.
You autofill that one password and then the database locks again.
which means it's a little slower to use.
It's not quite as graceful,
but it means that the database remains locked the entire time,
which keeps things just as secure
as if you were using it inside the app,
which is probably the main lesson in general
with any extension, whoever provides it,
is try and keep your database locked as often as possible
rather than just leaving it unlocked.
Got it. Yeah, thank you.
And earlier you mentioned Have I Been Pwned.
It's a great database.
You can see if you're caught in data breaches,
so you guys integrate with that.
And that's the only server connection?
Is there any telemetry or anything else in the app that people should be aware of?
So the app has two external providers.
So we use RevenueCat to process purchases, which is in substantial amount of the apps in the App Store, if not most at this point, I'd imagine.
And then the paywalls we have in the app are powered by Superwall.
Both of those are effectively in the most limited state they possibly can be.
So to give you a bit more information on that, we don't have any identifiers that we track.
So if you wrote me an email and you said, why is my subscription not working?
I couldn't go into anywhere and find you.
I have no way to know who you are.
All I know on tools like RevenueCat is I know what our revenue is and it updates effectively in real time.
And it lets me do things like I can change offers remotely.
So when we run our sales, I can just set that going remotely and we can tweak the prices here and there.
And then with Superwall, Superwall lets us do paywalls without having to change the app all the time.
And that doesn't mean we're adding new paywalls.
But what it does is it lets us change how our paywall looks and feels to try and get more people to use Strongbox.
It's a huge lever that we have, which means we don't have to invade someone's privacy and start tracking what they're doing in the app to work out how can we get them to pay.
We can just test, you know, if I show you something different on the paywall, are you more likely to pay for it or not?
You know, a really good example would be what if I had a paywall where all it talked about was autofill?
And that's what you saw when you got through onboarding in the app.
As I was just like, hey, auto feels incredible, but you need pro to use it.
I can just test that and see if that works better or worse.
And the only information I get is how many people paid and how many didn't.
I don't get like telemetry on who did it, who they are, anything like that.
I just know that someone paid or someone didn't.
So someone who hears this, I mean, you know, like how do you distinguish the safety of someone's passwords to what you just described here?
if someone's concerned about that?
Yeah, the general rule that we followed
throughout all of this
is that we haven't added analytics.
I know there's been some debate around
whether or not they think RevenueCat
serves as analytics.
And I understand that there's a discussion there,
but RevenueCat also weighed in to help out there
and let people know that the data in RevenueCat
is the same data that the App Store gives us.
So nothing has changed.
The kind of second line of defense
I have a very firm policy that nothing like this is allowed to be after the database is opened.
So Strongbox's paywalls and, you know, syncing purchases and so on happens when you open the app.
It's not when you open a database, it's when you open the app.
I'm sure we can get background updates that say, hey, the subscription's expired,
but we're not sending anything to anyone.
We just might realize that your subscription's expired and tell you, you know, you can't use Touch ID to unlock your database anymore.
That was a kind of a long answer, but the short answer is nothing goes to anyone and we don't really have a plan to change that.
It would be really useful if I had analytics about how people use the app just to drive forward where to put our time.
The usual answer to analytics is scary data collection and so on, which I completely understand.
but it would also be not for that purpose.
But we've stayed true and we will do.
I'll just ask people with a survey every now and again
how they use Strongbox.
Just to clarify, if Touch ID isn't allowed,
you can still get in with a password.
It's not just keeping you away from your passwords.
Yeah, that would be a terrible strategy for user attention
to take their database away if they don't pay us.
But yeah, all of our...
That's very LastPass, though.
I've definitely seen places say you haven't paid, you can't get in.
And thanks to them not using KeyPass, that database is just gone.
But with us, all we do is we take away convenience features.
We don't actually stop you getting into a database or anything.
You will just lose autofill and you'd lose Touch ID, Face ID.
So you can still do everything just about.
It's just not quite as cool.
Right. And then I'll touch a little bit more on the business model in a second as we zoom out.
But the last question, I feel like telemetry analytics, very charged, very controversial subject,
because the way I see it is that it is so prolific and so bad in all these services.
People have this association with analytics and telemetry coming from these really invasive and bad big tech companies
that it's just easier to say, I don't want any of this.
And I think that is not a wrong answer.
But having spoken to so many privacy-first projects,
even on this podcast,
one of the most common themes is
we don't know what our users actually use our service for
because they don't have any insight.
And so they all say, we wish there was a way,
but if we did this, then there would be too much pushback.
And so it's a really hard line to walk around.
So I understand the difficulties there.
I'm sure it impacts you guys as well.
Yeah, I think it's a really, it's an interesting subject because I think people are very right to be scared of invasive telemetry.
I think it's something that you should always be careful with.
You know, I use tools like Little Snitch on my computer to check where's data going.
Like I've downloaded this cool app off the internet.
What's it doing?
Especially if I've had to have given it like a sensitive permission or something.
So I entirely agree.
I mean, the flip side of it is I think something that's happened over time is analytics are absolutely everything everywhere now.
You'll be tracked in like basically everything.
Even a lot of privacy first projects still have analytics somewhere.
They just try and say it's not in there.
And I generally think the analytics from bad actors are looped in with analytics from people who, like us, would just really benefit from knowing how do people use this thing?
We obviously get the cynical answer of,
will they use it to store passwords?
But the nuance is,
if we knew a little bit more about,
for example, how many passwords do people have in here?
Do people use Strongbox as their only password manager,
which we could kind of insinuate by,
do they have a huge list of vaults and passwords?
Do people share things with each other a lot?
Do businesses use this a lot?
All of these things can help drive
our direction on the product.
Like, do we find that people download the app and then start onboarding and then get to the sync screen that tells them all the different options and just close the app?
That's probably happening, but we have no idea.
So we kind of just have to trust what people tell us and ask people and try our best to get information that way.
Whereas in other apps, I can tell the users are dropping off at a certain point.
We need to make that better. And that's a really useful thing to be able to do.
And I sort of, as a thing I think about quite often is, is there any way that privacy apps
could do some kind of opt-in super light information dump somehow?
I've never come up with an answer for it.
So I've never, never come back to it.
But I'm sure, yeah, you've had a similar discussion many times where people just say,
we could have a much bigger business and much happier users if we had that information,
but we can't have it for a very good reason.
So for now, we don't have it, but I can kind of get a good feel for things from, you know, public communities, the emails that come in and so on.
Yeah, I guess on the topic of community, a really difficult thing originally when I found you guys, it was difficult to know if it was or wasn't.
But how do you feel about open source? Are you open source? If not, what's kind of your rationale behind that?
Yeah, so the short answer is yes, the co-based of Strongbox is open source.
The kind of longer answer is we do have some parts of it that aren't shared in the repository.
And that doesn't mean we've hidden something.
It's literally the Xcode project that you would download and run to be able to run Strongbox on your own phone.
You can't do that.
And that's not, again, it's not us trying to sneak something in.
It's a decision that was made a while ago.
And it's effectively just protection.
Because if we didn't have that very thin layer of protection,
you could just grab our repo and push your own password manager to the App Store tomorrow.
We have a license in there that says you can't do that,
but licenses don't necessarily prevent bad actors.
I've seen it happen.
This happens a lot.
There was some news earlier today where cal.com took their code base offline.
I just saw that before recording.
I got the email for it.
That's happening all the time.
we see it a lot where someone will make a really cool app and I'll be like this is great and then
I'll notice 10 kind of similar versions appear the next week and they're very very slightly different
and they're all paid products and you can tell it's the same app because you'll spot the same
bug in all of them like oh okay that's a bit more of a coincidence so the point is we want to be
transparent and that's important to us that you know there's nothing crazy going on just look at
a code you can have it and that's why we open source like the serverless function we have where
like we told people the main reason we have that is we don't want to put paid service keys inside
the app because someone could just grab them and start using our have I been pwned service but we
still want to make sure everything we do is transparent so that code is up there so yeah
there's some discussion around the strict definition of open source source available open source and
so on. But we do push everything to the cloud. And we also have like our Chrome extension is fully
open and so on. So it's all there to look at. It's just you can't quite build it very quickly.
Got it. You mentioned earlier that you're trying to broaden your horizons. You don't even want
someone to know they're using KeePass, which I respect. I think the best privacy security tools
don't need to tell users what's going on. I feel like something that can happen when you broaden
is it's easy to lose sight of the OG audience.
So do you still want to be committed
to those hardcore keypass people?
Will they still see those features?
Are you trying to balance that mainstream audience
and still secretly be serving that hidden audience
that they don't even know maybe is being served?
I think the easy way to put it would be,
I see broadening our horizons
and making a simpler experience
something that someone would opt into at the start.
So there's plenty of UX improvements we can make.
They're sort of the real key pass wizards that we will continue to do.
That will never change.
But I think for, say, if I wanted to give my parents Strongbox, they don't know what key pass is.
And I sort of don't need them to.
I want them to just use a password manager that I think is great.
And I can also give them for free.
That's quite nice as well.
But I can just give them that.
And they don't need to know technical details about anything.
I just want to give them it and say, hey, hit new database and go.
and the vision for it which is something I repeated a few times but effectively what if
really early on in the app you basically got asked the question do you know what keypass is
I wouldn't actually ask someone that but in a way like what if I could just let you pick
if you want a really simple way of using it or the complex way and that would most likely not change
anything at all about the in database experience I think we've done a really good job there and
we're continuing to improve it but I think that's really good but I think outside of that with you
know picking vaults customizing syncing things and setting up a bunch of I guess the more strict
privacy features and so on it's not necessarily something people will find a really common
complaint I get is people think autofill doesn't work but it's just because they haven't turned it
on and I think most people downloading our app and paying for it because they want to use autofill
probably expect it to just be on. So I think that kind of the answer is let people have an easy setup
button somewhere where we're like you just have one database and we turn on all the cool stuff
and we make sure you've got convenience unlocks turned on and it would then feel to you like
you're using one of these cloud-based solutions that doesn't have key pass details in there. It
would just feel a little bit smoother to you but I think it's incredibly important that that is
something that we do in addition to what we already do. I would never want to take anything away from
anyone. If anything, I actually have quite a lot more stuff I want to add, to be honest.
But I also think a simple kind of option would be really good.
Nice. And then kind of behind the scenes, what does your organization look like? You know,
how many people are working there? What are the different roles?
So there's a reasonable amount of us these days on the specific Strongbox team. There's me and
another product person so whilst I work a lot on product I also mostly look after everything to do
with engineering and then I try and look after social media and customer support too mostly
because I think it's quite important that this app transitioned from a face that people knew
they knew they could say like hey mark or address him directly in comments and so on so I think it's
really important we keep that so I'm maintaining that with me but I also think it's good to have
other people involved in terms of direction, design, where we go from here. So we have a head
of product who helps me with that direction and also gives me a little bit of a kick sometimes if
I'm dragging my feet thinking something has to be tweaked with for two months instead of just letting
people play with it and see what they think. And then I also have a team of three engineers
who work with me. So we have a big mixture of skill sets within that, people who are better at
design people who are better at web stuff or ios ipad there's a big mixture of skill sets but it
means that we have effectively triple the ability to work on the app that we used to have because it
used to be one person working on it before we took over so quite a lot more people involved
technically and then also just above that we have you know two people sort of looking out for where
it goes from here there's a you know a bunch more people who work in the company looking after
things like finance and so on.
But just in terms of Strongbox, there's give or take
five of us on a weekly basis that are looking after it.
Right, and I guess this is definitely the elephant in the room.
The acquisition, and so I think Mark is the original developer?
Is that correct?
Okay, so that happened, and then on the community side of things
there was the Strongbox acquisition.
So do you mind speaking to what that looks like,
how that changes things?
What are some of the concerns that you've seen?
I know that our audience is very wary of acquisitions.
We've seen open source projects go very downhill after acquisitions.
And so we kind of want it like there's that natural reluctance to be in support of them.
So maybe you can kind of speak to this and where you feel, how you feel about it.
I mean, look, I think that the initial thing is no matter what happens with an acquisition,
I think people are generally a little skeptical because there's been so many terrible ones.
I've seen plenty of acquisitions where apps have been bought and the price has doubled the next day or they've not had a subscription and then they've added one.
There's a lot of reasons that people are wary of these.
And I think what happened with Strongbox is we announced it and I think maybe didn't give people enough reassurance of what was coming.
people were sort of a bit worried about all the things that usually go wrong with acquisitions
where people just abandon it and jack prices up and close the source and so on so i think there
was a justifiable apprehension to us owning it the flip side of us owning it is that there's way more
people that work on it we can work faster and we can make bigger changes to the app than one person
could but i understand why people are apprehensive and i think we did post uh on the strongwatch blog
announcing it and Mark posted a letter to to sort of hand the reins off to us but we just sort of
rightfully had to help gain the trust of the community a bit. I think we had to put the work
in to share that we weren't going to do anything crazy and that we weren't going to drop analytics
in instantly which I think is what people mostly thought was going to happen. I think they presumed
we'd throw in loads of analytics on the first day and then jack up prices or add subscriptions.
Adding subscriptions was probably the most common thing I saw within telemetry, but Strongbox already had a subscription.
We didn't add that, but it was a thing that came up a lot.
And things like people thought we were going to kill Strongbox Zero, which we are not doing and I won't let happen.
So something that I've definitely learned from this and is something that we will take going forward into future acquisitions is to make sure we get the point home in our announcement.
And really try and start getting that trust straight away.
And that means, you know, whilst I did introduce myself really early and was talking to the community quite often,
like it took quite a while to get around to doing like a proper sort of Q&A and things.
And I think that's something that we definitely learned from.
But the way I've kept things going is everything's open.
I try and post in our Reddit whenever I do something new in the app.
I ask for feedback a lot. I ask for feature suggestions and comments.
Even when people are a little bit grumpy with me, I'm still happy to hear it.
Like I want to help people get their best experience and have them not hate us.
That would be great.
So I think we've done quite a lot to try and help prove that we're not going to do anything
sketchy with Strongbox.
Time is sort of the thing that proves that.
But we learned from making announcements better.
And then I'm hopeful that people have a slightly different opinion of us after the last year
or so.
I don't quite have a poll or anything to prove that.
But I think the community of Strongbox generally feels better about it now
than they did when it was announced.
So pretty good, I think.
We've added stuff.
To kind of round us out, I have just a couple more questions.
Subscriptions, and this is actually somewhat of a criticism I have,
maybe with a lot of people who are free open source advocates.
Free, people forget the meaning of free.
That means freedom, not free as in beer.
That is the very common metaphor that's used to help explain this.
But that culture still exists, right?
Where people really don't want to pay.
In fact, I don't know of any other KeePass client
off the top of my head that charges.
Maybe KeePassium has a paid plan as well on iOS,
if I remember.
But other than the Apple ecosystem,
I can't think of a paid KeePass client.
So I might ask, why should someone pay for a KeePass client?
Just as a question,
and then what are your subscription models?
Because I think I actually got Lifetime back in a day,
and I still have Lifetime.
So I think the reason for buying an app like ours
kind of applies to the argument as like a whole in that we're in a world now where there's always
been open source software but now there's probably been six new open source apps whilst we've had this
conversation they're springing up all the time people can make what they want and it can be great
it can be bad it can be whatever but there's new software all the time and a lot of the time people
choose to make that free and push it out to the world that way and i think that's incredibly
valuable and open source is the reason why keypass clients can even exist keypass itself is open and
that's what powers all of these keypass apps i think the choice for the person generally is do
you think the experience you get from an app like strongbox is worth some money a discussion i see
a lot is people say oh you know keypass itself is open source so why isn't strongbox just free
but strongbox the reasons it gets praised are years of love and affection and lots of hard work
and developer time is definitely not free even when you're building it for yourself it's quite
expensive to make apps and there's a lot to that you know you probably see reasonably often even
on open source repos there's hundreds of issues and problems all the time and you see how much of
that person's time gets eaten up with support, changes, fixes, and so on. And a lot of these
open source things become a full-time job for someone. And as apps get more complex and they
scale, more people have to be involved. And when more people get involved, the cost just starts
going up and up and up. And supporting via open source is viable for a lot of projects. I pay for
loads of support on GitHub these days. But for apps like ours, the craft we put into it,
the team we put into it isn't something we could sustain with open source.
And that was true when Mark ran it by himself and remains true now.
Except now there's five people instead of one and we haven't changed the price
because we're pretty happy with it as it is.
But this sort of cost of subscriptions sustains people building great things.
If no one paid for anything, then there wouldn't be great software.
Most of the open source software...
Yeah, most open source software you see probably at some point had some paid application involved,
which had a lot of people involved in an office somewhere.
So, you know, software can be free, it can be paid.
And it's just up to you if you think if a free one is fine for you, then that's OK.
There's no problem with that.
But you think the paid one is right for you, then that's good too.
You can support developing something and see it continue to improve over time.
Where I think we strike a middle ground is you can use most of Strongbox fully for free.
We limit very small things like convenience unlocks and autofill.
So you can use us and what I think is a very good experience for absolutely no money.
And if you want the other features, you can pay for them.
But if you don't, then Strongbox is free for you.
And we have a huge amount of free users and we don't get anything from that.
But we're happy that people choose to use us.
but we wouldn't be possible without the people who do pay for Strongbox. So it's an interesting
choice people have to make. I think I always vote for supporting good software but I appreciate that
I'm very biased in that I make a lot of software so I probably do want people to pay for it but
we do have options for people who really don't like subscriptions. We do let you have a lifetime
option for the app. If you really don't like in-app purchases you can grab it straight from the app
store. You can grab Strongbox Pro or Xero. And if you're using the free app, you can also grab it
in the app as an app purchase if you feel like it. So we do have an option for you for a lifetime sub,
which is priced at the equivalent of like a few years of subscription.
So what's next for you guys? And where can people connect with you or Strongbox? Just kind of
leave it open ended for you to kind of round things out.
So the place we're most active is there is a Strongbox subreddit where people post all the time, like requests, bugs and just thoughts.
We're super active in there. We reply to basically everything and try and get involved in the conversation.
We have a Strongbox Twitter account, which we don't necessarily post on super often, but we do reply to people who get in touch with us and tag us and so on.
And finally, we do have just an open email inbox.
So if people want to get in touch with us and speak to us,
they can just fire us an email and say whatever they want.
So we're pretty open to a whole bunch of different ways of getting in touch with us.
You can kind of pick your poison on that one.
You can open an issue on a GitHub repo if you'd like, if that's your preferred medium.
So we're kind of all over the place with communication.
We just want to meet people where they are.
Just get in touch, give us your ideas, niggles, whatever it is.
we're here for it.
Very cool.
Well, thank you for coming on the podcast, Alex.
And maybe someday in the future, I'll be back.
I think it's nothing you guys are doing.
Maybe, you know, I hope the system evolves,
the ecosystem evolves,
and I can go back to my really clean KeePass experience
because I used to really love that.
But that's something I'm hoping for.
I'm sure we'll get you one day.
I'm excited.
In the meantime, thank you for the work you do
because, again, it's my favorite KeePass client.
So thank you.
Appreciate it. Thank you very much.
great speaking with you.
talks.