>Tackle the information disclosure issue
I'm curious how you plan to approach this one. One nice thing about passff is that it can find the right password file based on if the file name matches the domain. I don't need to drill down to my bank/paypal file when I visit paypal.com for instance.
It would be nice if a public github repo would suffice, but putting a git remote on a usb stick works pretty nicely and is private as well.
I'm considering writing an implementation myself for a different audience, so it is nice to pick your brains as you've probably given this a lot of thought too :)