You could say I put a lot of trust in Google, as I use the built-in password manager in Chrome. My rationale is the following: 1. My browser vendor can access my browser passwords anyway. 2. It's better to trust fewer vendors and pieces of software. 3. Copying passwords to clipboard is awfully insecure. 4. Trying to remember all passwords is also awfully insecure. I do not save any money-related passwords. I do dream…
1. Is not necessarily true. If you use an open source browser like firefox, your browser vendor would absolutely not be able to access your passwords (...without creating a huge scandal where users would catch up immediately) 3. Can actually be mitigated, or other options can be used. For example, in my browser I disabled JavaScript clipboard access, so that random websites can't access my passwords. You mention pass…
Ask HN: How comfortable do you feel using cloud-based password managers?
81–90 of 199 posts
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#82Never. I moved from Lastpass to pass( https://www.passwordstore.org/ ). It's by far the best decision I've made in a long time (I've moved a lot of services over to my servers and self host pretty much everything) I use Mac, but it works on any machine to my knowledge and the great thing is: 1. Use your keys, so ONLY YOU can only decrypt it (gpg keys) 2. Has Chrome/Firefox extensions that automatically fill out passw…
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#83I have used 1password. I only moved to Bitwarden because I decided that if the PM was going to demand cloud backing I might as well pay cloud cost to an open-source entity. 1password is faster. I used to use rsync (bittorrent-sync) to keep my own hosts up to date against each other. This was painful to manage so I accepted the bitwarden cloud model. The risks are there, for sure. If you doubt the crypto behind your k…
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#84Prior to doing this (requirement for my job) I didn't have any particular set up, so in comparison this feels really good.
Main grumble is I don't pay for Dropbox so have a device limit, so end up just downloading database onto extra devices which mostly works but sometimes requires redownloading to get latest and potentially uploading to Dropbox if I have created a new password. Maybe I will pay for Dropbox sometime (as let's face it, it is useful beyond this case).
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#85I don't mean to hijack the thread, but allow me to ask what you guys use within you company, if anything. Do you use a cloud solution, something self-hosted, or nothing?
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#86Just because of the LastPass experience I'm not sure would I try something else.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#87Lastpass has has intrusion in the past 2015 and are closed source.
Site below has a list of some security incidents related to password managers. https://password-managers.bestreviews.net/faq/which-password...
A secure password manager would need to have the decryption keys offline client side save from central attacks.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#88Earlier quoted context omitted.
1. Is not necessarily true. If you use an open source browser like firefox, your browser vendor would absolutely not be able to access your passwords (...without creating a huge scandal where users would catch up immediately) 3. Can actually be mitigated, or other options can be used. For example, in my browser I disabled JavaScript clipboard access, so that random websites can't access my passwords. You mention pass…
Your browser sends and receives tons of packets to addresses owned by the browser vendor and third party sites. After all that's its main function. Your open source browser is millions of lines of code. You think it would not be possible to exfiltrate passwords without your notice? It seems a much more practical approach to assume your browser vendor is a "good guy", as the alternative model is that you choose to do…
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#89You could say I put a lot of trust in Google, as I use the built-in password manager in Chrome. My rationale is the following: 1. My browser vendor can access my browser passwords anyway. 2. It's better to trust fewer vendors and pieces of software. 3. Copying passwords to clipboard is awfully insecure. 4. Trying to remember all passwords is also awfully insecure. I do not save any money-related passwords. I do dream…
So you remember unique, high entropy passwords for all your money related sites? If not, you might be putting yourself at greater risk than syncing the passwords.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#90I've used pretty much every password manager under the sun at one point or another. Lastpass, 1Password, Bitwarden, Dashlane, Remembear, KeePass(X) and I've finally settled on regular ol' pass. I never really understood how it "syncs" but it's just git! Push and pull to update on every device. I use a private repo since site names are still metadata. You could put the whole directory tree in a tomb as well but that e…
Sadly this isn’t a modern solution. People have smartphones and occasionally have to login to Windows (without WSL). While I’d love for everything I use to provide an easily accessible *nix shell it just isn’t practical for phone use or modern computing environment where you can access cloud data using web services from any internet connected computers/devices.
https://itunes.apple.com/us/app/pass-password-store/id120582...