Ask HN: How comfortable do you feel using cloud-based password managers?
1–10 of 199 posts
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#2I used to use rsync (bittorrent-sync) to keep my own hosts up to date against each other. This was painful to manage so I accepted the bitwarden cloud model.
The risks are there, for sure. If you doubt the crypto behind your keystore, where it is should worry you little because how insecure it is should not be about where it is: its about how its shrouded, and how what is shrouded can be revealed.
My belief in the shroud protecting my secrets is my belief in their ability to code to the spec. it wasn't founded in my use of a private filestore to back the keystore, although I did, and I prefer private files, to private cloud files, to cloud files hosted by some intermediary, to public cloud.
Bitwarden is a private cloud file, hosted by some intermediary. The risk here is twofold: the intermediary is broken and its persisting filestore is readable, and bitwarden is broken and its interior private view becomes visible.
My best belief is that no part of my interactions depend on bitwarden knowing the interior state of my keys, they only handle shrouded data, and either I run apps which decode locally, or I run javascript which decodes locally, but I do not expect or believe any transit of the un-shrouded state of my data routinely has to flow through their hands. And the persistence of that belief is because they say the limits to how they can help recover my keystore, if I lose critical information. if they are truthful here, they cannot help me if I lose the escrow passphrase, because nothing they hold is the decrypt of my shroud. I have to give permission to de-shroud there side, the protecting key. its otherwise only used locally to me. (if somebody breaks the .js code, then the filestore being in the cloud is irrelevant)
1Password made the same kinds of commitment to me. As do LastPass and a number of other people. They all have to be comparable in this regard because its the fundamental business model.
At one stage, there was some leakage in the model for some keystores. The file names un-necessarily encoded revealing parts of the URLs they related to. I think thats changed now. It was scary. I had assumed everything was shrouded, it turned out for some period of time, only passwords and identity inside the URL had been fully protected. They changed that. I think it was 1password, it might have been lastpass. It wasn't bitwarden because I moved to them earlier this year and that was 2-3 years ago or more.
If I have misunderstood and sometimes my data is visible to them in clear, on their machines, I'd love to know.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#3Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#4I moved from Lastpass to pass(https://www.passwordstore.org/). It's by far the best decision I've made in a long time (I've moved a lot of services over to my servers and self host pretty much everything)
I use Mac, but it works on any machine to my knowledge and the great thing is:
1. Use your keys, so ONLY YOU can only decrypt it (gpg keys)
2. Has Chrome/Firefox extensions that automatically fill out passwords
3. Can upload the encrypted passwords to git to use on other machines (presumably)
4. Dead simple to use (go on terminal and generate random passwords, bunch of other goodies)
5. As said previously, it's all on your machine, no one else having access.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#5At work I’ll see people — the security team, usually — taking some already-encrypted thing and re-hardening it to the nth degree. I think that’s stupid. If you don’t trust your encryption, don’t bother using it. If you do trust it, stop there. It’s maths. It’s proven.
I feel the same about 1Password. I trust that they encrypt my stuff with trusted encryption. That’s it.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#6I prefer to store KeePass encrypted dB on Dropbox than going for 1Password cloud.
Plus Keepass is opensource...
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#7Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#8Never. I moved from Lastpass to pass( https://www.passwordstore.org/ ). It's by far the best decision I've made in a long time (I've moved a lot of services over to my servers and self host pretty much everything) I use Mac, but it works on any machine to my knowledge and the great thing is: 1. Use your keys, so ONLY YOU can only decrypt it (gpg keys) 2. Has Chrome/Firefox extensions that automatically fill out passw…
Currently using keepass. I would migrate to pass since I enjoy managing data via command line, but what I don't like is depending on a gpg key being installed in order to use it.
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#9I never really understood how it "syncs" but it's just git! Push and pull to update on every device. I use a private repo since site names are still metadata. You could put the whole directory tree in a tomb as well but that extension is only supported on mac only or something.
Pass is the one thing that seems fairly universal I think and it's all just text files which makes things really nice. No worrying about will it work on mobile or if the browser extension is useless without an application.
For example, 1Password X is a standalone extension so you could use it on Linux while Dashlane requires the desktop application running on the host. The connection works but isn't always reliable when running non-natively ie WINE
As for security, they're all fairly well audited I think? Remembear and 1Password both have external audits they pass, and provide remediation plans for any findings. Probably the same with Lastpass. Personally, I don't really think about it that much so I don't have a good answer. You can interpret that as me trusting providers but I have no real idea. I mainly just focus on the usability hah
Re: Ask HN: How comfortable do you feel using cloud-based password managers?
#10Passwords are too important to evaluate a manager on convenience primarily. I think it is a little strange that banks do not work to get in this area. You trust your bank or else you would not keep your money there. I know too little about the main password manager companies to know if they are trustworthy.
I guess this is too small domain for banks but I think it would be interesting to see what happened if they moved into it.