Live data from Hacker News

KeeWeb: Unofficial KeePass web and desktop client

github.com

111–120 of 125 posts

Re: KeeWeb: Unofficial KeePass web and desktop client

#111
post #106
post #93

Earlier quoted context omitted.

This is what I'm talking about. You, a security enthusiast, are only interested in the technical security details. You respond to a comment about tradeoffs with details on the bug. I don't care about why the bug happened or how easy it is/isn't to fix. I care about whether the existence of the bug is something I should be so concerned about as to not use the software. In order to gauge that, I need a little more info…

>I don't care about why the bug happened or how easy it is/isn't to fix. I care about whether the existence of the bug is something I should be so concerned about as to not use the software. In order to gauge that, I need a little more info about the threat level. Threat level is 0%. No currently known attacks exist. This threat level immediately goes to 100% when a practical attack is discovered. There is no guarant…

This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here?

This is why security people are so frustrating to talk to; you only talk in extremes.

> Rather than worry about whether or not a practical attack already or will one day exist, I'd use cryptography that hasn't been shown to be broken.

That's not what I'm worried about. I'm worried about given that they do exist what is the risk to me? What is the likelihood that my account has been broken into?

Re: KeeWeb: Unofficial KeePass web and desktop client

#112
post #2

This is awesome. People are obviously going to give you a hard time about security and your implementation of the important parts of the software, but that's the advantage of open source! Edit: I am a daily user of KeePassX and get really tired of the UI after a while so I will definitely be trying this out ASAP!

I find it strange no-one is talking about https://spideroak.com/solutions/encryptr

Re: KeeWeb: Unofficial KeePass web and desktop client

#113
post #111
post #106

Earlier quoted context omitted.

>I don't care about why the bug happened or how easy it is/isn't to fix. I care about whether the existence of the bug is something I should be so concerned about as to not use the software. In order to gauge that, I need a little more info about the threat level. Threat level is 0%. No currently known attacks exist. This threat level immediately goes to 100% when a practical attack is discovered. There is no guarant…

This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here? This is why security people are so frustrating to talk to; you only talk in extremes. > Rather than worry about whether or not a practical attack already or will one day exist, I'd use cryptography that hasn't been shown to be broken. That…

I'm worried about given that they do exist what is the risk to me? What is the likelihood that my account has been broken into?

    ¯\_(ツ)_/¯

Re: KeeWeb: Unofficial KeePass web and desktop client

#114
post #96

Earlier quoted context omitted.

A warning about Macpass: After I saved my Keepass database with Macpass, KeepassX couldn't open it any more. So keep a backup unless you're sure you want to switch permanently. This probably applies to switching from any password manager to any other, honestly. (I think I was able to fix it in that case by opening and saving it with Keepass.)

> by opening and saving it with Keepass The mono version?

I don't remember exactly how I fixed it. The point is, have a backup, and don't use Macpass to do any editing until you're sure you want it.

Re: KeeWeb: Unofficial KeePass web and desktop client

#115
post #111
post #106

Earlier quoted context omitted.

>I don't care about why the bug happened or how easy it is/isn't to fix. I care about whether the existence of the bug is something I should be so concerned about as to not use the software. In order to gauge that, I need a little more info about the threat level. Threat level is 0%. No currently known attacks exist. This threat level immediately goes to 100% when a practical attack is discovered. There is no guarant…

This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here? This is why security people are so frustrating to talk to; you only talk in extremes. > Rather than worry about whether or not a practical attack already or will one day exist, I'd use cryptography that hasn't been shown to be broken. That…

>This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here?

I'm not a security expert, more of a hobbyist. So I'll let someone else quantify potential specifics. To my understanding, they would not require physical access and would be able to guess any passwords generated (once an attack has been found/created).

>That's not what I'm worried about. I'm worried about given that they do exist what is the risk to me? What is the likelihood that my account has been broken into?

The chances of 0 becoming 1 are not quantifiable because it requires knowing unknowns. It is, however, non-zero. For a small list of unknowns:

1) Who knows about the attack

2) How practical is the attack?

3) What software/websites/people are they choosing to attack

4) Are you even using any of the software/websites that are being attacked?

5) Are they going to accept cracking 50%~ accounts? Many crackers only care to scrape the bottom of a barrel. What are the chances you were in the part of the barrel they scraped?

I assume the worst because being compromised is a zero-sum game. I've been compromised or I haven't. Therefore my variables are:

Everyone. Extremely. Only things I use. Of course. Doesn't matter, I'm in the targeted group.

I wouldn't make any bets on security through obscurity.

Re: KeeWeb: Unofficial KeePass web and desktop client

#116
post #95

Earlier quoted context omitted.

As far as I can see, the comment you replied to contains no mention of these things. Can you quote the relevant part?

cmrx64: it all depends on how much you trust 1password and what your threat model is. For me, the advantage of keepass is that I don't need to upload my credentials anywhere oneeyedpigeon: But if you want to sync your credentials across devices, you still have to upload them somewhere, right? dorfsmay: You are uploading a file that is encrypted using very strong encryption, not plain text password I took that to mean…

Thanks. This was very cryptic, I'm surprised you pieced it together.

Re: KeeWeb: Unofficial KeePass web and desktop client

#117
post #115
post #111

Earlier quoted context omitted.

This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here? This is why security people are so frustrating to talk to; you only talk in extremes. > Rather than worry about whether or not a practical attack already or will one day exist, I'd use cryptography that hasn't been shown to be broken. That…

>This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here? I'm not a security expert, more of a hobbyist. So I'll let someone else quantify potential specifics. To my understanding, they would not require physical access and would be able to guess any passwords generated (once an attack has been…

Getting my reddit account hacked is not the end of my life. Hell, getting my bank account hacked is not the end of my life. I don't want those things to happen, I will take precautions to prevent it.

But too often security people talk as though it's the only thing I should care about. And it's not, I care about other things too, to varying degrees.

So, to make an informed decision, I need to know more than just that Math.random() is insecure. Knowing that an attack wouldn't require physical access is the type of information I'm interested in. So thank you for that.

Re: KeeWeb: Unofficial KeePass web and desktop client

#118
post #117
post #115

Earlier quoted context omitted.

>This comment doesn't make sense. All attacks are not equal. Some require physical access; some do not. Some require seed data; some do not. What exactly are you talking about here? I'm not a security expert, more of a hobbyist. So I'll let someone else quantify potential specifics. To my understanding, they would not require physical access and would be able to guess any passwords generated (once an attack has been…

Getting my reddit account hacked is not the end of my life. Hell, getting my bank account hacked is not the end of my life. I don't want those things to happen, I will take precautions to prevent it. But too often security people talk as though it's the only thing I should care about . And it's not, I care about other things too, to varying degrees. So, to make an informed decision, I need to know more than just that…

I understand completely. I feel most people's threat models stop even before 'threat has physical access'. The chances of both your computer being stolen and the person who stole it being tech-savvy enough [0] to break into things may as well be 0 for anyone who isn't the target of a state actor or working in a security field. At that point the only people who care are the people who care about security or slim chances like that occurring. :)

[0] Or the thief selling it to someone who is tech savvy enough. Still practically 0 for most everyone.

Re: KeeWeb: Unofficial KeePass web and desktop client

#119

Earlier quoted context omitted.

I host mine on gogs.sr.ht, a private git service I run for myself and friends. I used to host it on a private GitHub repository. There are other options like a private Bitbucket repository, or even just a public repo on GitHub - since the passwords are all encrypted, you don't really have to worry about that. I'll happily give an sr.ht account to anyone who wants one for this purpose, mention HN in your application c…

Can you approve @nikolay, please?

Looks like you requested an account in June of 2015? What's the story there?

Re: KeeWeb: Unofficial KeePass web and desktop client

#120
post #41

Earlier quoted context omitted.

No, it's not worse for your scenario. (That wasn't my assertion) However, this is an alternative to KeePass/KeePassX, so the typical behavior of KeePass users is to generate passwords with it, not reuse bad passwords. For example, I use KeePassX to generate strong passwords for long-term encrypted archives, and if I switched to this app, I wouldn't get the same security. I'm confused, though, should I say: "All right…

I use KeePass and I don't use it to generate passwords. It's a pain to open and close every time I need to login somewhere, especially if I'm on mobile. I use it for when I forget my passwords, and I honestly believe that is the common use case, but who knows?

Yep, I use KeePass primarily for password management, in most cases I don't control what the passwords are - how else am I meant to store all these different client VPN credentials?
Post reply on HN