Live data from Hacker News

Security Flaw in OS X displays all keychain passwords in plain text

medium.com

51–57 of 57 posts

Re: Security Flaw in OS X displays all keychain passwords in plain text

#51
post #37

Earlier quoted context omitted.

i dont even know which version i run, so no idea if i have to be scared or not. updates are way to painful to do regulary on a working dev machine. (lazy linux user here) anyway i never saved a password, thats exactly my point. There is not a single reason to believe that the apple keychain can be fully trusted, its that simple.

> There is not a single reason to believe that the apple keychain can be fully trusted, its that simple. How do you believe that differs from any other cloud manager, local or cloud-hosted? What reason(s) do you have to believe they can be fully trusted? Or do you not use password managers at all? I assume you don't re-use passwords from site to site (because there's also no single reason to believe any particular si…

I dont use any of these but use the gnome keyring at home. Its OS, based on industrie standards and afaik never had serious issues. (It sure helps that linux has more restrictive user rights)

On other places i use a password sheme, and if possible 2fa. A sheme is not perfect ether, but would require to attacker to fetch multiple of my passwords until he can recreate it.

Re: Security Flaw in OS X displays all keychain passwords in plain text

#52
post #39
post #37

Earlier quoted context omitted.

i dont even know which version i run, so no idea if i have to be scared or not. updates are way to painful to do regulary on a working dev machine. (lazy linux user here) anyway i never saved a password, thats exactly my point. There is not a single reason to believe that the apple keychain can be fully trusted, its that simple.

So how do you manage your passwords you have for multiple sites?

i use a password sheme, and if possible 2fa. A sheme is not perfect ether, but would require to attacker to fetch multiple of my passwords until he can recreate it.

Re: Security Flaw in OS X displays all keychain passwords in plain text

#53
post #51

Earlier quoted context omitted.

> There is not a single reason to believe that the apple keychain can be fully trusted, its that simple. How do you believe that differs from any other cloud manager, local or cloud-hosted? What reason(s) do you have to believe they can be fully trusted? Or do you not use password managers at all? I assume you don't re-use passwords from site to site (because there's also no single reason to believe any particular si…

I dont use any of these but use the gnome keyring at home. Its OS, based on industrie standards and afaik never had serious issues. (It sure helps that linux has more restrictive user rights) On other places i use a password sheme, and if possible 2fa. A sheme is not perfect ether, but would require to attacker to fetch multiple of my passwords until he can recreate it.

What's a password sheme?

Re: Security Flaw in OS X displays all keychain passwords in plain text

#54
post #51

Earlier quoted context omitted.

I dont use any of these but use the gnome keyring at home. Its OS, based on industrie standards and afaik never had serious issues. (It sure helps that linux has more restrictive user rights) On other places i use a password sheme, and if possible 2fa. A sheme is not perfect ether, but would require to attacker to fetch multiple of my passwords until he can recreate it.

What's a password sheme?

Essentially something like this:

Base Passwort: 123456, Rules: a = A, e = #, Platform: Hacker News, Connector: Social _, Money -

Password: HAck#rN#ws_123456

Re: Security Flaw in OS X displays all keychain passwords in plain text

#55
post #54

Earlier quoted context omitted.

What's a password sheme?

Essentially something like this: Base Passwort: 123456, Rules: a = A, e = #, Platform: Hacker News, Connector: Social _, Money - Password: HAck#rN#ws_123456

Oh, you mean to spell "scheme" I think?

Is there reason to believe that's significantly more secure than just re-using the same (strong) password everywhere?

Personally, I'd feel safer with a unique strong password for every site, even though it effectively requires a password manager (and trusting that password manager). So far, i think most attacks don't usually involve your local computer, people aren't attacking your laptop trying to crack your password manager (I think? Any known attacks of such? I guess I'd assume the NSA probably _is_, but anyway, regardless, I'd rather have unique strong passwords).

Re: Security Flaw in OS X displays all keychain passwords in plain text

#56
post #54

Earlier quoted context omitted.

Essentially something like this: Base Passwort: 123456, Rules: a = A, e = #, Platform: Hacker News, Connector: Social _, Money - Password: HAck#rN#ws_123456

Oh, you mean to spell "scheme" I think? Is there reason to believe that's significantly more secure than just re-using the same (strong) password everywhere? Personally, I'd feel safer with a unique strong password for every site, even though it effectively requires a password manager (and trusting that password manager). So far, i think most attacks don't usually involve your local computer, people aren't attacking…

yeah :) not my native language. thanks for the correction.

I am on my phone and lazy so excuse missing sources. But afaik a lot of malware targets password managers. Dont forget that some of these also are really really bad and easy targets. some bigger ones may be good, but still tend to fail from time to time.

a unique password for every site is defintly better, but not if these passwords are saved anywhere.

My sheme, which only exists in my head, imo provides therefore more safety.

honestly i am just paranoid, but the way some users use password managers scares me.

Re: Security Flaw in OS X displays all keychain passwords in plain text

#57
post #56

Earlier quoted context omitted.

Oh, you mean to spell "scheme" I think? Is there reason to believe that's significantly more secure than just re-using the same (strong) password everywhere? Personally, I'd feel safer with a unique strong password for every site, even though it effectively requires a password manager (and trusting that password manager). So far, i think most attacks don't usually involve your local computer, people aren't attacking…

yeah :) not my native language. thanks for the correction. I am on my phone and lazy so excuse missing sources. But afaik a lot of malware targets password managers. Dont forget that some of these also are really really bad and easy targets. some bigger ones may be good, but still tend to fail from time to time. a unique password for every site is defintly better, but not if these passwords are saved anywhere. My she…

Yeah, passwords are all a mess no matter what, just choice of lesser evils.

"Scheme". It's pronounced like "skeem", not "sheem".

Post reply on HN