Live data from Hacker News

Horcrux: A Password Manager for Paranoids

arxiv.org

151–160 of 168 posts

Re: Horcrux: A Password Manager for Paranoids

#151

If you are paranoid, then there is only one option, you are the password manager. Certainly not a piece of software you didn't author yourself. Else you are not truly paranoid.

I'm paranoid enough to only use my own password manager, but if you must use a password manager written by someone else then don't use one that runs in a web browser. Moreover, although this doesn't apply in this case, don't use a password manager that stores anything on a server not totally controlled by you.

a piece of paper in your wallet is probably safer in many cases... but not as convenient

Re: Horcrux: A Password Manager for Paranoids

#152

Earlier quoted context omitted.

No, actually only stating truly paranoid people would not use a 3rd party password manager. Else you still have somewhat trust in third parties, making you not paranoid. Your reply however... stamps paranoid label on it :)

If you were that paranoid you wouldn't be using a web browser in the first place. After all, its some 3rd party software that has access to your passwords. There seems to be a growing chatter on HN and elsewhere about how you can't trust free software because you didn't audit/write it yourself. I'm not sure if people actually believe that or use it as a way to point out how they're smarter than other people. Sure its…

Don't forget about the OS, you probably didn't write that software either (you are doomed)... and even if you keep your password on paper or in your head, there could be a keylogger when the time comes to use that password.

Re: Horcrux: A Password Manager for Paranoids

#153
post #54

Earlier quoted context omitted.

I suspect it's the same reasons nuclear launch facilities use floppy disks -- the solution is approved, and getting a new solution approved is viewed as too expensive/infeasible. Not saying the argument is valid, just that it may be the reason.

That and its proven to work, has a ridiculously long track use history (for software) so the bugs are fixed or well documented, and pretty damn hard to exploit. It's not like anyone is going to plug an 8 inch floppy disk they found laying in the rural Wyoming dirt parking lot into the nuclear silo master computer to check what's on it.

Yikes! Last time I looked, the intercontinental nuclear launch codes of any major power have not yet been proved to work.

But OK, I assume they still pass whatever dry-run test procedures exist. But if it is true that they are based on floppy-disks, then I don't think sticking with them is a net win for reliability and safety.

Bits rot, especially on floppies. So if they are still using them they have created procedures for refreshing the bits from backups. By now the floppies might be little more than ceremonial objects inside the systems that really determine the launch procedure.

And those systems would have evolved informally over time and might be ever-changing, poorly understood and poorly tested.

Re: Horcrux: A Password Manager for Paranoids

#154
post #54
post #48

Earlier quoted context omitted.

What is it with banks and their annoyingly terrible "security" requirements? My old bank once sent me an email saying I had to reset my password. The email seemed legit, but upon following the link therein something didn't seem quite right. So I use another device to visit my bank's site directly. Upon trying to login, I get redirected to the same form I reached from the email link and had a sinking realization that…

I suspect it's the same reasons nuclear launch facilities use floppy disks -- the solution is approved, and getting a new solution approved is viewed as too expensive/infeasible. Not saying the argument is valid, just that it may be the reason.

On the other hand, when the collective idiocity better known as the Internet of Things finally comes back to bite us in the ass, we can at least be sure it wont be in the form of a nuclear winter.

Re: Horcrux: A Password Manager for Paranoids

#155
post #48

Earlier quoted context omitted.

What is it with banks and their annoyingly terrible "security" requirements? My old bank once sent me an email saying I had to reset my password. The email seemed legit, but upon following the link therein something didn't seem quite right. So I use another device to visit my bank's site directly. Upon trying to login, I get redirected to the same form I reached from the email link and had a sinking realization that…

I've known banks that don't let you change the PIN on their cards - for "security" reasons. And banks with 5-digit maximum password lengths - "oh, it's strong enough, you need to use a token to get money out anyway" ... but not to login.

The IT community should launch a campaign against the stupidity of banks' security procedures, which discredit our jobs...

Re: Horcrux: A Password Manager for Paranoids

#156
post #149

Earlier quoted context omitted.

Many international withdrawals only do 4 digits which means 6 digits in your home country becomes meaningless...

they should fix the underlying problem but in the meantime, they probably could just automatically truncate to 4 chars when 6 can't be used?

No, because certain combinations, e.g. 1111 are prohibited in four digit codes but wouldn't be at the start of six digit codes.

Re: Horcrux: A Password Manager for Paranoids

#158

Earlier quoted context omitted.

Similar: https://webpass.rkeene.org/ Though it does syncing

That's pretty cool. How does the syncing work? You should add emojis! :-)

It just posts an encrypted json blob to a CGI script that waits for another connection with the same ID. The script then connects those two connections so that anything one sends the other receives using a FIFO, so no disk involved and they can stream as much as they want to each other.

Re: Horcrux: A Password Manager for Paranoids

#159
post #48
post #45

Sticking with zx2c4 pass. It is an assembly of gnupg, git, and pwgen. Trusted open source components. Works with a Yubikey (opensc and gpg-agent) to prevent private key theft via software. PassFF extension provides excellent browser integration. Android Password Store and OpenKeychain allow pass and yubikey to work on my mobile. Strong 2 factor password storage everywhere I need it. My biggest problem these days is d…

What is it with banks and their annoyingly terrible "security" requirements? My old bank once sent me an email saying I had to reset my password. The email seemed legit, but upon following the link therein something didn't seem quite right. So I use another device to visit my bank's site directly. Upon trying to login, I get redirected to the same form I reached from the email link and had a sinking realization that…

I'm having a battle with HSBC in the UK at the moment and can't get past canned customer support responses either.

If there is a security issue with your card, HSBC Fraud department will send you a text, telling you to call them.

The text comes from an unknown number. The number you are told to call is not listed on their website anywhere.

At the same time they are sending letters to customers warning about how to protect from phishing attacks.

I've been trying to explain to them, that they are training their customers to accept phishing attacks, but they are having none of it.

Yes, I understand that they don't want to publicise their special number on the website - but at least put it on an unlinked page, so that if a customer visits hsbc.com and searches for the number it comes up in the results.

I really don't understand these people.

Re: Horcrux: A Password Manager for Paranoids

#160

Earlier quoted context omitted.

As an infosec guy, I'm honestly getting really tired of this. Virtually every time someone submits some new security tool to Hacker News, the author has made trivial, catastrophic, and what should be completely avoidable security mistakes. So for the hundredth time, if you're not a cryptographer or experienced security engineer, please stop releasing and promoting your crypto-related projects before they have been ve…

Is there a good way to find people who are qualified to do such a review? This paper was written by a Ph.D. student and professor of Computer Science at a respected university. The professor teaches a crypto course on Udacity ( https://www.udacity.com/course/applied-cryptography--cs387 ). If they don't meet the criteria for being cryptographers, I wonder how many people in the world do?

I'm going to push back on this a bit.

Thomas responded alongside this comment to talk about how academic cryptographers are not necessarily qualified to implement original crypto, and I largely agree with that; however, I don't actually think that's the issue here. Rather I would pin this on a lack of peer review.

I could be wrong, but I don't believe the author of this paper has had it published or at least accepted in any journal or conference proceedings. Being an eprint format with endorsement rather than peer review, you can expect mistakes like this to happen often, even if the authors are ostensibly qualified. When you submit original research for publication you generally go back and forth a bit with adjustments as needed, and as long as there is nothing egregious you don't need to redo it all.

In this specific case, I believe the author fully understands the issue (or would, were it presented to them) and is fully capable of fixing it. A qualified peer review would (hopefully :) have caught this and other latent issues if an HN commenter did.

We see this in the broader mathematics and computer science communities, and we especially see it in sub-disciplines like machine learning as well. It's absolutely true that academic cryptographers should not be assumed capable of rolling their own crypto a priori, but in my (educated) opinion I would certainly place far more weight on crypto developed by an academic cryptographer than a software engineer without any particular training.

My platonic ideal for someone who is capable of developing original crypto is something like an academic with a PhD in math or computer science (focusing on crypto), who can develop software very well and who joins an applied lab for crypto engineering and development (like NCC's) or a top cryptanalysis firm like Riscure. Failing that, I'd probably place the most weight on someone who had a lot of training in crypto engineering or practical cryptanalysis over an academic with no implementation experience.

(I apologize if any of this is patronizing, I don't know what your background or familiarity with the academic process is w/r/t peer review, etc).

Post reply on HN