Live data from Hacker News

On Password Managers

tbray.org

151–160 of 347 posts

Re: On Password Managers

#151

Any password manager recommendations such that people don't need to deal with 1Password's cloud-based storage?

I'm happy with PasswordSafe. It's very oldskool, you'll have to run it under Wine on MacOS and Linux, and you'll have to do your own syncing (I just use Dropbox, but want to switch to Owncloud some time).

Re: On Password Managers

#152
post #82
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

For Windows, there is "1Password for Windows" and 1Password 4. I've never used the "for Windows" version, but I believe it's cloud only. 1Password 4 allows local vaults. However 1Password 4 is in maintenance mode and missing lots of nice features, like searching two vaults at once.

Also they don't sell licenses for 1password 4 on Windows anymore. On Windows after the 30 Day trial your stuck or forced to go cloud...

Re: On Password Managers

#153
post #50

Against all recommendations I reject all password managers. I feel like all security software is eventually compromised, most frequently by business folks as in this case. Instead I use a tiny notebook that I keep in my wallet. I pick long 12+ character passwords myself, not super randomized but I haven't heard of a brute forcing attack in a long time. It allows me to easily meet weird password requirements. I feel p…

> Instead I use a tiny notebook that I keep in my wallet. So, if your wallet gets stolen or lost, you'll have to go through every site you use and change all your passwords, quickly, and hope that whoever has that notebook hasn't taken over your accounts in the interim? Also problematic if you travel, and don't particularly want to make that list of passwords available.

I used pen and paper password management for a while (I use keepass these days), so I'll defend it a bit.

1) I used practically exclusively my desktop at the time, so the password slip stayed home

2) My home was relatively safe place; I didn't really have guests or other people mingling around and bulglary was basically unheard of in the area. My threat model did not include defending against law enforcement.

3) Paper is literally unhackable (with software), and it is trivial to understand that. I considered keyloggers to be a game-over situation anyway.

4) I always used secure password generator to create the passwords

5) I felt at the time that paper was more safe against catastrophic data loss (either due software or hardware failure)

6) Paper works universally crossplatform without needing any syncing. Multibooting and reinstalling different OSes etc did not impact my passwords

7) I wasn't confident in my ability to evaluate software password managers and especially establising secure usage patterns for them

With these points I still feel like the decision to use "paper under keyboard" was pretty well justfied and reasonably secure. Most importantly it enabled me to make the huge leap forwards from previous really insecure methods. Of course there are many reasons why you wouldn't want to use paper, some of them implied in above points.

I would never carry my password-slip with me on a regular basis, that seems just foolhardy, so that is the main difference between past me and OP.

Re: On Password Managers

#154
post #18

Earlier quoted context omitted.

Lastpass doesn't necessarily have the best track record, and you said you couldn't go into detail, but I'm curious so will ask - if you feel comfortable sharing, what securities issues do you see with lastpass besides storing secrets in some companies cloud?

By default the browser plugin is configured in such a way that 2FA is completely bypassed for a second when logging in. This is officially documented, so we can likely assume that it will never be fixed. https://lastpass.com/support.php?cmd=showfaq&id=2775

This isn't a bug, this is due to the offline access option. If your machine has the database locally cached, 2FA won't do anything because your database won't be encrypted with 2FA (not possible), just your master password. An attacker could just copy the cached database and decrypt it with your master password. All 2FA does is restrict who can download your database (both initial and updates), not decrypt it. If you don't like this behavior, disable offline mode.

This is just fear mongering.

Re: On Password Managers

#156

I use password managers, but I think the usual way of thinking about them is wrong Besides password reuse being not recommended, the main issue is: most websites don't give a eff about whether they store your password correctly or not It's a trust asymmetry, they ask you to provide a password (and most ask one with a lot of BS restrictions) THEN md5 it and put it on the database, or worse And as said by the article (…

Do you mean this: https://www.troyhunt.com/password-managers-dont-have-to-be-p...?

Re: On Password Managers

#157
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> 3. They're promoting cloud vaults and hiding local vaults, and the Windows version of 1Password has apparently never used local vaults.

Windows had local vault, I used the local vault version synced via dropbox for years.

Re: On Password Managers

#158
post #69

Earlier quoted context omitted.

Well, no, unless I missed something, they have not been clear that local-storage 1Password will continue to work. They have carefully left the door open to changing that at some undefined point in the future. At which point I will migrate away. I love the apps (use it on MacOS and iOS), but local-only storage and non-cloud sync are my hard requirements. I'm willing to pay a monthly rent, but will not 'cloudify' my pa…

Did you see the links included in my parent post? The founder specifically said that standalone vaults will continue to be supported. You don't have to sync your standalone vault to any service if you don't want to. Though of course it'd be difficult to use both the desktop and mobile apps if you don't sync somehow.

Will continue to be supported for 6 and 7. Nothing beyond that.

Re: On Password Managers

#159
post #82
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

For Windows, there is "1Password for Windows" and 1Password 4. I've never used the "for Windows" version, but I believe it's cloud only. 1Password 4 allows local vaults. However 1Password 4 is in maintenance mode and missing lots of nice features, like searching two vaults at once.

I have the Mac and the Windows licenses for 1Password. Windows 1Password 4 is a nightmare to use with its terrible UI and its buggy Chrome plugin integration.

Re: On Password Managers

#160

Earlier quoted context omitted.

> 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords 1Password v6 for Windows doesn't work with local vaults, it requires 1password.com

This won't help new users, but for people who own a previous release (before it turned into a "modern app") you can still download 1Password v4 for Windows. https://app-updates.agilebits.com/

I have it and it's terrible IMO.
Post reply on HN