Live data from Hacker News

On Password Managers

tbray.org

191–200 of 347 posts

Re: On Password Managers

#191
post #176

Earlier quoted context omitted.

I think there are two concerns: 1. Accessing 1password.com's from a browser is less secure than using an app. You can choose never to log in but it makes it harder to recommend 1Password to journalists, political dissenters, etc. The most paranoid people need a local vault option. 2. The 1password.com can change to work differently from Dropbox at any time. 1Password for teams already allows recovery without your mas…

The other major concern would be that you are moving your trust in the security of your data from very large companies that have staff in place to maintain such security as well as an established track record of offering service in the wild to a much smaller company with much less of a track record.

I understand this argument for iCloud, but Dropbox does not have a history of strong security [0] [1] [2]. This doesn't mean that AgileBits is more trustworthy, but it makes sense that they'd prefer to build their own cloud service over relying on Dropbox for the security of their customers' data.

[0] https://www.washingtonpost.com/news/the-switch/wp/2016/09/07...

[1] https://venturebeat.com/2012/08/01/dropbox-has-become-proble... child-of-cloud-security/

[2] https://venturebeat.com/2011/06/21/dropbox-files-left-unprot...

Re: On Password Managers

#192
post #59

More and more, I'm recommending that friends and family get a Mooltipass[1]. It's open source, it works on any platform that supports USB HID (including mobile devices using an OTG cable), it's got multiple browser plugins, and it allows you to have "two factor" auth by seperating the pin-protected crypto key from the device itself using smart cards. The device can be backed up, and the cards can be backed up too (si…

If this thing fit on my keychain, I'd strongly consider it. I can't see carrying a card, a device and two usb cables around, which is what the current form factor seems to require for use with my phone and computer. Maybe a usb key with a screen, bluetooth radio and battery would work.

Re: On Password Managers

#193

Good security hygiene is like a diet or exercise plan: the most effective one is the one you will stick with. Most users don't follow good habits because its a giant pain for non technical users to get set up. 1p's subscription plan is aimed squarely at those people and I think its a great idea. It's reasonably secure and easy to set up everywhere. That is a big deal in my mind. Yes, its not bullet proof but its a 10…

> Additionally, managing your own password vault is a lot like managing your own email server.

As someone who actually does both, this is IMHO backwards. My "password vault" is a GPG file I open in emacs and cut and paste from. It's trivially copied and maintained, extends cleanly to "non-password" secret info (e.g. credit cards, my kids' SSNs), involves no third party systems beyond the operation of the software, is trivially backed up via straightforward file copies that I do all the time anyway, and just in general works better than the rather complicated ecosystem of commercial offerings.

Works poorly in a phone, though.

Re: On Password Managers

#194
post #159
post #82

Earlier quoted context omitted.

For Windows, there is "1Password for Windows" and 1Password 4. I've never used the "for Windows" version, but I believe it's cloud only. 1Password 4 allows local vaults. However 1Password 4 is in maintenance mode and missing lots of nice features, like searching two vaults at once.

I have the Mac and the Windows licenses for 1Password. Windows 1Password 4 is a nightmare to use with its terrible UI and its buggy Chrome plugin integration.

I agree, it's not great. I use it in Linux under Wine. But at least it works, and is definitely better than nothing.

Re: On Password Managers

#195
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

On what planet is this not a concern:

>3. They're promoting cloud vaults and hiding local vaults, and the Windows version of 1Password has apparently never used local vaults.

1Password has absolutely used local vaults since its inception. They STOPPED supporting them in the latest version which is ridiculous, frustrating, and feels like a bait and switch. Had I known that was going to be their tactic going forward I never would've bought version 4 for Windows.

And no, I don't want to hear about how "version 4 still works just fine" - version 4 has all sorts of bugs, on windows 10 frequently hangs for minutes at a time when unlocking the database, and in general looks like it was written as an after-thought.

Re: On Password Managers

#196
post #50

Against all recommendations I reject all password managers. I feel like all security software is eventually compromised, most frequently by business folks as in this case. Instead I use a tiny notebook that I keep in my wallet. I pick long 12+ character passwords myself, not super randomized but I haven't heard of a brute forcing attack in a long time. It allows me to easily meet weird password requirements. I feel p…

Writing them down also happens to be recommended by Bruce Schneier, though I'm not sure what he'd say about how you're using Firefox:

https://www.schneier.com/blog/archives/2005/06/write_down_yo...

Re: On Password Managers

#197

I'm surpised nobody cited lesspass, https://lesspass.com/#/ Nobody store your password it's pure stateless, you can access the software by the official website, your website, web plugin, the terminal see this blog: https://blog.lesspass.com/lesspass-how-it-works-dde742dd18a4

Thank you, I'm always proud when LessPass community talk about my product!

Re: On Password Managers

#198
post #180
post #100

Earlier quoted context omitted.

I use pass, written by zx2c4 of WireGuard fame: https://www.passwordstore.org/ My favorite thing about it is that it uses standard tools I understand, and I can back it up and version it with git.

It doesn't have a browser plugin and will not work with my iPhone... So it's a no-go for me and I guess many others.

I wouldn't let any password manager touch my browser. Giving attackers access to your password manager's APIs via JS or DOM elements is how most (all?) of the dozens of severe LastPass bugs have happened.

Re: On Password Managers

#199
post #81

Earlier quoted context omitted.

> Looking into my configuration, it would appear that AgileBits has silently moved my data from iCloud to the AgileBits cloud How could that possibly happen? Local vaults can't just silently turn into cloud vaults, and you need a subscription license to use cloud vaults anyway.

How could that possibly happen? Local vaults can't just silently turn into cloud vaults, Why not, all they'd have to do is copy the local vault to their cloud service and you'd never notice until you discover that the local file you're syncing somewhere else no longer contains your new passwords. I'm not saying they've done this, but they could.

You're confusing what's theoretically possible with what they're actually doing. You asserted that they did something that they categorically do not do, and are trying to defend it by saying "but they could!".

I don't understand why you're doing this though, unless you're trying to intentionally create FUD around 1Password.

Re: On Password Managers

#200

Just to be clear, it's still 100% possible to keep your 1Password vault in Dropbox etc and not use the SaaS version [1]. I felt like this fact was buried in the article. Edit: Here's the link to buy the standalone license [2] which is hard to find on the site now. In a post from the founder one week ago [3] he said, "We know that not everyone is ready to make the jump yet, and as such, we will continue to support cus…

https://blog.agilebits.com/2016/06/02/1password-6-beta-for-w...

1Password 6 for Windows has been out for a year, and it still doesn't support local vaults. I'm going to consider my own and others skepticism of their commitment to local vaults completely valid.

Post reply on HN