Live data from Hacker News

On Password Managers

tbray.org

211–220 of 347 posts

Re: On Password Managers

#211

Any password manager recommendations such that people don't need to deal with 1Password's cloud-based storage?

I recall seeing some domain-hashing solution on hackernews some months back, and built https://gist.githubusercontent.com/bradbeattie/c688e567e8564... in response. It's been working pretty well for me.

    $ ./pgen.py foobar.com foobar.net foobar.org
    Password? 
                    foobar.com: Aa0$d8~04h4W}Oj-MWA5  Aa0$eaxxF4XzaDaOnx5o
                    foobar.net: Aa0$q;7uc=@(4nSS5PIF  Aa0$pG5+6ekXTONYJXrE
                    foobar.org: Aa0$%YY$Dle*&(egUuL1  Aa0$y4AhSpO64xF+Aa/l

Re: On Password Managers

#212
post #160

Earlier quoted context omitted.

I have it and it's terrible IMO.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

Did they add OTP support to version 4 of the windows client? Last I saw it was not supported, so it was not super useful to me.

Re: On Password Managers

#213

Earlier quoted context omitted.

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cl…

Have you put much energy into making sure that Enpass is secure? Do you know who's reviewed it, and what their review looked like? It bothers me when people point to other password managers as alternatives to 1Password because of packaging and pricing issues. It's easy to find other commercial password managers that have attractive packaging and pricing! That's not the hard part! I happen to like 1Password as a produ…

Since neither of them are open source, I haven't put energy into making sure either of them is secure. Not being a security researcher or having access to either product's code, I'm not sure how I could be expected to perform that level of evaluation, but I've built systems that have passed security reviews and, from a non-privileged access point of view, I see little difference between the two. Enpass does seem to handle security incidents in a pretty responsible fashion. They post blog updates on vulnerabilities (e.g. https://www.enpass.io/blog/an-update-on-the-reported-vulnera...) after releasing fixes. It's great that you recommend 1Password based some other criteria, but I'm not sure why your recommendation should mean anything to me unless you've been given some privileged access to their code that the rest of the world doesn't have and if you have been given that type of access, it's irresponsible of you to denounce other products unless they've denied you similar access.

What I can see is that 1Password is pushing users towards a model that's fundamentally insecure. Their web-based products require a level of trust in 1Password (the company) that none of us should be willing to place in any company. What we've learned from Snowden is that any cloud provider can be secretly made to bend to their governing body's will. Running closed-source software on our own computers involves a level of trust in the authors of that software. That's just a fact of life when software isn't open source. But when code is pushed out into the world, it can, at least, undergo some scrutiny/testing by people outside the company. This is not true of software running on the company's servers. In so much as the security of 1Password requires executing a single, line of code on servers controlled by 1Password, the product is insecure and fundamentally unauditable because that line of code can be changed at any time without users being made aware.

The other point that should probably not get lost is that we're dealing with levels of security. In advocating for password managers, the interface absolutely does matter. Most computer users haven't adopted any password manager yet. When comparing a secure but difficult to use password manager, a potentially insecure password manager with an easy-to-use UI and a combination of insecure passwords, post-it notes and all the other terrible ways that users have of "managing" their passwords, the middle ground is likely to come out ahead for all but the most technically adept users. Need proof? PGP/GPG passes security reviews but has terrible UIs...what percent of emails are PGP/GPG encrypted? We shouldn't let the perfect be the enemy of the good. There can be different classes of security products for those that need protection from state-level actors and those that don't. Because people who are worried about that level of attack are generally willing to undergo a lot more pain to stay secure than your average user is.

Re: On Password Managers

#214

Earlier quoted context omitted.

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cl…

Have you put much energy into making sure that Enpass is secure? Do you know who's reviewed it, and what their review looked like? It bothers me when people point to other password managers as alternatives to 1Password because of packaging and pricing issues. It's easy to find other commercial password managers that have attractive packaging and pricing! That's not the hard part! I happen to like 1Password as a produ…

> Have you put much energy into making sure that Enpass is secure? Do you know who's reviewed it, and what their review looked like?

I'd really like to know this as well.

I'm aware that LastPass doesn't have a perfect security record, but because of its prominence it gets lots of attention from hackers and security researchers, security issues tend to be well-reported, and the responses to them seem to be reasonably transparent and proactive.

In contrast, Enpass appears to be a side-project of a small app development house in India. Did a miss a memo where Security Expert X said Enpass is better than LastPass?

Re: On Password Managers

#215
post #195
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

On what planet is this not a concern: >3. They're promoting cloud vaults and hiding local vaults, and the Windows version of 1Password has apparently never used local vaults. 1Password has absolutely used local vaults since its inception. They STOPPED supporting them in the latest version which is ridiculous, frustrating, and feels like a bait and switch. Had I known that was going to be their tactic going forward I…

I thought I was going crazy fighting with their staff about the existence of this bug.

It makes it maddening trying to get on a website, and having to wait for the vault. Input queues up in the meantime, meaning I can't click or type on other things. Then suddenly, my mouse will shoot around the screen and my characters will get typed to wherever I was.

Re: On Password Managers

#216
post #13

Earlier quoted context omitted.

That's what I use as well. Only thing missing I guess is a mobile workflow, though there are some options.

We use https://www.pwsafe.org/ . It has clients for android, iOS and windows. In Mac and Linux you can use password-gorilla with the same files. And sync with dropbox.

There are other clients such as iOS and MacOS by App77 -- is there any validation of that companies implementation of pwSafe?

Re: On Password Managers

#217

Earlier quoted context omitted.

You can do that, but those local vaults aren't part of the team/family.

"You can do that, but those local vaults aren't part of the team/family." Yes, this is correct. So if you want to share items or share a vault with a family member, you are obligated to store and sync with 1Password servers.

Well, you can use third-party syncing with local vaults to sync with family members, e.g. using Dropbox sync with a Dropbox shared folder to share your vault with a family member. This just doesn't fall under the heading of "team" or "family" syncing.

Re: On Password Managers

#218

I use Enpass on Linux, Windows, OS X, Android, and iOS. I also use the Chrome extension. It has a similar user experience to 1Password, but is actually serverless (you sync your encrypted blob to a cloud service of your choice, or not at all). I wish Enpass were open source, but I can understand their decision not to make it so -- its desktop application is free and its mobile apps include a small perpetual license f…

I can definitely endorse Enpass as a great product. I never used to believe in password managers but the past year has made a believer of me. I had the passcode to our garage door stored as an encrypted note and ended up getting home for ElixirCon via a late night Uber and rather than wake up the family, I looked it up in Enpass, keyed it and and it was perfect. I have it on all my Macs, my iPad and iPhone and sync v…

Agree. I switched over from 1Password when it became evident they would never have a Linux client. Been using Enpass and it works a dream syncing between various OS with a very nice UI quite similar to 1P.

Re: On Password Managers

#219
post #193

Good security hygiene is like a diet or exercise plan: the most effective one is the one you will stick with. Most users don't follow good habits because its a giant pain for non technical users to get set up. 1p's subscription plan is aimed squarely at those people and I think its a great idea. It's reasonably secure and easy to set up everywhere. That is a big deal in my mind. Yes, its not bullet proof but its a 10…

> Additionally, managing your own password vault is a lot like managing your own email server. As someone who actually does both, this is IMHO backwards. My "password vault" is a GPG file I open in emacs and cut and paste from. It's trivially copied and maintained, extends cleanly to "non-password" secret info (e.g. credit cards, my kids' SSNs), involves no third party systems beyond the operation of the software, is…

Read what you wrote one more time, and imagine some manager working in a bank, or a 17 year old business student.

It's hard enough to convince people not to use the same e-mail and password combo, and instead use something like 1password or last pass, making them use your proposed "solution" would be a massive step back.

Re: On Password Managers

#220
post #193

Good security hygiene is like a diet or exercise plan: the most effective one is the one you will stick with. Most users don't follow good habits because its a giant pain for non technical users to get set up. 1p's subscription plan is aimed squarely at those people and I think its a great idea. It's reasonably secure and easy to set up everywhere. That is a big deal in my mind. Yes, its not bullet proof but its a 10…

> Additionally, managing your own password vault is a lot like managing your own email server. As someone who actually does both, this is IMHO backwards. My "password vault" is a GPG file I open in emacs and cut and paste from. It's trivially copied and maintained, extends cleanly to "non-password" secret info (e.g. credit cards, my kids' SSNs), involves no third party systems beyond the operation of the software, is…

Nothing wrong with what your are doing if it works for you, but I wouldn't describe your workflow as trivial, and I wouldn't call using Password complicated. The value to me of 1Password is: Go to Website, Right click 1Password, enter password, logged in. No copy paste, no switching windows, no launching emacs, no searching through a list. Even the added friction of 1Password took a few starts and stops to get through. For people like me, your solution would quickly devolve into reusing a common password.

The 1Password workflow on iOS is more similar to what you describe because there is no browser integration, and I strongly dislike the experience. I often will abort doing things on mobile so I don't have to bother app switching and copy pasting.

Post reply on HN