Live data from Hacker News

Backdoored password manager stole data from as many as 29K enterprises

arstechnica.com

31–40 of 117 posts

Re: Backdoored password manager stole data from as many as 29K enterprises

#31
post #13
post #4

Why would any "enterprise" customers trust closed sourced AND small-time password manager?

It seems to me there's a trend around "enterprise" software having weaker supply chains than the more nimble and agile tools. Perhaps mindset related? Larger teams needed to meet enterprise needs? Or simply more focus on the sales machine to close complex enterprise deals, and less focus on securing the pipeline through which the product is made? Solarwinds is a great example of this - "big enterprise software" used…

> It seems to me there's a trend around "enterprise" software having weaker supply chains than the more nimble and agile tools.

Or enterprise tools are a more attractive target for attacks. Due to that they should be better at this, so still shame on the slack ones.

Re: Backdoored password manager stole data from as many as 29K enterprises

#32
post #18

That's why I don't use password managers. That's giving one entity too much power over everything I own.

Do you simply remember hundreds of random passwords?

In my case, the most critical passwords are memorized and are not stored in any other medium after the brief period that it takes to memorize it. Simply put, I saw a breach like this coming and I anticipate many more in the future. Simply put, password managers are too big of a target.

As for the rest, a written record is sufficiently secure since most of those login credentials aren't protecting anything important. I also have a tendency to avoid services that require a login.

Re: Backdoored password manager stole data from as many as 29K enterprises

#33
post #13
post #4

Why would any "enterprise" customers trust closed sourced AND small-time password manager?

It seems to me there's a trend around "enterprise" software having weaker supply chains than the more nimble and agile tools. Perhaps mindset related? Larger teams needed to meet enterprise needs? Or simply more focus on the sales machine to close complex enterprise deals, and less focus on securing the pipeline through which the product is made? Solarwinds is a great example of this - "big enterprise software" used…

IME enterprise software is chosen very poorly in general. Microsoft wouldn't be nearly as large now if it weren't for this.

Re: Backdoored password manager stole data from as many as 29K enterprises

#34

That's why I never used and will never use a password manager... You can't get more security by trusting more intermediaries with your passwords. When it comes to anything that matters, you want to trust as few intermediaries as possible. The more entities have access to your passwords, the less secure you are. I can't believe I even have to say it, it seems so obvious. Why not just remember your passwords? There is…

If you think the concept doesn't make sense, consider that you do not understand it. Highly respected people whose entire careers is security will disagree with you. I'm not telling you to take an argument for authority, but maybe do some introspection about who is more likely to be correct there... Edit: Parent comment edited out some really outrageous claims, so my reply no longer makes as much sense.

Of course security folks who stand to profit from selling these password management solutions will insist that these solutions are important... After all, like you say, their whole career depends on selling 'security products' to companies and individuals. This kind of argument would never stand up in court because of conflict of interests.

About the edit, the meaning of my comment hasn't changed. I just removed the phrase "the concept doesn't make any sense" and expanded it to explain why it doesn't make any sense... It's dishonest to say that I've made an outrageous claim or changed the meaning of the comment in any way.

But it's good that expanding my reasoning has led you to reconsider the validity of your argument.

Re: Backdoored password manager stole data from as many as 29K enterprises

#35
post #12
post #10

Earlier quoted context omitted.

That's like saying that seatbelts don't help very much, unless you're willing to wear a motorcycling helmet, and install a roll cage in your car. In the worst-case scenario, no, your seatbelt won't help. I'm still going to wear one.

The difference is that the interior of your car is not typically an adversarial environment.

The exact moment that you need a seatbelt is the same moment your car's interior becomes an adversarial environment.

Re: Backdoored password manager stole data from as many as 29K enterprises

#36
These days I generally don't trust any security product. They are as much malware themselves as the malware which they claim to protect you from.

- Many security software providers are hackers or ex-hackers... So you're basically paying hackers to protect you from themselves. Why should I trust software which is almost 100% guaranteed to have been written by hackers more than any other random software I might download from the internet which has maybe a less than 1% chance of having been written by a hacker?

- The software security industry is more about selling security products than actually helping to keep people and companies secure. The incentives are to sell peace of mind while keeping systems vulnerable (don't kill the goose that lays the golden eggs).

- Most security products capitalize on fear rather than genuine threats (security tools tend to show lots of false positives to draw attention to themselves or to upsell additional software).

Re: Backdoored password manager stole data from as many as 29K enterprises

#37
post #18

That's why I don't use password managers. That's giving one entity too much power over everything I own.

Do you simply remember hundreds of random passwords?

It's easy. Just come up with a secret rule and derive the passwords from that rule such that the password is different for each website/service.

Re: Backdoored password manager stole data from as many as 29K enterprises

#38

Earlier quoted context omitted.

If you think the concept doesn't make sense, consider that you do not understand it. Highly respected people whose entire careers is security will disagree with you. I'm not telling you to take an argument for authority, but maybe do some introspection about who is more likely to be correct there... Edit: Parent comment edited out some really outrageous claims, so my reply no longer makes as much sense.

Of course security folks who stand to profit from selling these password management solutions will insist that these solutions are important... After all, like you say, their whole career depends on selling 'security products' to companies and individuals. This kind of argument would never stand up in court because of conflict of interests. About the edit, the meaning of my comment hasn't changed. I just removed the…

> But it's good that expanding my reasoning has led you to reconsider the validity of your argument.

What I meant is that my first sentence, which references something you removed from your original comment, sounds very out of context now.

And no, none of the folks I'm thinking of actually make money from password management solutions. Your comment sounds the same as "of course all those doctors would recommend getting vaccinated since they make a profit from selling you the vaccines".

Please, just stop.

Re: Backdoored password manager stole data from as many as 29K enterprises

#39

Earlier quoted context omitted.

If you think the concept doesn't make sense, consider that you do not understand it. Highly respected people whose entire careers is security will disagree with you. I'm not telling you to take an argument for authority, but maybe do some introspection about who is more likely to be correct there... Edit: Parent comment edited out some really outrageous claims, so my reply no longer makes as much sense.

Of course security folks who stand to profit from selling these password management solutions will insist that these solutions are important... After all, like you say, their whole career depends on selling 'security products' to companies and individuals. This kind of argument would never stand up in court because of conflict of interests. About the edit, the meaning of my comment hasn't changed. I just removed the…

Who stands to profit from FOSS, self-hosted password management solutions (e.g. Keepass) then?

Generating long, high-entropy, unique passwords and then not relying on your brain to remember (and your fingers to type) is always going to be more secure than doing it the hard way for its own sake.

Re: Backdoored password manager stole data from as many as 29K enterprises

#40

These days I generally don't trust any security product. They are as much malware themselves as the malware which they claim to protect you from. - Many security software providers are hackers or ex-hackers... So you're basically paying hackers to protect you from themselves. Why should I trust software which is almost 100% guaranteed to have been written by hackers more than any other random software I might downloa…

There's a distinction between "protection" security software such as antiviruses and VPNs which indeed is an industry filled with scams and conmen, and utility security software such as password managers.

Most of the big name password managers are very good. The only one I'd recommend avoiding is lastpass, and even so they're not that bad, just strictly worse than the others.

Emphasis on big name. 1Password, Bitwarden, keepassx(c), and whatever microsoft's was called.

Post reply on HN