Live data from Hacker News

Ask HN: Why should I trust password managers?

news.ycombinator.com

191–200 of 289 posts

Re: Ask HN: Why should I trust password managers?

#191

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

1password does this unless I'm misunderstanding your post.

Re: Ask HN: Why should I trust password managers?

#193

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

Apple keychain?

Re: Ask HN: Why should I trust password managers?

#194
post #191

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

1password does this unless I'm misunderstanding your post.

Yes! As far as I'm aware the "cloudy" password managers all do it.

Re: Ask HN: Why should I trust password managers?

#195

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

> Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. The Bitwarden browser extension does this. When you add a login, it also adds the URI of the website, so the login info and auto-fill will only show up when you're on the same domain. Of course you can edit and add or remove your own URI…

Yes, and this is what I use.

Re: Ask HN: Why should I trust password managers?

#197
post #187

Well, if one's using a Mac and iCloud one already trusts Apple. so no additional trust needed to use iCloud Keychain I guess.

not wise. you're giving apple way too much power over you. imagine if your account is revoked one day.

That's why I like Apple's approach of local backups. Nothing is exclusively in the cloud alone, it's only backed up to cloud. Everything I care about, I can access it locally with no internet, including all old photos, files, chats, mails, passwords pretty much everything.

Re: Ask HN: Why should I trust password managers?

#199

Earlier quoted context omitted.

1Password has raised almost $1B. Surely they could put at least $1M toward a critical bounty?

Depends on the cost/benefit. 3x security engineers to detect/respond vulns and attacks is less expensive but gets similar coverage plus a lot of other work capacity, for instance.

1M allocated to this bug bounty is 1M not spent if their security is strong enough.
Post reply on HN