Live data from Hacker News

Ask HN: Why should I trust password managers?

news.ycombinator.com

201–210 of 289 posts

Re: Ask HN: Why should I trust password managers?

#201

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

I agree with everything you've written here, but while all good points, they're really more about convenience -- not trust. _Why_ do you trust Bitwarden? I also use BW btw, but I don't have a good reason as to why they're trustworthy, and will probably run my own server someday.

If I'm accessing my passwords via the clients that BitWarden the company distributes, then I'm still putting my trust in the company. Where the encrypted data is stored is in many ways less important.

And the irony is that the one website I can't trust my password manager to protect me from phishing attacks on is the password manager's own web interface. So I always want to log in with one of the non-web clients, and only trust the web vault if I reached it via a known-good link (like the one in the settings panel of the browser addon and mobile apps).

Re: Ask HN: Why should I trust password managers?

#202
post #193

Something I've not seen come up yet: a password manager that's integrated with your browser is a good defence against phishing. Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. This is fairly similar to the "trust on first use" that SSH gives you, which some folk were wishing might have…

Apple keychain?

If I were an Apple ecosystem person, certainly.

Re: Ask HN: Why should I trust password managers?

#203
post #92

Earlier quoted context omitted.

That is correct and they apparently have the audits to prove it. That said, it's not bulletproof. The chink in the armor is the browser extensions they all use. All it would take is somebody to slip some trojan code into one of the browser extensions and all of the sudden you have a few hundred million decrypted password databases which could trivially be uploaded to wherever.

Could you not argue the same thing for almost any code used by almost any piece of software closer to the metal? e.g. someone manages to slip malicious code into Chrome/Chromium which eventually makes its way out to every Electron app/most browsers, or something gets injected into Windows/macOS/Linux, etc.

>Could you not argue the same thing for almost any code used by almost any piece of software closer to the metal?

You could. But if you haven't trusted all/most of your passwords to any single app, you wont have a problem with them being exposed when that particular piece of software is compromised.

Even if someone compromises your OS itself, you'll only lose the passwords you typed in while you were using it compromised. And that's if it does captures thoses, and if it sends them to some remote endpoint, and if it's not caught soon, and so on.

With a password manager compromised, on the other hand, you could loose anything you've put it in, all at once.

Re: Ask HN: Why should I trust password managers?

#205
post #28

I'm surprised by so many of the comments here out-of-hand dismissing or denigrating any password manager that stores data in the cloud. There are ways to store data securely, one of the simplest methods is to do zero-knowledge encryption of that data by way of key-generation from a password only the user knows at the time of decryption. This is essentially how the vault functionality of most password managers work, w…

The safety of ciphertext stored in the cloud is entirely dependent on the lack of state level actors interfering in encryption research, cipher engine design, chip manufacture, operation of cloud hardware, and day to day safety of cloud operator employees.

The USA has been shown to be quite willing to violate all those conditions: NSA directly influencing cipher design, interfering with chip manufacture, seizing hardware wholesale, and engaging in “enhanced interrogations” in attempts to extract information.

The threat level of this state action is 100% because they aren’t going o spend all that time and money on these tools and not use them. They aren’t focussed on cracking your password, they just crack everyone’s because that is easier to automate (see prior discussion regarding weakening encryption to suit the tools the TLAs already have access to).

At least with my secrets stored on my hardware I have the assurance that the TLAs will need to be targeting me directly in order to obtain my secrets (much less likely than getting caught up in a dragnet).

Re: Ask HN: Why should I trust password managers?

#206
post #130

Earlier quoted context omitted.

I suspect that’s not nearly enough, given that their breached database would probably sell for multiple orders of magnitude more on the darknet. Should probably be $1M at least.

1Password vaults are encrypted end-to-end, their database would not be worth nearly that much. It's a bunch of worthless data. A successful hack of 1Password would probably require pushing bad client updates. Besides which bug bounties are not really intended to disincentivize people from committing crimes, they're intended to incentivize researchers to report findings and reward them for their efforts.

>1Password vaults are encrypted end-to-end, their database would not be worth nearly that much. It's a bunch of worthless data.

Doesn't matter for our case, since it already assumes the database potentially compromisable. The parent's comment concerned whether the "bounty for capturing a flag inside a publicly available encrypted vault" is enough. So the question is not whether the bounty is enough given it's impossible to win, but whether it's enough given it might be possible to win.

In other words, whether someone who finds an exploit to decrypt the vaults contents would get a better value by (a) revealing it to 1Password company and taking the $100K bounty, or (b) selling the exploit to people who would give millions to be able to decrypt other's vaults...

Re: Ask HN: Why should I trust password managers?

#207

Earlier quoted context omitted.

1Password has raised almost $1B. Surely they could put at least $1M toward a critical bounty?

Depends on the cost/benefit. 3x security engineers to detect/respond vulns and attacks is less expensive but gets similar coverage plus a lot of other work capacity, for instance.

What cost? There is literally zero cost.

Unless a successful attack actually occurs, in which case it's literally almost priceless in terms of their reputational damage, unless they can get their hands on it before someone else.

Re: Ask HN: Why should I trust password managers?

#208
post #153

Earlier quoted context omitted.

> because it’s a company that happily makes money from that trust You could also say this about Microsoft, except they've been breaking such trust for a long time.

That's a pretty obviously bad take. You're comparing a company whose single product is about keeping one kind of thing secure, and another company that makes dozens of products, most of which don't explicitly have to do with security.

I’m not an expert by any means but I have a layman sense that keeping Windows safe is a way more gargantuan task than keeping an encrypted vault safe inside my computer (before 1password moved to this cloud nonsense to milk subscription money).

If my windows is compromised no amount of tech wizardry can protect my 1password credentials.

Re: Ask HN: Why should I trust password managers?

#209

Earlier quoted context omitted.

That is terribly low for such a critical issue. There are Ethereum L2s that pay out $2M bounties. https://twitter.com/saurik/status/1491821215924690950

That's a bad analogy, although you point out a possibly good thing for L2/crypto - the bug bounties are massive because the projects have a silly amount of funds. Password managers don't operate with those economic models though.

Password managers unlock hot wallets, and much more besides.

Re: Ask HN: Why should I trust password managers?

#210

Earlier quoted context omitted.

That's a bad analogy, although you point out a possibly good thing for L2/crypto - the bug bounties are massive because the projects have a silly amount of funds. Password managers don't operate with those economic models though.

1Password has raised almost $1B. Surely they could put at least $1M toward a critical bounty?

Agreed!

In fact, I'd argue that, if they are positing that the reputational risk for a successful hack exceeds 10% of their notional valuation, then they should try to commit at least 10% of their market cap as insurance against that ever happening, or at least if they would gain enough information to prevent this from ever occurring. This isn't that hard to figure out.

The best thing about that insurance is that it's literally free -- they never have to pay out unless the event actually occurs.

Post reply on HN