Live data from Hacker News

Ask HN: Why should I trust password managers?

news.ycombinator.com

211–220 of 289 posts

Re: Ask HN: Why should I trust password managers?

#211
post #29
post #22

Earlier quoted context omitted.

You could use a different password for each service and just write them in a paper notebook. Paper is generally not susceptible to malware or other ways passwords can leak from a local or hosted password manager.

But now your password manager (notebook) is vulnerable to fire and water damage, with no backup or recovery options.

I use a copy machine to back up my password list. The pages go in my fire safe with other important papers, and a second copy off-site.

I guess you could just take pictures of the pages and save them to a thumbdrive or an SDcard, but I prefer the lower-tech solution.

Re: Ask HN: Why should I trust password managers?

#212
post #68

I don’t trust or use SAAS password managers. They are massive honeypots just waiting to be pwned and everyones’ passwords to all their websites stolen. They have above average security, but unlike a typical website they can’t just store a one-way hash of passwords that remains secure even when stolen, they have to store the actual password. I imagine nation state-supported malicious hackers are targeting them. Everyt…

I do the same thing but worry about a nation state or rich enough hackers to just take over the project and add nefarious code. I’ll never audit the code and make sure it produces the binary I get from the Apple store. So I’ve started adding my own “salt” - I type an extra character or two (same for all passwords) to the end of every password I enter. It’s the easiest way to protect against not being able to trust my…

If the hacker can decrypt your whole password safe and view all your plaintext passwords, I think they'll work out your scheme.

Re: Ask HN: Why should I trust password managers?

#213
post #92

Earlier quoted context omitted.

That is correct and they apparently have the audits to prove it. That said, it's not bulletproof. The chink in the armor is the browser extensions they all use. All it would take is somebody to slip some trojan code into one of the browser extensions and all of the sudden you have a few hundred million decrypted password databases which could trivially be uploaded to wherever.

Could you not argue the same thing for almost any code used by almost any piece of software closer to the metal? e.g. someone manages to slip malicious code into Chrome/Chromium which eventually makes its way out to every Electron app/most browsers, or something gets injected into Windows/macOS/Linux, etc.

The likelihood of malicious code making its way into a browser extension in production is way, WAY higher than it is for something like Chrome or Windows.

Re: Ask HN: Why should I trust password managers?

#214
Your decision here is based on balancing security and convenience. It's a tradeoff that you have to decide on based on your situation.

Most average users are willing to trade the upside of the SaaS apps (sync is easy and pretty secure) for the downside (have to trust a third party like 1Password, that they won't send you a malicious client that slurps your master password).

We're technical, so we can use Password Store[0] and avoid the downside of the SaaS programs (have to trust a third party) while still having sync. If you're pissing off entities who might conceivably blackmail or hack 1Password, Password Store is the bare minimum.

[0] I'm not addressing that Password Store doesn't encrypt the sites it has logins for, just the fact that it doesn't require entering your master password in a web page.

Re: Ask HN: Why should I trust password managers?

#215

Earlier quoted context omitted.

> Because it'll only offer passwords for sites that match the entry, defaulting (most often) to being the same domain, if you come across a phish then it won't offer the site at all. The Bitwarden browser extension does this. When you add a login, it also adds the URI of the website, so the login info and auto-fill will only show up when you're on the same domain. Of course you can edit and add or remove your own URI…

Yes, and this is what I use.

I'm sorry, I misread your first sentence and thought you were saying you hadn't seen any password managers that defend against phishing. My bad!

Re: Ask HN: Why should I trust password managers?

#216

Earlier quoted context omitted.

This kind of dependence sometimes scares me to be honest, not that password dependent services have left much choice to us.

I store the printed credentials to my password manager and my e-mail account in a safe deposit box (without mentioning on that paper what the codes are for). Then I store a YubiKey which is a second factor to these accounts in another safe deposit box in another location. So should I forget my master password: drive to box 1. Should my house with all my computers burn down: drive to boxes 1 and 2, find a pc or phone…

Could you help me understand, that if you are this considerate and comprehensive about your risk factors and prepared at all sorts of possibilities, why still use a password manager solution that can "go bankrupt overnight and take my vault with them"? Why not just use KeePass and manage the vault yourself? If your answer is "I only need to do these safe box things once", then writing your own scripts to sync KeePass database between your devices is also only needed done once, right? Even if it's more hassles, considering you will never have the last 3 bullets listed, isn't that worth the trouble?

Re: Ask HN: Why should I trust password managers?

#217

Earlier quoted context omitted.

I agree with everything you've written here, but while all good points, they're really more about convenience -- not trust. _Why_ do you trust Bitwarden? I also use BW btw, but I don't have a good reason as to why they're trustworthy, and will probably run my own server someday.

Because it’s a crime for them to make use of the passwords, and I’d be able to claim back any financial loss. I picked Bitwarden because it’s widely trusted, it’s trusted because it’s open source and widely assumed to be casually audited by many _other_ people. There’s a weak point here in how many of us are relying on others to do the audit, in a bystander effect sense. I don’t think either of these are BW specific,…

But so is wordpress. Open source and a lot of eyes can find bugs but not everyone reports

Re: Ask HN: Why should I trust password managers?

#218
post #34

https://www.passwordstore.org/ gpg "make-key" mkdir -p ~/.passwordstore/foo/bar echo "hunter2\nusername: hunter@hunter.com\n" \ | gpg "sign" > ~/.passwordstore/foo/bar/entry.gpg gpg "decrypt" ~/.passwordstore/foo/bar/entry.gpg tree ~/.passwordstore/ -- Basically, "passwordstore" is pretty trustworthy, open source, reasonably inspectable, and kindof automates the above steps in a decent CLI (and has a nice git integra…

In addition, plasma-pass, qtpass, android password store (https://github.com/android-password-store/Android-Password-S...) are nice as well. Throw in a NFC Yubikey and OpenKeychain on android, then you can lock them with hardware keys. Since pass uses git, syncing can be done to a private repo on your home network or even just a cheap usb stick.

Re: Ask HN: Why should I trust password managers?

#219
post #165
post #41

I will tell you a good reason to trust password managers. I know a lawyer who does estate planning. When you start talking about "what happens when I die", passwords are a class of problem that has only gotten worse in the last 2 decades. There are legal ways for estate executors to request passwords, but it is a pain, and can be time consuming. She tends to recommend password managers because they tend to be more co…

I'm pretty sure even after death, it's still technically breaking the law to use someone else's password. So I'm surpised a lawyer would be so open about it, though I agree it definitely makes life 90% easier when it comes up :)

Yeah, I can't think of many reasons why an executor would need the passwords of the deceased. Banks and other financial institutions have a protocol for this: send them the death cert, and they distribute to beneficiaries or as directed by law. There's no need to log in as that (dead) user, and it could make things complicated if withdrawals or transactions are made that go against the beneficiary rules.

Maybe you need the password for crypto wallets, but that's on the deceased for not thinking of another plan.

Re: Ask HN: Why should I trust password managers?

#220

Earlier quoted context omitted.

I sort of fall into the second category, except I don't sync passwords across devices or even store them at all. I generate them on the fly with [1]. [1] https://chrome.google.com/webstore/detail/hashpass/gkmegkoip...

How does this work with sites that have absurdly strict password requirements? i.e. 8-16 characters, 3+ letters (1+ of which is upper case), 2+ numbers, 1+ special characters (from their curated list only!) I've seen a few financial related sites have requirements like these, and with a typical password generator I can just click 'generate' until one pops out that meets the reqs, and save it.

For those sites, I usually just add whatever characters are needed to satisfy the requirements to the generated password (e.g., 0). This is annoying, since I have to keep track of which sites required such amendments. Fortunately, the majority of websites I use don't have such annoying requirements. And if I ever forget which sites have "amended" passwords, it's easy to find out simply by attempting to log in and being denied entry (in other words, I can brute force my way in).

Despite this awkwardness, I think this approach is worth it. I only have to memorize one password, and yet I still have a different password for every website. And if the Chrome extension ever gets shut down (*), the algorithm is simple enough to recreate in 4 lines of Python:

    bits = (domain + '/' + universal_password).encode()
    for i in range(2 ** 16):
        bits = hashlib.sha256(bits).digest()
    generated_password = base64.b64encode(bits).decode()[:16]
(*) I am the author of that Chrome extension, so I personally am not worried about it being shut down. But it is perfectly valid for other people to have that concern, of course.
Post reply on HN