Live data from Hacker News

Notes on the Celebrity Data Theft

nikcub.com

271–280 of 292 posts

Re: Notes on the Celebrity Data Theft

#271
post #74

Earlier quoted context omitted.

This is really easy. You have one good password for 1pass, and one good password for iCloud. If you can manage to memorize one, you can memorize two.

My real problem with this is writing the password with numbers, punctuation and stuff on a mobile keyboard. Feels like surgery even if I'd memorize it. I use 1P on my laptop most of the time so it's not a huge deal. Everything else on the iPhone just remembers credentials. I know I can force myself to use a great password for iCloud but my point is that most of the time, I'd go for an idiot password rather than forci…

This may help, some special characters dump the keyboard back to the primary keyboard, so create a password that is letters, then numbers/specials, then the ' character, then more letters.

for example, pass2'word would only require you to hit the alt-keyboard switch once.

Re: Notes on the Celebrity Data Theft

#272
post #92

Earlier quoted context omitted.

Well, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board). Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to g…

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

Wow, Hacker News really hates the idea of paying a reasonable amount of money for important software?

Edit: And hates being told they hate it. How meta. If you disagree, please leave a comment. Drive-by downvoting does not help anyone.

Re: Notes on the Celebrity Data Theft

#273
post #238

Earlier quoted context omitted.

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

Are you by chance a purchasing manager for a large corporation? Do you feel that signing a $100K-$1M Oracle contract is worth it because "if MySQL or PostgreSQL were worth something, then they would charge you for it?"

Thanks for the straw man and entirely manufactured quote. We're talking about paying $50 for software that manages your passwords for everything, not paying hundreds of thousands to millions of dollars.

Re: Notes on the Celebrity Data Theft

#274

Earlier quoted context omitted.

I'm sure it is useful, except for when 1Password attacks take place.

1Password is not a cloud service.

I didn't say anything about how it is implemented. It is software, there is always a way to attack it.

Re: Notes on the Celebrity Data Theft

#275

Earlier quoted context omitted.

> Unless, of course, the things you are doing on the internet are wrong and misogynistic, in which case people are sending you articles and comments for a reason. Fortunately no one sends me anything like that, they just end up in my news feed as I have many friends involved in feminism/minority movements, and because local media loves to spin everything as gender issues. > Certainly if you are a man who doesn't do t…

> Well, even if one has nothing to worry about personally, it's just tiring and demotivating to see all those broad accusations all the time. sigh You do realize that when people talk about men as a class, that isn't the same thing as a personal accusation, right?

Yes, yes it is. Same as if someone referred to all women as a class. It's not fair to generalize about all women. It's not fair to generalize about all men. If you refer to men as a class, you're inherently being just as unfair as if you do the same to women.

Re: Notes on the Celebrity Data Theft

#276
post #239

Earlier quoted context omitted.

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

IMHO, the license is not really the big question for this type of software. The most important thing is the competence of the team(s) who wrote and audited the software.

Exactly. I love open source software and use (and contribute to) it all the time, but the sad fact is that, despite the "many eyeballs" claim, most open source software is very rarely audited. I am willing to believe that KeePass is in fact implemented well and safe to use, but I don't actually know anything about the developer(s) behind it, don't know anything about the future development of the software (will it still be the same developers? Will new unknown people start contributing? etc), and pretty much the only thing that the developer(s) stand to lose by screwing up is reputation.

On the other hand, AgileBits (makers of 1Password) is a company, with actual money on the line (in addition to reputation) serving as an assurance that the product will not only continue to be developed, but will remain secure.

If KeePass screws up, some reputation is lost, people may switch to another product, and the developer(s) can just move on to working on other software if KeePass can't be salvaged. If AgileBits screws up, not only is reputation lost, but so are paying customers, depending on the severity the entire company might go belly-up (e.g. if 1Password is compromised heavily enough that it can't be trusted anymore), a lot of people are suddenly out of a job, etc. Basically, there's a lot more at stake for AgileBits, which makes it much easier to trust that not only are they going to do their job right, but they're also going to have processes in place to ensure a build never gets released externally that doesn't pass QA, etc.

And don't forget that as a paying customer of AgileBits, I can get support from them for any problem I might be having. Open source projects don't typically employ support personnel, and generally rely on the community to try and provide whatever support they can.

---

Ultimately, this comes down to the fact that this is a specialized class of software, where one breach can mean irreparable damage as the attacker now has access to your passwords for everything. For that kind of software, I really want the backing of a company, with a significant amount to lose, rather than just some unknown collection of open source developers.

Which is to say, for nearly any other class of software, I'm much more inclined to judge it based on its merits, and open source has a lot of advantages. But this isn't any other class of software.

Re: Notes on the Celebrity Data Theft

#277
post #196

Earlier quoted context omitted.

Free as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.

Why do you assume paid software is more reliable?

See this other comment I just posted: https://news.ycombinator.com/item?id=8264450

Re: Notes on the Celebrity Data Theft

#278

I use a Yubikey with a generated key. This is only half of my password; the first part is a password I can remember easily with numbers and letters, the second is the generated key. This means that even I don't really know my password and if someone found my Yubikey then it's useless to them without the other half that only I know. (I do have a printout in a safe place of the key and also a backup Yubikey) I use this…

Same here on halfsies, I use YubiKey Static + 2FA http://www.yubico.com/products/yubikey-hardware/lastpass-yub... plus a Password card https://www.passwordcard.org/en both for 1Password and LastPass

I like 2FA on LastPass but the UX is better on 1Password

For files like my Tiddlywiki http://tiddlywiki.com/, I like Minilock https://minilock.io/ with BTsync https://github.com/tuxpoldo/btsync-deb

i admit i'm lazy and have less secure login creds in my Tiddlywiki but at least it has some crypto https://crypto.stanford.edu/sjcl/

Re: Notes on the Celebrity Data Theft

#279

Earlier quoted context omitted.

I'm not sure if it's completely fair, but everytime I see "security questions" I can't help think: "Oh, it's an American site". Silly "security" questions about mothers, dogs and favorite teachers seems to be cultural to the US (and maybe Canada), why is that?

The whole "mother's maiden name" thing is pretty popular in US banks. I'd wager this is where it came from. Then again, you are talking about a country where the only thing people need to steal your identity is your ... social security number. Brilliant.

Stealing the social security number in Denmark is just as bad and possible easier than in the US. If you know a persons birthday and gender you have at least a 1 in 500 chance of simply guessing the last four digits.

Re: Notes on the Celebrity Data Theft

#280
post #239

Earlier quoted context omitted.

IMHO, the license is not really the big question for this type of software. The most important thing is the competence of the team(s) who wrote and audited the software.

Exactly. I love open source software and use (and contribute to) it all the time, but the sad fact is that, despite the "many eyeballs" claim, most open source software is very rarely audited. I am willing to believe that KeePass is in fact implemented well and safe to use, but I don't actually know anything about the developer(s) behind it, don't know anything about the future development of the software (will it st…

Won't complain FOSS/OSS has its drawbacks, but everything has two sides.

I might be a strange case, but I just have this feeling "real" companies spend their $$$ on meetings in Bahamas and Ferraris, while FOSS/OSS would be more open to security audits/etc.

A company with money on the line can (also) easily be shut down or aquired. I imagine a FOSS/OSS team would be demanding more guarantees for the future of the project, while "in it for the money" companies would take the check and not give a damn if it was shut down the same day.

"Real" companies often seem to push releases/features (prematurely?) to attract new customers. That the new features pass review/QA doesn't necessarily mean they are implemented right (goto fail?). In addition FOSS/OSS have public bug trackers, I'd rather know there are x number of bugs labeled "security" in my os, than not beeing told at all.

Support can (should?) be where open source make money, there are lots of FOSS/OSS projects out there offering paid support/installations/sass.

And the unknown collection of open source developers _may_ be a much better collection of security specialists/coders than in the "real" company. As most of FOSS/OSS is done voluntarily you don't have to pay huge paychecks for top of the line expertise.

Bottom line, I trust Debian (& co) and Mozilla. I don't trust Microsoft, Apple and Google.

This is 100% biased as to what I think. I understand that this is a two sided issue, and fully understand people who think like you sketched out. I'm just not one of those people :P

Post reply on HN