I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.
Bitwarden is great, but I'm getting frustrated at their ridiculous excuses for not implementing fixes. For the longest time bitwarden has been broken in the firefox's private browsing after mozilla deprecated some apis due to security concerns. They've given alternatives but they are just refusing to fix it, to the point of basically saying mozilla needs to fix the issue. What's sad is a similar mechanism is used in…
1Password for Linux beta
111–120 of 254 posts
Re: 1Password for Linux beta
#112The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…
I definitely have some password manager anxiety. I'm not too concerned about hacks or losing my password database. For me, it's more about the sense of independence, and being able to log in to my accounts using just my noggin. I might be able to remember one or two strong passwords, but not dozens, which is kind of the selling point of a password manager. I use KeePassXC with a password and key file. I sync the data…
Re: 1Password for Linux beta
#113The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…
Password managers make security tradeoffs, providing a nice balance of convenience and defense against many of the most important attack vectors.
So while it of course possible to come up with basically endless possible attack vectors for password managers (and indeed all software), it is most likely not a productive exercise.
Also, a small tangent, but if someone compromises the play store and is able to install malicious software on your phone, there are plenty of ways for tmem to get your password that don't involve password managers.
Re: 1Password for Linux beta
#114Earlier quoted context omitted.
You might want to look at KeepassXC.
That does not come with a simple way to have your passwords and automatically though. A better alternative in my opinion would be Bitwarden.
I suspect a typo, but could you describe the problem in more detail? I'm using KeepassXC, and while there are a few challenges around workflow, there's nothing insurmountable.
Re: 1Password for Linux beta
#115Earlier quoted context omitted.
Presumably the alternative to 'a password manager as a service' is 'a local password database and password manager which is not a service'. This can be something like password store, or keepass, where the attacker needs both your password database unlock key / gpg passphrase, but also needs access to the database / gpg keys, which means either physical access, or at least access to your local files. I think there is…
I've never used 1Password, but both LastPass and Bitwarden support hardware tokens like Yubikey for two-factor authentication. Keeping the encrypted store locally might give you some edge, but I personally need to be able to access secrets from more than one device, and once you allow external access then the advantage of your solution compared to hosted services disappears.
Let's look at one possible attack: the attacker knows all my passwords, and they manage to steal my laptop from my car. What can they do in each scenario?
In the case of lastpass, bitwarden, or keepass, the attacker now has all my passwords. The 2fa token was used once in the past, so all the passwords are stored on the device, protected only by a password at most.
In the case of password-store with my gpg-private-key on the yubikey, the attacker still can't decrypt anything unless they also stole my yubikey, which I never leave unattended.
The fact that my private key on my yubikey isn't just required to sync or login (like it is for the 2fa case), but is rather where the actual decryption is done every single time I access a password, does have a difference.
I don't think the difference is very large though, no.
Re: 1Password for Linux beta
#116Earlier quoted context omitted.
What if service goes away? Even if stand alone app vendor goes away, the app still works. There are things that I see are okay as a monthly service like Netflix or other content provider where the content is literally changing month to month. Stand alone software that rarely changes, like 1Pass, does not warrant a monthly service fee from me. I am self-hosting the content, so I don't need their cloud services.
Playing devil's advocate here, but the service fee (at least to my mind) is more for the maintenance & upkeep of the infra. I'd gladly move to self-hosting if it was only me. But after a few months, I was able to convince my wife to use it for convenience and security. So if there's an issue with the self-hosted version, it wouldn't just be me impacted, but my wife. And that's an SLA you don't wanna break. :D Also, w…
Re: 1Password for Linux beta
#117I would like to throw out Bitwarden out there. Cross platforms, works on everything and can be self hosted if you so desire.
Agreed. I have been using Bitwarden for over 3 years now, paid premium user as well. No big issues, the odd bug a few times but all fixed promptly and didn't impact my ability to access my data. While the Bitwarden apps are not as "pretty" as 1Password's I find them a little simpler to use. Obviously UI design is highly subjective though so your thoughts may be very different :) Anyway yes I highly recommend Bitwarde…
Re: 1Password for Linux beta
#118The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…
Re: 1Password for Linux beta
#119The reasonable person inside me wants to use a password manager, yet the paranoid in my brain is terrified. I read all those texts explaining why password managers are better, yet I am still afraid. I keep thinking in attack vectors such as someone compromising the Play Store and submitting a malicious app or other similar stuff. I even have a Bitwarden account and have some passwords stored on it. I also considered…
I'm using KeePassXC. Originally between three computers (Debian desktop, Debian laptop, and Microsoft laptop) where it was part of my git repo that I'd sync in between the machines as needed (git repo hosted within my own instance of gitolite, btw).
I've migrated more functionality into Syncthing - so now it's very rare that I ever need to do a manual merge within KeePassXC (which was always a robust operation anyway). KeePassXC has a setting to reload from disk if it sees that the password db file has changed, which makes this process seamless.
Part of my Syncthing setup is that I have a receive-only copy of my various repos on a Debian VM that runs a couple of archive tools (dirvish and borg) which provides for point-in-time restorations if needed.
So - I'm wondering what synchronisation problems you've had, and what you've tried. And what alternatives there are to trusting someone else's OS (replete with non-free components) on mobile, along with someone else's bundling of code into mobile packages?
There's a handful of keepass-compatible android apps, some of which are GPL, and Syncthing can keep a copy on Android easily enough, but ultimately there's a lot of trust in mobile land no matter how you slice it.
Re: 1Password for Linux beta
#120Earlier quoted context omitted.
The only way to guarantee that your keyring is secure long-term is for the source code (and change history) of your password manager to be inspectable and verifiable. A promise made by a corporation is not sufficient. You can pay a corporation to buy a product with more features or better service. But you can't pay a corporation to hold or maintain a principle. There will always be someone who can offer them more mon…
And what makes you think that Jason or Raymond won't wake up one day and decide they had a change in principles? Just like people, companies have reputations and values. Individuals are not immune to malevolence.
People can certainly lose their principles, but from observing past behavior (e.g. the number of times Raymond has told moneyed interests to fuck off), I believe that certain people are capable of holding certain principles for longer than a corporation would be able to.
Secondly, these individuals and communities recognize the inherent problem with needing to trust them, so they jump through hoops to make sure that publicly available binary builds are reproducible and verifiable. They publish their open-source software in a way that doesn't require you to trust them as much as you would need to trust a corporation with a closed-source product.
Not only do many corporations not bother doing this, many corporations that maintain open source products deliver binaries that obviously have more stuff baked in than their source code would suggest. For some categories of product, like a password manager, open source with reproducible builds is table stakes, not an optional feature.