Live data from Hacker News

Ask HN: How comfortable do you feel using cloud-based password managers?

news.ycombinator.com

121–130 of 199 posts

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#121
post #89
post #71

You could say I put a lot of trust in Google, as I use the built-in password manager in Chrome. My rationale is the following: 1. My browser vendor can access my browser passwords anyway. 2. It's better to trust fewer vendors and pieces of software. 3. Copying passwords to clipboard is awfully insecure. 4. Trying to remember all passwords is also awfully insecure. I do not save any money-related passwords. I do dream…

>I do not save any money-related passwords. I do dream of switching to pass from time to time. So you remember unique, high entropy passwords for all your money related sites? If not, you might be putting yourself at greater risk than syncing the passwords.

I don't have that many and the ones I use tend to enforce password type (say, a 4-number PIN as part of MFA).

But yes, I do remember a bunch of important unique passwords, and I do have to reset them occasionally by physically visiting and showing my id.

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#122
post #68

Earlier quoted context omitted.

Agreed w/your post in general. > On one hand, Bitwarden's online offering where you trust them with your data is convenient, but also a single point of failure. Put your network connectivity off, and try to relogin to Bitwarden. It will work. I just tried it. The only downside is that the database might not be synced (which, I admit, can be a problem). > The only caveat with self-hosting being the overhead. Regular n…

What operational security risks do you have to be aware of when self hosting passwords?

This is a great question which everyone should ask themselves.

It has to be user-friendly enough (which Bitwarden IMO is). You need to do a CIA threat assessment yourself.

Confidentiality I solve by using WireGuard; hence I don't mind if I use HTTP or HTTPS with self signed certificate. You might be able to use Lets Encrypt instead. Integrity I solve with offsite backups of the most important data. Availability is solved by having decent uptime on my cable provider, about 25 mbit upload. I also used RAID1 on my server. My server is a Synology NAS with Docker.

If that gets compromised by hackers, they have access to private data of mine anyway. If you include the government in your threat assessment they are very likely able to get access to your server (VPS or my example). That is why I prefer to stick to my local government/jurisdiction. I'm already bound by them anyway. If they want to screw me over (including working together with US government) they can and (since we are part of Nine Eyes) likely will.

YMW(ill)V

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#123
post #21

Earlier quoted context omitted.

Not to mention pass, due to its connection to GnuPG, can protect secrets using Yubikey that require 6 digit PIN (will lock after 3 tries) and touching the blinking dot.

How do access your passwords from your phone?

There's an Andriod client for that: https://github.com/zeapo/Android-Password-Store#readme

Plenty of other extensions, managers here: https://www.passwordstore.org/#other

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#124
post #32

Earlier quoted context omitted.

Bitwarden has also had an external audit. With regards to Bitwarden, it has a wordphrase on the account which only you know. You can verify this when you connect to the cloud. You can run the server within your own cloud. With the cloud, you can assume that the government has access to the encrypted database. If you have a strong password, it will take them longer to brute-force your database. We are talking about tw…

> With the cloud, you can assume that the government has access to the encrypted database. If you have a strong password, it will take them longer to brute-force your database. We are talking about two governments here: the US government (most password managers are from US companies and are hosted in US clouds) and your own (who can attempt to ask for the data), this is no issue, but I believe you should by default n…

> IMO the relevant thread model is more that they can convince / coerce / do it themselves the provider to change the javascript that does the client side decryption.

Yes, this is the MITM I referred to in another post. I'm not sure the fingerprint phrase [1] is adequate to mitigate that danger

> I wish there were something that used (as a second round of encryption) a key residing on a yubikey to decrypt the password of individual entries, without going through gpg. Going through gpg just seems to complicated and fragile to me, and has annoying restrictions like not really allowing multiple yubikeys.

I currently use 2 YubiKeys with OTP and 2 YubiKeys plus 2 Solos with FIDO U2F on top of an Authenticator App as backup. There's backup codes as well. E-mail or SMS I prefer not to use (they don't provide SMS AFAIK but do provide Duo). I plan on fine-tuning this once I receive my new smartphone with NFC and my Somu; then I will likely remove some of these keys, reset them, and sell them.

[1] https://help.bitwarden.com/article/fingerprint-phrase/

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#125
post #86

My company uses some enterprise Lastpass, and I would never give a dime for it myself. Not because of the quality, but because if the UX. I constantly have issues to find credentials shared with me, the plug-in is constantly interrupting my usual flow, and so on. Just not a fan. Personally I use KeePass. I know there are some security concerns with the application itself, but it has served me well. Just because of th…

This is exactly the boat that I was in for a number of years. I also have a few security concerns regarding bad practices of theirs that they essentially told me they didn't care about.

About a month ago I switched to BitWarden and it's been phenomenal. The UI is great, as is their mobile application. I've also heard good things about KeePass.

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#126
post #21

Earlier quoted context omitted.

Not to mention pass, due to its connection to GnuPG, can protect secrets using Yubikey that require 6 digit PIN (will lock after 3 tries) and touching the blinking dot.

How do access your passwords from your phone?

See sibling comment. Additionally it's possible to use the same Yubikey token on laptop and phone (through NFC or USB). Convenient and secure!

Second benefit is Yubikey can hold authentication subkey that can be used to SSH to a server on a phone.

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#128
post #94
post #21

Earlier quoted context omitted.

Not to mention pass, due to its connection to GnuPG, can protect secrets using Yubikey that require 6 digit PIN (will lock after 3 tries) and touching the blinking dot.

Interesting. I've never used pass, but this thread is making it sound interesting. Does it support fallbacks (multiple keys, other forms of credentials) simultaneously?

Multiple keys: yes, through a config file (can be also useful for team access). I'm not sure about "other forms of credentials" though. Pass is just a simple GnuPG wrapper if gpg can do something pass can do it too.

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#129
post #93

1Password has always offered the best usability for me. Many other password managers (eg LastPass) have failed, for instance, to work with the AWS sign in page and some other tricky websites. 1Password UX is also well polished in other ways and is nice to use. I consider this kind of good usability to significantly increase my quality of life, since I login to various online services all the time and I want to elimin…

I love 1Password but haven't upgraded specifically because of the cloud service. All my stuff is already in Dropbox, and 1Password essentially came to it's old users touting a subscription fee to a functionally identical service. Why am I paying them every month to store my passwords when I'm already storing them myself?

I'm sure I'll have to cave at some point what with the ongoing march of progress, but it leaves a bad taste in my mouth whenever a previously purchased product (i.e. 1Password) suddenly is asking for more money with no perceived benefit to me, other than getting to continue using a product I already bought.

Re: Ask HN: How comfortable do you feel using cloud-based password managers?

#130
post #89
post #71

You could say I put a lot of trust in Google, as I use the built-in password manager in Chrome. My rationale is the following: 1. My browser vendor can access my browser passwords anyway. 2. It's better to trust fewer vendors and pieces of software. 3. Copying passwords to clipboard is awfully insecure. 4. Trying to remember all passwords is also awfully insecure. I do not save any money-related passwords. I do dream…

>I do not save any money-related passwords. I do dream of switching to pass from time to time. So you remember unique, high entropy passwords for all your money related sites? If not, you might be putting yourself at greater risk than syncing the passwords.

Obligatory https://xkcd.com/936/
Post reply on HN