Live data from Hacker News

On Password Managers

tbray.org

131–140 of 347 posts

Re: On Password Managers

#131

Earlier quoted context omitted.

Keepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.

If you can stomach an electron app Keeweb is a nice keepass compatible alternative.

This looks nice.

How has your experience with it so far?

Re: On Password Managers

#132
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

Keepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.

Have you used KeepassXC. I am panning to move to it from lastpass, and want to make sure I am making the right choice.

Re: On Password Managers

#133

Earlier quoted context omitted.

By default the browser plugin is configured in such a way that 2FA is completely bypassed for a second when logging in. This is officially documented, so we can likely assume that it will never be fixed. https://lastpass.com/support.php?cmd=showfaq&id=2775

This "second" became very noticeable to me once I moved to Sydney. I was actually able to log in to my Gmail before my 2FA kicked in. Right then I decided that, despite being a loyal LastPass user for the last 10+ years, it was time to try something else. I would prefer a tool that works for teams if anyone has suggestions. I care about how my team manages and shares their passwords. Looking for something that works…

I'm not an expert and i haven't tried this, but i would think you could use the pass tool and encrypt the files to multiple gpg keys, and share those files using a git server which you control. That sounds like a rather easy homebrew password manager that supports shared logins, i would think.

Disclosure: happy user of pass, but haven't tried encrypting to multiple identities.

Re: On Password Managers

#134
post #46

Encryption Wizard [1] solves issues 1-4, but is severely lacking on #5 (device syncing). It also has no mobile support. I've performed a cursory search to see if any OSS password manager comes close to EW on features, but didn't find anything: * Supports CAC encryption/decryption * Allows you to store contacts public certs * Allows keys to decrypt * Generates passphrases * Allows multiple keychains to be opened at on…

hunter2 supports using DOD CACs (or any other smartcard) to encrypt and share passwords. In hunter2, users are identified by their public keys. Each password can be shared with any user by any user that can decrypt that password. The DB used is a flat, sorted, text file so it can be stored in a version control system. https://chiselapp.com/user/rkeene/repository/hunter2/ I'm interested in taking you up on your offer…

The reference:

http://www.bash.org/?244321

Re: On Password Managers

#135
Good security hygiene is like a diet or exercise plan: the most effective one is the one you will stick with. Most users don't follow good habits because its a giant pain for non technical users to get set up. 1p's subscription plan is aimed squarely at those people and I think its a great idea. It's reasonably secure and easy to set up everywhere. That is a big deal in my mind. Yes, its not bullet proof but its a 100000% better than what the current status quo is.

Additionally, managing your own password vault is a lot like managing your own email server. There's advantages but I feel that the disadvantages are substantial. For one, the likelihood that you, one person, are going to do a better job of securing your stuff than a dedicated team is optimistic at best. Keeping your password vault safe is literally this companies full time gig and they have entire teams dedicated to it. Do I think they are infallible? Of course not. I'm not an idiot. But I think they are going to do a better job than me at keeping my stuff safe. I happily will pay for that every month.

The authors point about the 1p web portal is a good one. I don't use it out of similar concerns. Besides that, I really could not be happier with 1p as a password management solution. They have a good track record (no hacks that I am aware of) and I want the company I trust with literally the keys to my kingdom to be profitable and motivated to keep improving.

Re: On Password Managers

#136
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

Can you clarify if you use the app in some sort of "family" mode, or do you mean solely for an individual's use case? I'm looking for a password manager for me and my wife, so I imagine there's some extra security considerations there, unless I guess we just share a single master password.

Me and my partner use 1Password in family mode. We have a private vault each, and also a shared vault that we can both see. Entries can be moved from vault to vault without re-entering. It's pretty good.

Re: On Password Managers

#137
I'm a 1Password user, and have synced my vault between devices through both Dropbox and iCloud at various points. I can't help but feel like either there's something I'm missing or something everyone else is missing, which statistically means that it's most likely me. But:

When I sync with iCloud, Apple can't read my vault--even though it's on their servers, it's strongly encrypted with my passphrase, and the encryption/decryption happens on my devices.

When I sync with Dropbox, Dropbox can't read my vault--even though it's on their servers, it's strongly encrypted with my passphrase, and the encryption/decryption happens on my devices.

When I sync with AgileBit's own cloud... doesn't the sentence go exactly the same way? Quoting from their own current web page: "Every time you use 1Password, your data is encrypted before a single byte ever leaves your devices."

So even if the vault is on AgileBits' own servers, isn't it _no more and no less secure_ than the third-party syncing solutions they offer? Maybe that's not the case, and things actually function differently--but I haven't seen anyone describe why that would be the case. Again, maybe I'm just missing it. But I keep missing it. And it's not in Tim Bray's article, either. He's fine with putting it on somebody else's server if that server is run by Dropbox, but not if it's run by the company that he's trusting to encrypt it against people hacking Dropbox? How is this is materially different than using iCloud, Dropbox, or any other solution that puts a copy of my vault on someone else's servers for syncing purposes?

If the real argument is that there should always be a way to use a password manager with _no_ cloud-based syncing solution, I'm on board with that; it'd be a requirement for some businesses. But that doesn't seem to be the argument that's being made. And if the real argument is that you don't like subscription pricing models, that's fine. I don't like them, either. But that's not an argument about security--it's an argument about pricing models.

Re: On Password Managers

#138
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

> as someone who does research in the field

> ...

> there's currently no other commercial password manager that I recommend.

> I'm sorry I can't go into more detail than that.

Hmm. OK. Well. How about this?

Without getting into specific products, can you list the top 10 things a good password manager must do, offer or implement in order to secure the recommendation of someone doing research in the field?

Re: On Password Managers

#139
post #81
post #11

I totally missed this switch by AgileBits. Does anyone know how to ensure that the data file continues to be synced to Dropbox or iCloud, not AgileBits? (Looking into my configuration, it would appear that AgileBits has silently moved my data from iCloud to the AgileBits cloud.) EDIT: Found: https://support.1password.com/sync-with-dropbox/

> Looking into my configuration, it would appear that AgileBits has silently moved my data from iCloud to the AgileBits cloud How could that possibly happen? Local vaults can't just silently turn into cloud vaults, and you need a subscription license to use cloud vaults anyway.

How could that possibly happen? Local vaults can't just silently turn into cloud vaults,

Why not, all they'd have to do is copy the local vault to their cloud service and you'd never notice until you discover that the local file you're syncing somewhere else no longer contains your new passwords.

I'm not saying they've done this, but they could.

Re: On Password Managers

#140
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

Keepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.

KeepassXC recently added support for Yubikey OTP too, in case that interests you.

https://keepassxc.org/blog/2017-06-26-2.2.0-released/

Post reply on HN