Live data from Hacker News

Password Managers

lock.cmpxchg8b.com

151–160 of 342 posts

Re: Password Managers

#151
post #95

> I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. I haven't used the browsers built-in password manager for years, so I don't know what features they have, but I find it hard to believe that they can provide the same functionality as a dedicated password manager. Some of the top features of dedicated pas…

Please don't put TOTP codes or back up codes in password managers. The whole point of 2FA is to have two factors protecting you. If you do that, you're back to 1 factor (your password manager master password).

Re: Password Managers

#152
post #38

I'm a little disappointed in the conclusion because there are more secure password managers out there that still offer the same level of convenience as the browser built-in password manager. Yes, if you use a password manager that's implemented entirely as a browser extension, you may as well use the browser's built-in password management features. However, if you're an advanced user and are comfortable using a separ…

It is my hope that this article keeps the 1Password team steered away from in-browser solutions. I’ve seen a couple of experiments of them trying it, and I’d much rather keep the awesome and extremely trustable methods that they have used up til now.

Anyone else remember when they essentially pushed OSX to get better at security by having a tunnel of protected memory? (It’s been a minute and I know I won’t be able to find the article, so please excuse me if the details are wrong)

Re: Password Managers

#153

Earlier quoted context omitted.

After realizing how every program running on your machine can Snoop on your clipboard I'm never allowing any program to send my password to the clipboard again.

Haven't you pretty much already lost when you can't trust the programs running on your machine? If they can snoop on your clipboard, they're probably also able to access your sensitive files, log key presses, take screenshots, install browser extensions etc.

They'd need root access to do half of those things. The other half are bad but not life-shattering.

Re: Password Managers

#154

The major problem with the built-in password managers is that they don't store more than the password. If there's a site that has security questions, I use LastPass to keep track of the security questions and my answers. I have to do this because I don't give real answers to security questions. A minor annoyance is that Safari will not let me treat sites which use multiple domains as equivalent. So Discount Tire uses…

How do you add multiple domains in LastPass? I couldn’t figure out how to do it.

Re: Password Managers

#155
post #72
post #67

Earlier quoted context omitted.

The point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.

That's only because there are more people who reuse passwords than people who use online password managers. As they're becoming popular, more cybercriminals are going to exploit it.

There are already enough people using password managers that they’re a target.

If they were as easy targets as you imply, then they’d already be exploited.

The fact they’re not demonstrates that’s reused passwords is lower hanging fruit.

Re: Password Managers

#156
post #132

The "attack surface" I worry about is forgetting to lock my screen before going down the hall to get some water, and someone slipping in to obtain a sensitive financial password. I've never succeeded in explaining this to any password manager's tech support. They stay in business because their tools are convenient to use. I've migrated from 1Password to a Dashlane family plan. I use two separate accounts for myself.…

If you're worried about that kind of attack, once someone has access to your computer they can install a key logger. Better to get in the habit of locking your computer every time you stand up.

Apple Watch supports this - lock upon getting a certain distance from the device.

I believe 1Password also lets you lock itself after a period of time which can be very short.

Re: Password Managers

#157
post #150

Earlier quoted context omitted.

"they might be able to get your master password, but that doesn't mean they gain access to anything" I can't be the only one who finds that to be small comfort; isn't it sensible to respond, "if my 1Pwd master pwd is stolen, I must treat the vault as if it had been exposed"?

Not really. At least not in the 1Password case. Having access to the 1Passswrd Master Password and your entire encrypted vault still doesn't get the attacker what they need. To decrypt your vault, you also need to know the 128 bit secret key which is also used in the encryption strategy that is stored offline (e.g. on a piece of paper in your safe or via another already authenticated device) https://support.1password…

This is not true for the standalone version of 1Password.

Re: Password Managers

#158

The major problem with the built-in password managers is that they don't store more than the password. If there's a site that has security questions, I use LastPass to keep track of the security questions and my answers. I have to do this because I don't give real answers to security questions. A minor annoyance is that Safari will not let me treat sites which use multiple domains as equivalent. So Discount Tire uses…

How do you add multiple domains in LastPass? I couldn’t figure out how to do it.

[0] - https://support.logmeininc.com/lastpass/help/duplicate-store...

Re: Password Managers

#159
post #150

Earlier quoted context omitted.

Not really. At least not in the 1Password case. Having access to the 1Passswrd Master Password and your entire encrypted vault still doesn't get the attacker what they need. To decrypt your vault, you also need to know the 128 bit secret key which is also used in the encryption strategy that is stored offline (e.g. on a piece of paper in your safe or via another already authenticated device) https://support.1password…

This is not true for the standalone version of 1Password.

The article is about Cloud-based Password Managers.

Re: Password Managers

#160
post #150

Earlier quoted context omitted.

Not really. At least not in the 1Password case. Having access to the 1Passswrd Master Password and your entire encrypted vault still doesn't get the attacker what they need. To decrypt your vault, you also need to know the 128 bit secret key which is also used in the encryption strategy that is stored offline (e.g. on a piece of paper in your safe or via another already authenticated device) https://support.1password…

This is not true for the standalone version of 1Password.

It’s 100% true of the standalone version of 1Password because there is only one version of 1Password - the standalone version.

Everything else interacts with it.

Your secret key is still required to decrypt passwords via the desktop application (which is the only version - everything else interacts with this.)

Post reply on HN