Earlier quoted context omitted.
While I think using password managers with random passwords is far better than sharing the same password between every account, I've never really gotten comfortable with storing passwords in a file on my computer. What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.
This is eventually going to be solved to a large degree by things like FIDO Universal 2-Factor dongles or whatever they evolve into over the next few years. It'll basically push specialized requirements to the hardware dongle (ie deciding whether it's enough to confirm user registration/authorization with the touch of a buttom, or whether it needs to be with a 4 digit pin, or even with biometrics like voice or finger…
Notes on the Celebrity Data Theft
181–190 of 292 posts
Re: Notes on the Celebrity Data Theft
#182Earlier quoted context omitted.
I've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that com…
Well, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board). Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to g…
Re: Notes on the Celebrity Data Theft
#183Earlier quoted context omitted.
My concern is that 1Password could shut down at any time and stop being supported, and I may lose access to all my passwords. KeePass is open source, so even if the current maintainer quits, it's likely that others in the community will step up to continue maintaining it. If absolutely necessary, I can edit the source code myself.
That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…
Re: Notes on the Celebrity Data Theft
#184Earlier quoted context omitted.
I currently use PasswordSafe which is clunky as hell but generally works OK. I checked the 1Password site and it seems like a bit of a bait and switch. Download links without any mention of a price or trial anywhere on the product pages until you create a vault and see a License link in the menus. Then $50+ and another $10 for the mobile app. I'm sure it's worth it, but I'd much rather they spell out their pricing up…
They have a 'store' link [1] right in their header with all the pricing. They could maybe be a little more upfront about it, but it's not really a bait and switch. Also, the prices do seem fairly reasonable for what it does. The only thing holding me back has been not having great mobile access (as far as I can tell) on Safari on iOS. Looks like iOS 8 will change that. [1] https://agilebits.com/store
Re: Notes on the Celebrity Data Theft
#185Earlier quoted context omitted.
The problem is to tap all of that into your phone, every time iOS decides it desperately needs it again, with just stars instead of letters. That's annoying.
It's a pain, but really not that bad. You tweet from your phone (or use email/SMS/whatever else). 20 characters is manageable and secure, as long as it's randomly generated.
Re: Notes on the Celebrity Data Theft
#186Earlier quoted context omitted.
That's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted)…
You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.
Re: Notes on the Celebrity Data Theft
#187Earlier quoted context omitted.
My problem is that 1Password et al are curing symptoms, not solving causes. Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them. We need to educate and/or provi…
12 character? Please! ;-) (Most of mine are markedly longer.) Though I'll admit to being a tad less aggressive on the rotation than I ought to be.
Other sites silently break if you use characters outside A-Za-z0-9. e.g. you set a password with } or @ in it, then can't log back in again.
Ebay wouldn't let me paste a password into the password field recently, I had to type it out, and the keepassx "autotype" feature was thwarted by their focus-altering javascript code on the form. I also think they silently dropped special characters - I know it took me 4 or 5 password reset emails to get the new stored pw to stick.
Paypal requires that you enter a credit card number to change the password, so rotating it is tricky if you don't have the card on hand. I'm undecided if this is good or bad, since this sort of 2 factor makes it harder for someone to hijack your account.
There are a lot of ways that sites try and make life hard if you are doing things the right way and using a pw manager. It feels like there's this big conspiracy driving us to use the same "Monkey123" password everywhere.
Re: Notes on the Celebrity Data Theft
#188Earlier quoted context omitted.
You are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.
I use Dropbox, but my password for Dropbox itself is stored inside 1Password. The escape hatch is that the 1Password sync folder is shared publicly, and the URL is copied to a slip of paper in my wallet.
Just keep a copy on a local computer with Dropbox if need be.
Re: Notes on the Celebrity Data Theft
#189Earlier quoted context omitted.
Why do you assume every KeePass user is storing their passwords on a server somewhere? I would never send my password file over a network, and I don't consider USB storage "sharing."
The password file itself is an encrypted DB. Unless you choose a weak password for that, it's pretty secure.
Re: Notes on the Celebrity Data Theft
#190Reddit should not be listed among the sites hosting the stolen images, as reddit does not support image uploads. Imgur is the primary site hosting the stolen images in that case.
Are we still unable to move past this pedantic hosting-vs-linking nitpicking? It's like you willfully ignore how content discovery works on the Internet.