Live data from Hacker News

Password Managers

lock.cmpxchg8b.com

191–200 of 342 posts

Re: Password Managers

#191
post #173

Earlier quoted context omitted.

I believe he was referring to the old 1Password that let you handle the storage of your encrypted vault (which doesn't incorporate the secret key encryption approach)

Yes, I was - and it still exists and gets updates. 1Password goes out of their way to not promote it though.

And rightly so.

Re: Password Managers

#192
post #38

I'm a little disappointed in the conclusion because there are more secure password managers out there that still offer the same level of convenience as the browser built-in password manager. Yes, if you use a password manager that's implemented entirely as a browser extension, you may as well use the browser's built-in password management features. However, if you're an advanced user and are comfortable using a separ…

It is my hope that this article keeps the 1Password team steered away from in-browser solutions. I’ve seen a couple of experiments of them trying it, and I’d much rather keep the awesome and extremely trustable methods that they have used up til now. Anyone else remember when they essentially pushed OSX to get better at security by having a tunnel of protected memory? (It’s been a minute and I know I won’t be able to…

> I’ve seen a couple of experiments of them trying it,

? Browser-addon 1password has been the only way to use (modern?) 1password on Linux for a long time.

Re: Password Managers

#193
post #190

Earlier quoted context omitted.

That would be news to me. I have never used a secret key with 1Password and a local vault.

Then sounds like you're working with a diminished product that's less secure.

I am curious how managing secrets locally is less secure than a cloud based solution?

Re: Password Managers

#194
post #191

Earlier quoted context omitted.

Yes, I was - and it still exists and gets updates. 1Password goes out of their way to not promote it though.

And rightly so.

It has nothing to do with security - they want to move everyone to a subscription model for reoccurring revenue. I can't blame them for that, but it isn't necessarily the best for customers.

Re: Password Managers

#195
I think iOS does this right. It helps you get a password from the Bitwarden app when using the browser. No browser extension with injection is required.

Re: Password Managers

#196
post #137
post #80

Earlier quoted context omitted.

2, 3, 4 are handled by Chrome, for example. These really are trivial features that any decent corpo can get right. 1 obviously isn't.

Last I checked I couldn’t export Chrome passwords (aka offline backup), couldn’t add non site passwords, and couldn’t manage non site based passwords/secrets with chrome password manager. And that was a month ago?

You can import chrome passwords from other browsers so I think you can also export them for backup.

I agree that I don't think you can add custom secrets.

Re: Password Managers

#197
post #144

I think this guy is missing one reason you definitely want to run browser based password managers, especially at a business. And that is... phishing. Not every one is tech savy enough to notice a phishing site and some phishing sites are hard to notice even for those who are aware. Browser based password managers fix this problem. Yes, the browser vendor and the password manager vendor are weak points, but it's often…

Prefer WebAuthn to fix phishing. The problem your approach has is that the user always really believes this is the BigCorp site - from their point of view the stupid password manager isn't working as intended, they need their BigCorp password and it isn't being filled out. The user will definitely figure out how to work around this (e.g. with cut-paste), almost always before they realise (if they ever do) that it's a…

Mmm... haven't tried WebAuthn, so I'll have to figure that out.

Curiously, I haven't had the issue with coworkers at my company using their password where they shouldn't... but the company I'm at is rather small... and I do scare them with a long phishing presentation when they join the company, and show them all the ways they can be phished, and tell them very carefully not to use passwords where they aren't suggested... I bet there are people who are like that though. And that would be a pain =/.

I haven't had to deal with the 2nd thing you mentioned, but yeah, I imagine it's quite a bit more secure that way. I bet it's caused a few trouble calls, that's for sure. I'll check out WebAuthn though.

Re: Password Managers

#198

Earlier quoted context omitted.

Please don't put TOTP codes or back up codes in password managers. The whole point of 2FA is to have two factors protecting you. If you do that, you're back to 1 factor (your password manager master password).

If you use a password manager that's two factor, then you are still at two factors. e.g. vault-based or hardware key based

I justify the second factor as having the 128-bit security key for the vault.

It's not that easy to install a 1Password vault onto a new device, so I'm okay with the 2FA codes getting stored in the same place as the passwords and sync between.

The realistic scenerio for my passwords leaking is target database exploitation or MITM attacks and not vault exploitation. The 2FA is still a rolling phrase that makes any capture of my password useless after about 1 minute, and not only that but I actually even get email notifications ('xx logged in from a new device') if someone uses my password but can't get past my 2FA. It feels very secure and I reject the dogma that 2FA means 2 separate physical devices.

Re: Password Managers

#199

The major problem with the built-in password managers is that they don't store more than the password. If there's a site that has security questions, I use LastPass to keep track of the security questions and my answers. I have to do this because I don't give real answers to security questions. A minor annoyance is that Safari will not let me treat sites which use multiple domains as equivalent. So Discount Tire uses…

[deleted]

Re: Password Managers

#200

Earlier quoted context omitted.

It is my hope that this article keeps the 1Password team steered away from in-browser solutions. I’ve seen a couple of experiments of them trying it, and I’d much rather keep the awesome and extremely trustable methods that they have used up til now. Anyone else remember when they essentially pushed OSX to get better at security by having a tunnel of protected memory? (It’s been a minute and I know I won’t be able to…

> I’ve seen a couple of experiments of them trying it, ? Browser-addon 1password has been the only way to use (modern?) 1password on Linux for a long time.

This is a recent development, but 1Password is now available on Linux as a native program, and it’s probably my favorite implementation!

https://1password.com/downloads/linux/

Post reply on HN