Live data from Hacker News

Flaws in deterministic password managers

tonyarcieri.com

31–40 of 106 posts

Re: Flaws in deterministic password managers

#31
post #10

Earlier quoted context omitted.

> Worse, an attacker who sees one of your passwords has a pretty decent shot at brute forcing the rules you use, and an attacker who sees two of them has the rules and has totally cracked your scheme. If an attacker is specifically targeting me and thinking about my passwords, there's not much I can do at that point. Password security in general kind of relies on attackers scanning huge quantities of credentials and…

> If an attacker is specifically targeting me and thinking about my passwords, there's not much I can do at that point. Have really long passwords that are extremely random on a bit-by-bit basis and doesn't have a snowball's chance in hell of containing a dictionary word (which are the blindingly killer flaw in your formula). Like: 6vRmÓ£æp¥£{&XèñgäÐë¸pH©Þ|÷g¸jn§/¥ÔÎpV4fÎ or ò\f4¬Ð³ &{W+ãÄçÏ)æý½06Ýzȯ+µ>få²9Æð:WÚu >…

That is massive overkill.

128 bits of security is way more than sufficient. 23 characters (uppercase, lowercase, numbers) already gives much security.

Honestly, 128 bits is already overkill. An attacker that determined is probably quite proficient at rubber hose cryptography.

The point of PW manager is to prevent compromise from spreading. Not to keep a motivated NSA out of your PC.

Re: Flaws in deterministic password managers

#32
post #5
post #3

The only deterministic password manager you need is your own mind. Come up with a set of password rules that are generic enough to accommodate all these issues. For example my deterministic password manager might be: 1. random english wordx2 + first 4 letters of registered domain, all caps + remaining lowercase + number of letters in domain (integer) + symbols associated with digits of the integer digits 2. If site d…

> If the site restricts passwords to max 12 characters The problem with this is that most sites are designed by idiots and don't state their pointless password rules on the login page - only on the 'change password' page. So you can be trying your coppercopperYCOMbinator11!! password and thinking "why the hell doesn't this work?", then after 10 minutes you give up and go to change it and see "Your password must be be…

This is exactly why I started using a password manager, the situation you described is infuriating. Additionally, all it takes is one site with poor security practices having a breach and someone could figure out your scheme and use it to figure out other sites passwords or even seed a dictionary attack with the "shape" of your passwords

Re: Flaws in deterministic password managers

#33
post #21
post #12

Earlier quoted context omitted.

I too am interested to see how long it takes assuming the attacker knows the generator ruleset (which he will have had to work out previously from two plaintext passwords of mine). Still, I don't think it's that easy to figure out the ruleset of a good password generator if you make it obscure enough. For example: Amazon: NovemberAlphaies12# Facebook: KiloFoxtrototto16& What's the ruleset? Answer: Phoenic alphabet of…

> Seems like way too much work for an attacker to try to figure out. I dunno, seems like way more work to come up with, maintain, and actually use the generator. Seems easier to just click a bunch in my vault to generate and copy, although I guess you're protected from vault-theft? Given your example, I had already figured out all the way up to ies/otto are probably foreign numbers (more specifically, otto looks like…

Give me some time with him and a $5 wrench an I can "steal" his "password vault" - https://xkcd.com/538/

Re: Flaws in deterministic password managers

#34

Earlier quoted context omitted.

If your browser is caching all of your passwords, I think you've got security problems well outside the scope of your choice of password managers.

I'd guess he doesn't mean cached, but instead means that his web browser works with this system keyring (or has its own) to save/use the passwords.

Which is bad. I've reverse engineered script kiddie malware far too many times to find them shipping "iStealer" and similar, which basically just dump browser password stores and send them to a gmail or FTP account. Often these pieces of malware include the SMTP credentials to the same gmail account or FTP access to download the results.

And having seen their results, let me just say, these script kiddies can do damn well with this tactic.

Do not use a browser/system keyring store under any circumstances unless you can be 100% positive that you won't accidentally run that sketchy exe you came across.

If you use Keepass, it presents another layer, they have to actually get your keepass password too, or dump your database when it's logged in. Often something like that won't be hit by script kiddies but certainly would in a targeted attack. The best practice here is to run Keepass on a separate machine to prevent an all-at-once dump. Even a separate machine on the same network where you use Synergy or similar to sync the clipboards would probably be sufficient.

Anything worth more than dirt should of course have 2FA, which is why I also suggest a tiered password system (ie: junk password for common and worthless sites, separate passwords for banking, etc) and 2FA as an alternative to a real password manager.

Re: Flaws in deterministic password managers

#35

Earlier quoted context omitted.

I'd guess he doesn't mean cached, but instead means that his web browser works with this system keyring (or has its own) to save/use the passwords.

Which is bad. I've reverse engineered script kiddie malware far too many times to find them shipping "iStealer" and similar, which basically just dump browser password stores and send them to a gmail or FTP account. Often these pieces of malware include the SMTP credentials to the same gmail account or FTP access to download the results. And having seen their results, let me just say, these script kiddies can do damn…

> I've reverse engineered script kiddie malware far too many times to find them shipping "iStealer" and similar, which basically just dump browser password stores and send them to a gmail or FTP account.

Meet the guy behind some of them: https://news.ycombinator.com/item?id=13003236

Re: Flaws in deterministic password managers

#36
post #13

I don't agree with the author on many of his points. 1 and 2 are "merely" convenience features. Sure, those things make a truly stateless password manager harder to use and a very niche tool, but they're by no means fatal flaws. 3 is a good argument, but storing existing secrets is by definition out of scope for password generators. It is a usability problem, which makes using a truly stateless password generator as…

> Sure, those things make a truly stateless password manager harder to use and a very niche tool, but they're by no means fatal flaws. If the Deterministic Password Generator does not generate a valid password for a given site, it's certainly a fatal flaw for that site, and a usability nightmare - now I have to remember which sites aren't supported and keep a vault anyway. And I guess point 2 isn't a fatal flaw until…

We both seem to have a different view of what a "fatal flaw" is. For me (especially when talking about a computer security tool), it means a very serious security vulnerability and nothing less. You seem to have a more relaxed view, accepting things that create a bad user experience as fatal flaws, too.

Re: Flaws in deterministic password managers

#37
post #31

Earlier quoted context omitted.

> If an attacker is specifically targeting me and thinking about my passwords, there's not much I can do at that point. Have really long passwords that are extremely random on a bit-by-bit basis and doesn't have a snowball's chance in hell of containing a dictionary word (which are the blindingly killer flaw in your formula). Like: 6vRmÓ£æp¥£{&XèñgäÐë¸pH©Þ|÷g¸jn§/¥ÔÎpV4fÎ or ò\f4¬Ð³ &{W+ãÄçÏ)æý½06Ýzȯ+µ>få²9Æð:WÚu >…

That is massive overkill. 128 bits of security is way more than sufficient. 23 characters (uppercase, lowercase, numbers) already gives much security. Honestly, 128 bits is already overkill. An attacker that determined is probably quite proficient at rubber hose cryptography. The point of PW manager is to prevent compromise from spreading. Not to keep a motivated NSA out of your PC.

I know, but that's a good property to have, it's easy to do, and the extra costs are insignificant.

Re: Flaws in deterministic password managers

#38

Earlier quoted context omitted.

I'd guess he doesn't mean cached, but instead means that his web browser works with this system keyring (or has its own) to save/use the passwords.

Which is bad. I've reverse engineered script kiddie malware far too many times to find them shipping "iStealer" and similar, which basically just dump browser password stores and send them to a gmail or FTP account. Often these pieces of malware include the SMTP credentials to the same gmail account or FTP access to download the results. And having seen their results, let me just say, these script kiddies can do damn…

Wait, KeePass only decrypts the database into memory for a particular process, right? So it would take an exploit of some kind to read the memory holding the decrypted database?

Re: Flaws in deterministic password managers

#39
I have an irrational(?) fear of vault password managers. I see it as a single point of failure.

Furthermore, the more "useful" they become, with browser extensions etc., the greater the attack surface becomes.

Because of this fear, I generate random passwords and memorise them, which is not ideal.

Re: Flaws in deterministic password managers

#40
post #9
post #3

The only deterministic password manager you need is your own mind. Come up with a set of password rules that are generic enough to accommodate all these issues. For example my deterministic password manager might be: 1. random english wordx2 + first 4 letters of registered domain, all caps + remaining lowercase + number of letters in domain (integer) + symbols associated with digits of the integer digits 2. If site d…

A password like that would probably be guessed by a good password cracker pretty quickly. I've taken the liberty of following your procedure for an un-named domain. If anyone's got a password cracker running, I'd be interested how long it takes to break this SHA256 hash: dae640f98b6894d2f6eab5755b22918be46b0d219ea10d3ceea06ebe538a75d1. Post once you've guessed it. Just use 'pwgen -s 22'; it generates 128-bit password…

For unsalted hashes, they tend to be uncrackable if they don't show up in a simple google search.
Post reply on HN