Live data from Hacker News

On Password Managers

tbray.org

341–347 of 347 posts

Re: On Password Managers

#341

Earlier quoted context omitted.

To start, the LastPass browser extension auto logout feature has critical bugs. I've come back to my computer after several days and found it still logged in with full access to the vault (no master password re-entry required) even with auto logout set to 15 minutes of inactivity. After that happened several times, I lost trust in the product.

There is also a serious bug regarding 2FA. There is a race condition where if you know a users master password you can bypass 2FA for 1 single login. Apparently someone commented below that is a documented "feature". Wow.

It's a "feature" because it relies on a local cache. So it means that the attacker must be using your own unlocked computer (which contains the cache) to bypass 2FA through this "race"; and in that case it might as well install a key-logger instead or worse. The worse it can be said is that it is very confusing and breaks the usual pattern of what "logging off" means, but users should be taught to lock their computer, not log off stuff hoping not to leave nothing behind.

Re: On Password Managers

#343
post #334

Earlier quoted context omitted.

Your phone... I'm sure your data is hopping over many machines.

Can you explain? I use my home wifi to sync to my phone. I'm sure my data is not hopping over many machines, or any machines I do not control.

Fair enough, as long as you're sure that the app is not active when not on your specific wifi network.

Re: On Password Managers

#344

Earlier quoted context omitted.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

Did they add OTP support to version 4 of the windows client? Last I saw it was not supported, so it was not super useful to me.

Not that I know of? I'm not really familiar with OTP, nor do I use it.

Re: On Password Managers

#345
post #261

Earlier quoted context omitted.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

I'm happy with it with Google Chrome, which is what I use on my Windows gaming desktop. However, on my Surface Pro 4 I use Edge, because it supposedly uses less power than Chrome. If I've understood the 1Password forums correctly, the Edge integration that they are working on will only be in the subscription version. Those of us staying on 4 will be stuck with manually looking up passwords in 1Password.

Fair enough, I don't actually use any of the browser integrations.

Re: On Password Managers

#346
post #160

Earlier quoted context omitted.

I have it and it's terrible IMO.

As another opinion, I use 1Password 4 for Windows, and am quite happy with it.

Then you clearly don't have to use multiple vaults... I've tried using 4 and 6 together - but that resulted only in tears. Enpass looks ok-ish, although a lot more limited with some questionable UI decisions and features (last used in my browser extension? really?)

Enpass doesn't seem to support multiple vaults at all though...

Re: On Password Managers

#347
post #336
post #239

Earlier quoted context omitted.

Playing devil's advocate: if you can trust that 1Password is doing everything they can to protect you, the user (using HTTPS, resource integrity) while using the browser app, then are you worried that 1Password may act maliciously? I see this argument all the time but I don't buy it because why on Earth would 1Password do such a thing, if their entire model is based on the customer trusting them handling their data?

They can be compelled by an outside force to do so. Or their business model may change

"Compelled by an outside force" is the main fear for many people. Because it happens all the time, and some of those instances also have an NSL / gag order so they're unable to talk about it until years after the fact (if ever). Or they just threaten violence.

Threat models aren't the same person-to-person - this probably won't happen to you (the grandparent), but embedded journalists / people trying to overthrow a corrupt regime depend on this stuff to literally keep them alive.

Another fairly common possibility, and one that affects damn near everybody: they can get hacked and have their source code modified. This happens with some regularity, and it can affect apps too: https://www.macrumors.com/2017/05/07/handbrake-app-security-... but in a browser this happens silently and unpreventably. Apps don't (usually) update invisibly just because you launched them.

Post reply on HN