> If you want to use an online password manager, I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. Unfortunately, it also means I can basically never switch web browsers again, so it's an absolute non-option for me. I don't want to be locked into Chrome forever.
Password Managers
61–70 of 342 posts
Re: Password Managers
#62People can’t remember 80 passwords so they reuse the same one, that password eventually gets leaked and 9/10 times it doesn’t get leaked due to a targeted attack or a compromised machine but rather due to a breach of a service you signed up too.
Sure password managers have issues, they don’t solve user related errors and can even add to the attack surface of a machine they are running on but that’s really not important...
Using password managers and generating different passwords for each service reduces the blast radius from any breach.
This is why I don’t care if the password manager has the best encryption, or does it even encrypts at all or does it uses the clipboard vs some more secure side channel. Yeah that’s nice but that’s not in my threat model.
Which is why I don’t care if your password manager is a spreadsheet, it’s a terrible choice for a business because their threat landscape and the fact that a spreadsheet won’t allow you to audit who has access to what but for you or your mom even that is better than using the same password everywhere else.
Heck at home print your passwords and store them somewhere safe... put them on a post note for all I care as long as you live alone or at least not with anyone you wouldn’t want stumbling on that list...
Re: Password Managers
#63This somewhat overlooks the main threat model that password managers solve - leaked credentials. People can’t remember 80 passwords so they reuse the same one, that password eventually gets leaked and 9/10 times it doesn’t get leaked due to a targeted attack or a compromised machine but rather due to a breach of a service you signed up too. Sure password managers have issues, they don’t solve user related errors and…
Re: Password Managers
#64It's curious that we haven't seen dedicated effort towards a consistent password autofill API in browsers, like what is present in Android. Even the Credential Management API seems to have not picked up traction for passwords, though it was extended for use with FIDO2 security keys.
Is there one present in Android? My understanding is password managers on Android and iOS abuse a11y interfaces. (I'm not a mobile dev)
Re: Password Managers
#65The built-in browser password manager is the only one that ever made sense for me. You want the machine to verify the domain for you so you don't enter your credentials into some other site (no copying and pasting) and all third-party scripts are always clunky. I use Firefox with Lockwise[1] for Android and pass[2] as overflow for more involved secrets. This is a solo solution though that doesn't solve sharing these…
> I use [...] pass as overflow for more involved secrets
Why don't you consider pass a third-party script here in this context? Don't you use the Firefox plugin passFF?
Re: Password Managers
#66I really feel like people overthink this sometimes.
Re: Password Managers
#67This somewhat overlooks the main threat model that password managers solve - leaked credentials. People can’t remember 80 passwords so they reuse the same one, that password eventually gets leaked and 9/10 times it doesn’t get leaked due to a targeted attack or a compromised machine but rather due to a breach of a service you signed up too. Sure password managers have issues, they don’t solve user related errors and…
How does this address the point of the article? Which is that you should use the browser's builtin password manager and not a third party manager that injects user scripts into all websites and break the sandbox model?
Re: Password Managers
#68> If you want to use an online password manager, I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. Unfortunately, it also means I can basically never switch web browsers again, so it's an absolute non-option for me. I don't want to be locked into Chrome forever.
Chrome's password manager has an export feature. Are you perhaps thinking of some other browser?
Re: Password Managers
#69Earlier quoted context omitted.
Well someone can drug you and use your face while you’re passed out, but they can’t make your unconscious self share your pin code. This all assumes your attacker doesn’t think to just scare you into sharing by threatening you with a hammer. I was actually thinking more about law enforcement being the most likely to try gaining access to your phone. They can make you use your face or fingerprint, but they can’t force…
If your threat model includes someone using drugs/violence to get your passwords, then choosing the correct password manager is the least of your problems =)
Re: Password Managers
#70tl;dr: browser extensions are bad therefore all password managers are bad Also find it odd the author uses Chrome, which doesn't even let you set a master password to E2E encrypt its password store.
It's usually encrypted with your Windows / Mac / Linux login password.
*I have a password sentence.
Maybe because my disk is encrypted and I need to fill in a password when I login.
When I had auto login enabled, I had to fill in the Chrome password.