Live data from Hacker News

Flaws in deterministic password managers

tonyarcieri.com

71–80 of 106 posts

Re: Flaws in deterministic password managers

#71
post #62

Earlier quoted context omitted.

For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago. Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my ow…

> So if you cracked my LastPass vault - good luck with that, 2FA considered Well, the traditional[1] way to break[2] LastPass is to ignore individual accounts and go after poor coding technique[3]. 2FA won't help you there. [1] https://www.wired.com/2015/06/hack-brief-password-manager-la... [2] https://techcrunch.com/2011/05/05/password-manager-last-pass... [3] https://labs.detectify.com/2016/07/27/how-i-made-lastpas…

I'm probably the least knowledgeable person on HN so please understand these as questions more than objections, okay?

I would think the first link doesn't affect me since I use a fairly strong unique master password and haven't set an insecurity question.

As for the second link, much the same. I mean I'm fairly certain I can create an encrypted plaintext file that withstands extensive cracking attempts with standard Linux tools. These kinds of attacks would suck for people using 'lastpassword' as their master, if the stored vaults were unhashed and unsalted. Even then, how would that circumvent 2FA? Without my phone or Yubikey or whatever, you still don't get in.

As for the last one, and generally for most criticism: these tools give you the means to be more secure, they even encourage you by asking things that must annoy the average user. There's no unlimited trust for devices or browsers, the security checker is actually quite helpful in identifying possible problems - like my banking password being capped at five digits by design... sigh - and telling you when you're getting dumb ideas, like permanently storing your master password on your phone. So in the end, it's up to the user isn't it?

It's not using it by itself that makes the concept an increase in security, it's using it thoughtfully that is.

Re: Flaws in deterministic password managers

#72
post #66

Earlier quoted context omitted.

Maybe I'm paranoid, but it still doesn't feel "safe" to me. Let's assume that KeePassX is truly unbreakable at the moment. I still fear losing my kdbx file, as if someday it will become vulnerable (maybe for technical reasons, or maybe just because of master-password exposure) I'd lose much more than any single of the accounts there: even if passwords there will be outdated already, it will be exposed that all these…

I guess you have to balance the probability of that kind of breach in Keepassx against the probability of fucking up and forgetting a password or reusing passwords (I still see this) across multiple services. If you have an eidetic memory and can remember 20 digit random passwords for every service after securely generating them then keepassx increases your risk. If however you behave like a 'normal' user and use the…

FWIW, I do use a password manager. But what you say is pure speculation. I don't see any formula for how should I estimate risks here, and the common narrative amongst security folks is "hooray password managers!". I'm often giving that advice myself, but honestly, I'm doubting it more and more.

The truth is that I don't give a fuck about losing 90% of accounts I use (and I guess I'm not the only one). Many of them I could even give you myself as a birthday present. Using password manager as a rule of thumb would imply that these accounts are as important as the most important ones. Which is nonsense. Even if we discard all the disposable accounts, I still doubt that losing your twitter would hit you nearly as hard as losing your main email account or bank account.

However, exposing that all these trash accounts are mine might make me feel uncomfortable.

If that makes sense, then we must actually stop using the rule "password managers FTW" and start using the rule "consider how important is every given account to you, and treat it accordingly, chosing between several kdbx files". Which is much more complicated rule, obviously. I would even say it creates much higher mental load than remembering several sufficiently complicated passwords.

Re: Flaws in deterministic password managers

#73

Today I learned that many people on Hacker News have really insecure web security practices. :( I don't understand the resistance to using a vault-based password manager. Is it inertia? I mean, if you're using the same one or two passwords on every site, then sure, it may not seem worthwhile to us 1Password. But then, enough password hashes have been leaked this year alone to suggest that you need to do something bet…

For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago. Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my ow…

> For me it was a case of thinking I know better.

I'm deeply curious: why? When virtually every reputable security practitioner on this site and others has echoed the advice to just use a password manager for years, how do you come to the conclusion that you know better than them?

If it sounds like I'm asking judgmentally, please don't interpret it that way. Your experience mirrors that of many others, and if I can understand how this line of thinking happens then maybe we can find ways to combat it.

This is just one battle amongst many where, despite endless warnings and examples to the contrary, people seem to think they are qualified to go against encouraged practice for password storage, password management, encrypting data at rest, encrypting data over the wire, etc. And in almost all cases, people come to the conclusion that they know better, when they absolutely do not.

Re: Flaws in deterministic password managers

#74
post #66
post #58

Earlier quoted context omitted.

This is only true for cloud based password managers. I recommend using 1Password or KeePassX with Dropbox.

Maybe I'm paranoid, but it still doesn't feel "safe" to me. Let's assume that KeePassX is truly unbreakable at the moment. I still fear losing my kdbx file, as if someday it will become vulnerable (maybe for technical reasons, or maybe just because of master-password exposure) I'd lose much more than any single of the accounts there: even if passwords there will be outdated already, it will be exposed that all these…

I use KeePassX. I think the easiest way to break it (on Linux, at least) would be to get a program running on the user's machine, using a browser exploit or whatever, which would make a copy of the database and also sniff the X keypress events on the KeePassX window to get the master password. I don't know if it has any defence against that.

Re: Flaws in deterministic password managers

#75
post #73

Earlier quoted context omitted.

For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago. Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my ow…

> For me it was a case of thinking I know better. I'm deeply curious: why ? When virtually every reputable security practitioner on this site and others has echoed the advice to just use a password manager for years, how do you come to the conclusion that you know better than them? If it sounds like I'm asking judgmentally, please don't interpret it that way. Your experience mirrors that of many others, and if I can…

[deleted]

Re: Flaws in deterministic password managers

#77

I use a deterministic password generator so all I have to remember is my master password and default password scheme to get access to all my critical accounts (critical ones generally don’t have silly password requirements). If I were using something that stored passwords and lost my database somehow, I’d lose access to all of those.

"lost my database somehow"

I have mine in Dropbox and at least 3 devices. I'm really not concerned I'll lose it.

Re: Flaws in deterministic password managers

#78
post #58

Earlier quoted context omitted.

This is only true for cloud based password managers. I recommend using 1Password or KeePassX with Dropbox.

> This is only true for cloud based password managers I agree, in the sense that one successful attack on the supposed centralized database containing all user credentials would have a high ROI. But it also applies to local password managers. If 20 million people use the same password manager and I have an exploit for it, if I'm in the business of stealing data I'm likely to find a use for my exploit.

'If 20 million people use the same password manager and I have an exploit for it'

Someone is going to exploit my local password manager remotely?

Re: Flaws in deterministic password managers

#79
post #67
post #61

Earlier quoted context omitted.

Yes, I know that Otto is Italian for 8. But even if I convert the italian word to the number, it doesn't make sense, because "8" doesn't have digits on either side of the digit so there's nothing to sum up.

7 and 9 are on either side of 8, and the sum is 16.

Of course (x-1)+(x+1) = 2x

Re: Flaws in deterministic password managers

#80

I use a deterministic password generator so all I have to remember is my master password and default password scheme to get access to all my critical accounts (critical ones generally don’t have silly password requirements). If I were using something that stored passwords and lost my database somehow, I’d lose access to all of those.

"lost my database somehow" I have mine in Dropbox and at least 3 devices. I'm really not concerned I'll lose it.

Same here. Plus my email uses a different strong password I remember, so if worse comes to worse, I can just reset everything.
Post reply on HN