Live data from Hacker News

Password Managers

lock.cmpxchg8b.com

71–80 of 342 posts

Re: Password Managers

#71
post #67
post #63

Earlier quoted context omitted.

How does this address the point of the article? Which is that you should use the browser's builtin password manager and not a third party manager that injects user scripts into all websites and break the sandbox model?

The point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.

Ok so:

1) not use any manager => bad

2) use a 3rd party => pretty crap as the article says

3) use a built-in => great

Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy.

I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additional code into the website itself. I thought there's a dedicated browser API or something.

Re: Password Managers

#72
post #67
post #63

Earlier quoted context omitted.

How does this address the point of the article? Which is that you should use the browser's builtin password manager and not a third party manager that injects user scripts into all websites and break the sandbox model?

The point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.

That's only because there are more people who reuse passwords than people who use online password managers. As they're becoming popular, more cybercriminals are going to exploit it.

Re: Password Managers

#73
I need to share my passwords between multiple devices and browsers, that's why I use a password manager. I have a second one, called: pass.

But I didn't check to synchronise it with devices.

Re: Password Managers

#74
post #71
post #67

Earlier quoted context omitted.

The point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.

Ok so: 1) not use any manager => bad 2) use a 3rd party => pretty crap as the article says 3) use a built-in => great Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy. I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additi…

3rd party password managers have a bunch of useful features, which is why I use one. Here are the first few that come to mind:

- portability, if I use chrome on my desktop, firefox at work, and safari on mobile I'm out of luck.

- built-in password managers only work for websites - I store many non-website security credentials in my password manager

- extra details - I often add the security questions for a site into my password manager

- compromised password warnings (maybe some of the built in password systems do this now?)

Re: Password Managers

#75
post #38

I'm a little disappointed in the conclusion because there are more secure password managers out there that still offer the same level of convenience as the browser built-in password manager. Yes, if you use a password manager that's implemented entirely as a browser extension, you may as well use the browser's built-in password management features. However, if you're an advanced user and are comfortable using a separ…

I'm also a 1password customer and curious how the attack vector of spoofing the 1password input icon can harm the user. They might be able to get your master password, but that doesn't mean they gain access to anything.

Also, I never use that icon and exclusively use the shortcut. I'm curious if that can be spoofed somehow. But again, they can only get your master password. In the case of 1password, I'm pretty sure they would need direct access to the computer to gain access to your vault.

Re: Password Managers

#76
post #52

I don't understand the Nordpass demo. What would double-clicking actually do?

Seems like a clickjacking attack. Presumably you can use this to reveal passwords for other sites, depending on how the ui is coded.

Re: Password Managers

#77

Earlier quoted context omitted.

I recently moved my passwords from an expired 1Password account to Bitwarden (right at the time they announced linux support actually, which was always the biggest thing I missed). Bitwarden has a FF extension and allows me to use it across mac/windows/linux.

I was looking at Bitwarden yesterday as I've been putting off moving over from LastPass and 1Password seemed weird with importing from it. Is Bitwarden decent enough? The fact that it has a cli, FF extension etc. on a free plan is pretty tempting.

I’ve been a happy Bitwarden user for 2 or 3 years. Recently upgraded to the family plan for shared passwords and that is working well.

Re: Password Managers

#78

Earlier quoted context omitted.

What’s is the difference between keepass synced by X and another service which is completely online? Simplified with keepass I have a) the database and b) an online accessible Location for storage. If I use Bitwarden, I still have a) and b), right? So for keepass to be better it would need to be better (as in safer) for one of those. I’m not sure if that’s the case (you can even selfhost both Bitwarden and nextcloud…

Using keepass would decouple password management from your browser. Bitwarden, for example, usually runs as a browser addon.

https://bitwarden.com/download/

They seem to have desktop/mobile apps as well?

Re: Password Managers

#79
post #76
post #52

I don't understand the Nordpass demo. What would double-clicking actually do?

Seems like a clickjacking attack. Presumably you can use this to reveal passwords for other sites, depending on how the ui is coded.

Sure, but where do the clicks actually end up?

Re: Password Managers

#80
post #71

Earlier quoted context omitted.

Ok so: 1) not use any manager => bad 2) use a 3rd party => pretty crap as the article says 3) use a built-in => great Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy. I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additi…

3rd party password managers have a bunch of useful features, which is why I use one. Here are the first few that come to mind: - portability, if I use chrome on my desktop, firefox at work, and safari on mobile I'm out of luck. - built-in password managers only work for websites - I store many non-website security credentials in my password manager - extra details - I often add the security questions for a site into…

2, 3, 4 are handled by Chrome, for example. These really are trivial features that any decent corpo can get right.

1 obviously isn't.

Post reply on HN