I don't think there is anything wrong with storing passwords unencrypted locally assuming the machine itself has encrypted storage. Malware that retrieves passwords from password manager could get them from an unlocked password manager as well.
Browser password managers – flawed security, by design
71–80 of 127 posts
Re: Browser password managers – flawed security, by design
#72Re: Browser password managers – flawed security, by design
#73> Note – many of these dedicated password managers have browser plugins or extensions to help users save and fill passwords. These are very different and much more secure than the built-in password managers that are the subject of this article! This is a shitty article from someone who doesn't really know what he's talking about. Here is a post from Tavis Ormandy, well-known security expert at Google Project Zero, ad…
Although I trust Tavis Ormandy more than this random blog post, I disagree with the idea that the password managers built into your browser are somehow superior. I use Bitwarden and there's simply no comparison between what Firefox/Chrome offer me and what Bitwarden offers; you can't even add an extra field to the browser password manager and Google helpfully "encrypts" your data with the password they're already rec…
I use Password Safe. It doesn't integrate with my browser, and the database is stored locally. So I'm exposed to no threat from the subscription company; and there's no content script. It's easy to back-up the database. I can store the database and the Password Safe program on a memory stick. And I can use the password manager with any browser.
What do I lose? I lose auto-filling of login forms. That's it. Instead I have to copy-paste a password, something that happens 4-5 times a day.
I'm planning to switch to pass, for a few reasons (notably that Password Safe is Windows-only), but I'm dragging my feet.
Re: Browser password managers – flawed security, by design
#74This is a bunch of silly hand-wringing. I guarantee that if browsers required creating and memorizing and typing a master password all the time, users would be less secure overall. Because people simply wouldn't use the annoying password manager. Using a password manager without a master password is way more secure than not using a password manager at all. If you are a business and you want your employees to be secur…
Safari already gates password autofill on the secure element (or enclave, I can never remember the difference) when such is available, which is what you're suggesting :D That said you're absolutely correct, making autofill harder to use would mean people wouldn't use it, and would revert to predictable and reused passwords, and if you're a business you should be using token based authentication be they dongles or pho…
Phone? Really? I regard my smartphone as the least-secure piece of computing equipment in my posession. I certainly don't trust it to secure anything. A phone isn't a token; it happens to be "something you own", so some sites treat a phone as if it were a security token. This is a problem I encounter mainly on UK government sites (sites that I more-or-less have to use). These sites don't offer support for alternative hardware "tokens", nor for people who don't own a smartphone.
Re: Browser password managers – flawed security, by design
#75A lot of the criticism of this article seems to be: “If they already have access to your local file system, you already have bigger problems” What about defence in depth? This article is suggesting an alternative, which are password managers such as 1Password. These Password managers do not suffer from the same weak key storage as the browser’s build-in password managers. So this article is bringing attention to a we…
It is a manager-speak buzzword. What about it?
Re: Browser password managers – flawed security, by design
#76I get asked for my windows password when I try to view the passwords, are they not encrypted by windows?
No, the prompt just unlocks the UI. Otherwise you'd be asked for your Windows password every time you auto-fill a password.
Re: Browser password managers – flawed security, by design
#77Earlier quoted context omitted.
Safari already gates password autofill on the secure element (or enclave, I can never remember the difference) when such is available, which is what you're suggesting :D That said you're absolutely correct, making autofill harder to use would mean people wouldn't use it, and would revert to predictable and reused passwords, and if you're a business you should be using token based authentication be they dongles or pho…
> you should be using token based authentication be they dongles or phone and PC's secure elements. Phone? Really? I regard my smartphone as the least-secure piece of computing equipment in my posession. I certainly don't trust it to secure anything. A phone isn't a token; it happens to be "something you own", so some sites treat a phone as if it were a security token. This is a problem I encounter mainly on UK gover…
Assuming that, a phone is likely one of the most secure devices that you own.
Re: Browser password managers – flawed security, by design
#78This is a bad bad article, the advice is dated and the counter-arguments are well known and oft-discussed by anyone who's actually in the security community. The author / website does seem to be offering services in the security industry, but they seem compliance-focused rather than security-focused (compliance is a component of security). So likely offering legal & administrative expertise rather than technical.
On reflection, I think this article is why I find it extremely difficult to hire qualified security experts. The vast majority of "security experts" I find tend to be "box tickers", who can require lots of rules like this ("don't use the built in password manager"), but whose advice is worse than useless because they don't understand the actual threat models. I know great security people exist, but in my experience I…
So I think they're hard to find because there's no real market for them, there's little point in announcing themselves and their expertise since there's really [almost] nobody interested in hiring that.
It's a sad reality, tbh.
Re: Browser password managers – flawed security, by design
#79I don't think there is anything wrong with storing passwords unencrypted locally assuming the machine itself has encrypted storage. Malware that retrieves passwords from password manager could get them from an unlocked password manager as well.
A decent password manager will require explicit user approval before disclosing passwords to clients. Regrettably, few do this.
Re: Browser password managers – flawed security, by design
#80> Note – many of these dedicated password managers have browser plugins or extensions to help users save and fill passwords. These are very different and much more secure than the built-in password managers that are the subject of this article! This is a shitty article from someone who doesn't really know what he's talking about. Here is a post from Tavis Ormandy, well-known security expert at Google Project Zero, ad…
That's bad article too. It talks about 1 bad "feature" of specific password manager extension and then dismisses every other password manager extension without verifying if they have this bad "feature" too. And this is from security expert ? Bruh
He specifically says:
> All online password managers work in a similar way, this isn’t specific to any one implementation.
And they do - because that's the integration point they have to use. It's just how the architecture of browsers works.
> And this is from security expert ? Bruh
Not sure what this is supposed to mean but I'll take it as dismissal. Assuming that is the case you should rethink how you assess information because Ormandy knows what he is talking about.