Live data from Hacker News

Browser password managers – flawed security, by design

fractionalciso.com

71–80 of 127 posts

Re: Browser password managers – flawed security, by design

#71
post #8

I don't think there is anything wrong with storing passwords unencrypted locally assuming the machine itself has encrypted storage. Malware that retrieves passwords from password manager could get them from an unlocked password manager as well.

Encrypting your mass storage devices doesn't protect against malicious code as by definition the filesystem is unlocked once you're logged in. Mass storage encryption is primarily protection against physical access.

Re: Browser password managers – flawed security, by design

#72

Does this cover things like LassPass, OnePassword, BitWarden? Or just the built in managers?

Just the built in managers. Other are worse: they do vendor locking for profit.

They do CSV exports and imports so are quite friendly to moving to another option

Re: Browser password managers – flawed security, by design

#73

> Note – many of these dedicated password managers have browser plugins or extensions to help users save and fill passwords. These are very different and much more secure than the built-in password managers that are the subject of this article! This is a shitty article from someone who doesn't really know what he's talking about. Here is a post from Tavis Ormandy, well-known security expert at Google Project Zero, ad…

Although I trust Tavis Ormandy more than this random blog post, I disagree with the idea that the password managers built into your browser are somehow superior. I use Bitwarden and there's simply no comparison between what Firefox/Chrome offer me and what Bitwarden offers; you can't even add an extra field to the browser password manager and Google helpfully "encrypts" your data with the password they're already rec…

> I disagree with the idea that the password managers built into your browser are somehow superior.

I use Password Safe. It doesn't integrate with my browser, and the database is stored locally. So I'm exposed to no threat from the subscription company; and there's no content script. It's easy to back-up the database. I can store the database and the Password Safe program on a memory stick. And I can use the password manager with any browser.

What do I lose? I lose auto-filling of login forms. That's it. Instead I have to copy-paste a password, something that happens 4-5 times a day.

I'm planning to switch to pass, for a few reasons (notably that Password Safe is Windows-only), but I'm dragging my feet.

Re: Browser password managers – flawed security, by design

#74
post #68
post #7

This is a bunch of silly hand-wringing. I guarantee that if browsers required creating and memorizing and typing a master password all the time, users would be less secure overall. Because people simply wouldn't use the annoying password manager. Using a password manager without a master password is way more secure than not using a password manager at all. If you are a business and you want your employees to be secur…

Safari already gates password autofill on the secure element (or enclave, I can never remember the difference) when such is available, which is what you're suggesting :D That said you're absolutely correct, making autofill harder to use would mean people wouldn't use it, and would revert to predictable and reused passwords, and if you're a business you should be using token based authentication be they dongles or pho…

> you should be using token based authentication be they dongles or phone and PC's secure elements.

Phone? Really? I regard my smartphone as the least-secure piece of computing equipment in my posession. I certainly don't trust it to secure anything. A phone isn't a token; it happens to be "something you own", so some sites treat a phone as if it were a security token. This is a problem I encounter mainly on UK government sites (sites that I more-or-less have to use). These sites don't offer support for alternative hardware "tokens", nor for people who don't own a smartphone.

Re: Browser password managers – flawed security, by design

#75
post #25

A lot of the criticism of this article seems to be: “If they already have access to your local file system, you already have bigger problems” What about defence in depth? This article is suggesting an alternative, which are password managers such as 1Password. These Password managers do not suffer from the same weak key storage as the browser’s build-in password managers. So this article is bringing attention to a we…

> What about defence in depth?

It is a manager-speak buzzword. What about it?

Re: Browser password managers – flawed security, by design

#76
post #28

I get asked for my windows password when I try to view the passwords, are they not encrypted by windows?

No, the prompt just unlocks the UI. Otherwise you'd be asked for your Windows password every time you auto-fill a password.

Huh. So it's just to protect against casual perusal I guess?

Re: Browser password managers – flawed security, by design

#77
post #68

Earlier quoted context omitted.

Safari already gates password autofill on the secure element (or enclave, I can never remember the difference) when such is available, which is what you're suggesting :D That said you're absolutely correct, making autofill harder to use would mean people wouldn't use it, and would revert to predictable and reused passwords, and if you're a business you should be using token based authentication be they dongles or pho…

> you should be using token based authentication be they dongles or phone and PC's secure elements. Phone? Really? I regard my smartphone as the least-secure piece of computing equipment in my posession. I certainly don't trust it to secure anything. A phone isn't a token; it happens to be "something you own", so some sites treat a phone as if it were a security token. This is a problem I encounter mainly on UK gover…

I had assumed that at this point all android phones have got some equivalent to the secure element present in all apple products produced in the last 5+ years, if they don't that's bananas.

Assuming that, a phone is likely one of the most secure devices that you own.

Re: Browser password managers – flawed security, by design

#78

This is a bad bad article, the advice is dated and the counter-arguments are well known and oft-discussed by anyone who's actually in the security community. The author / website does seem to be offering services in the security industry, but they seem compliance-focused rather than security-focused (compliance is a component of security). So likely offering legal & administrative expertise rather than technical.

On reflection, I think this article is why I find it extremely difficult to hire qualified security experts. The vast majority of "security experts" I find tend to be "box tickers", who can require lots of rules like this ("don't use the built in password manager"), but whose advice is worse than useless because they don't understand the actual threat models. I know great security people exist, but in my experience I…

I feel that it's also very hard for people who understand security to put themselves out there. For people who actually care about security and not just compliance, there's no real job market at all. Companies never hire for this kind of role.

So I think they're hard to find because there's no real market for them, there's little point in announcing themselves and their expertise since there's really [almost] nobody interested in hiring that.

It's a sad reality, tbh.

Re: Browser password managers – flawed security, by design

#79
post #8

I don't think there is anything wrong with storing passwords unencrypted locally assuming the machine itself has encrypted storage. Malware that retrieves passwords from password manager could get them from an unlocked password manager as well.

> Malware that retrieves passwords from password manager could get them from an unlocked password manager as well.

A decent password manager will require explicit user approval before disclosing passwords to clients. Regrettably, few do this.

Re: Browser password managers – flawed security, by design

#80

> Note – many of these dedicated password managers have browser plugins or extensions to help users save and fill passwords. These are very different and much more secure than the built-in password managers that are the subject of this article! This is a shitty article from someone who doesn't really know what he's talking about. Here is a post from Tavis Ormandy, well-known security expert at Google Project Zero, ad…

That's bad article too. It talks about 1 bad "feature" of specific password manager extension and then dismisses every other password manager extension without verifying if they have this bad "feature" too. And this is from security expert ? Bruh

> It talks about 1 bad "feature" of specific password manager extension and then dismisses every other password manager extension without verifying if they have this bad "feature" too.

He specifically says:

> All online password managers work in a similar way, this isn’t specific to any one implementation.

And they do - because that's the integration point they have to use. It's just how the architecture of browsers works.

> And this is from security expert ? Bruh

Not sure what this is supposed to mean but I'll take it as dismissal. Assuming that is the case you should rethink how you assess information because Ormandy knows what he is talking about.

Post reply on HN