This title is hyperbolic linkbait and should probably be changed. From skimming the paper, the only real flaw that seems broadly applicable is in autofill features which I'm not sure 1Password even has. Those intuitively seem like a bad idea and are easy to disable.
Lastpass does autofill, but only once a site is recognized. That to me is OK - unless there is a way to trick it of course. EDIT: Nevermind..you can configure either behaviour. Either fill in or fill & submit.
Browser Extension Password Managers Exposing Passwords Everywhere
81–90 of 93 posts
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#82We need to put the headline and some of the odd generalizations stated in the paper aside, and look at the specific security issues raised. When we do that, we find that 1Password matches or exceeds the "far more secure" built-in form fillers.
If we ignore the title and some odd generalizations, this paper actually spells out how well 1Password avoids various risks when you look at the details.
Readers need to go through section 2 of the paper carefully to see which studied systems do what. The most worrisome of the kinds of flaws that browser-based password managers face (filling things for https://foo.example into http://foo.example and filling for bar.example origin forms on foo.example pages) are things that 1Password handles correctly.
The things that we don't do "right" in their eyes are things that their recommended alternative (built-in browser form fillers) also don't do "right". I'm not sure that the authors have fully thought through would it would even mean to do those "right". But I encourage people to read the paper and decide for themselves whether we've made the correct choices in our handling of subdomains, and whether filling should be tied to a specific page on a site.
What of course does need to be considered are the risks of not using something in the browser. If you are copying and pasting from your password manager to your browser you are far more likely to be tricked by phishing, or cross origin forms than you would be with 1Password.
1Password tries to make it hard for you to fill in your credentials in the wrong place (you have to use copy/paste to manually do it where 1Password refuses to do it automatically), and to the extent that the concerns in the paper are legitimate, there are cases where browser-based fillers may fail to "make it hard" where the should.
Contrast that with the alternative of using copy/paste. Copy/paste offers no protections whatsoever against you filling in credentials to the wrong web form.
It would be foolish to claim that 1Password's phishing prevention mechanisms can't ever been defeated. But with respect to what was tested in this paper, they are the best out there.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#83Earlier quoted context omitted.
... this doesn't sound easier, this sounds much more annoying. But each to is own.
I didn't assert that it was easier, just potentially more secure. Similarly, it's arguably annoying to only access financial accounts (and the email accounts that are associated with the financial accounts) using a dedicated banking computer, but I think that having a banking computer is worth it. Others will disagree.
One way of characterizing the particular paper is "password managers with browser extensions don't always prevent you from submitting your data to the wrong place."
Systems that rely on the user to copy/paste offer no such protections whatsoever (and so, I suppose, can't fail at them.) So I'm curious about what you may mean by "potentially more secure" in this particular respect. Are you concerned that you might come to rely too heavily on the password manager's anti-phishing mechanisms?
[Note that I fully acknowledge that there may be other security reasons you may wish to keep your password manager out of browser. 1Password and KeePass have different security architectures, development processes, platform support, etc, with their own advantages and disadvantages. People need to figure out which works best for them.]
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#84Looks like LastPass really screws up by auto filling forms within emails and submitting them. Which means that I can duplicate the yahoo login page, send it to your yahoo mail and LastPass would fill it up and submit because it's served under yahoo domain. 1Password seems to be just fine according to this paper. It did not fuck up like Lastpass and only live flaw is about subdomain matching, which I actually find use…
I honestly think for security purposes in general you shouldn't auto fill in a form regardless of the domain and the extension builders should just not build that feature because it exposes issues like this.
In 1Password 4, there is no auto-filling. People can use Ctrl-\ or Cmd-\ to tell 1Password to "fill this page". In versions prior to 4, auto-fill was an option. (I'm not sure which versions had what defaults.)
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#85Earlier quoted context omitted.
KeePass also makes a global keyboard shortcut available (Ctrl+Alt+A by default) that will complete login fields based on the active window title. (The mechanics of the text entry and the window title matching are all configurable, though the defaults are usually fine.) Not as slick as auto-filling without user interaction, but better than manually searching for each entry every time.
I've been using this in ubuntu (ctrl-alt-v in keepassx). It covers most of the sites I use, and works with minimal extra effort. I originally looked at Lastpass, but it seemed 'too' easy. Decryption is done client side via javascript, but what happens if someone hacks into Lastpass's server, and modifies the code to send the user's entered password to their server?
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#86On an unrelated note: I am looking for a password manager that would allow me to assign a system wide shortcut. When the shortcut is pressed, a window would appear where I can search for the password I am looking for (think Alfred or Launchy). Searching for the password and hitting enter would type in the password into whatever field I previously had selected. Something open source would be perfect. I looked, but did…
I didn't come here to engage in sales pitches, but when you specifically ask for a feature introduced in 1Password 4, it is hard for me not to mention it. 1Password Mini lives in the Menubar and does what you wish. There are also options for Alfred and LaunchBar integration.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#87I never use password managers. The reason is simple: I don't want to rely on another software. If I had to remember 20 passwords I would and in fact I do carry around 10 different passwords in my head constantly. I trust my own brain rather more. And if my brain is comprised, what else can you do with all the security we have on our desktop?
Because 1) Over the years it ends up being much more than 20 passwords. Bank accounts, credit cards, stock trading accounts, web servers, email accounts, IRA accounts, bitcoin passwords/keys, all kinds of work passwords, evernote, etc. I have more than 50 records in KeePass. 2) If you want secure passwords, they must be long (20 characters minimum) and random. Remembering something like that is nearly impossible for…
Don't sign up hundreds of accounts. I only have one bank so that's just one password.
Relying on another software to take care of security like this is not a good solution to me.
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#88I use KeePass and I haven't integrated it into any of the web browsers I use. When I want to log into a site, I don't load it via my web browser's address bar; instead, I Alt-Tab to KeePass, Ctrl-F to find the site/account, Ctrl-C to copy my password, and Ctrl-U to open the site. This takes only a few seconds longer than using a browser extension like LastPass (which I've used to share credentials with family members…
is anyone aware of an smartphone app that allows your phone/tablet to act as a usb keyboard for a pc, and "type" passwords in for you?
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#89Earlier quoted context omitted.
I honestly think for security purposes in general you shouldn't auto fill in a form regardless of the domain and the extension builders should just not build that feature because it exposes issues like this.
[Disclosure: I work for AgileBits, the makers of 1Password] In 1Password 4, there is no auto-filling. People can use Ctrl-\ or Cmd-\ to tell 1Password to "fill this page". In versions prior to 4, auto-fill was an option. (I'm not sure which versions had what defaults.)
Re: Browser Extension Password Managers Exposing Passwords Everywhere
#90Earlier quoted context omitted.
I didn't assert that it was easier, just potentially more secure. Similarly, it's arguably annoying to only access financial accounts (and the email accounts that are associated with the financial accounts) using a dedicated banking computer, but I think that having a banking computer is worth it. Others will disagree.
[Disclosure: I work for AgileBits, makers of 1Password] One way of characterizing the particular paper is "password managers with browser extensions don't always prevent you from submitting your data to the wrong place." Systems that rely on the user to copy/paste offer no such protections whatsoever (and so, I suppose, can't fail at them.) So I'm curious about what you may mean by "potentially more secure" in this p…
For some people, the risk of disclosure by violence is more a worry than the risk of disclosure by the clipboard.