Earlier quoted context omitted.
> I am pretty sure 99% of people would halt at 'gpg' Please do not mock gpg. I have been using gpg for 25 years now (and PGP before that). It works. It encrypts. It decrypts. It is in vogue to mock gpg on HN and recommend more modern solutions. As an experiment, I tried adding one of those modern tools (rage) to my ansible configurations, just so that they get regularly installed and maintained on my servers (without…
Not their point tho. Me too, gpg, no problem. Heck I had the "'smuggled' out of the country as a book" pgp back when. My kids? I really am not so sure at all. Still too early to tell for sure but so far I don't think any will be as technically savvy as I am. I really doubt they'd know what GPG (or PGP) are and how to use it.
Feds Link Cyberheist to 2022 LastPass Hacks
91–100 of 266 posts
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#92Earlier quoted context omitted.
I was under the impression that basically lastpass knew your password, 1password does not. Lastpass owned the whole key. With enterprise organizations though we can still reset a users password if they forget so 1password might “know” your password too. Maybe older versions or individual versions are more secure.
It would probably be more accurate to say that LastPass has the information to decrypt your vault if they can guess your password. By contrast 1Password would need to both guess your password and guess your personal secret key. The latter is effectively impossible assuming the key generation was well-implemented. The trade-off is that users must keep track of their own secret keys.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#93Re: Feds Link Cyberheist to 2022 LastPass Hacks
#94Me, looking at my local KeepassXC, calm, sticking with it.
This is the kind of control that is really becoming a luxury. And I don't know how we get back to a simple state; Let's say you're a family of three with shared services and accounts: Keeping everything under Keepass means handling the file sync between all the devices and OSes, with potentially your credentials flying through third party sync services, thus negating most of the advantages of Keepass. Moving to somet…
If everyone has only apple devices (iphones + macbooks), then you can use a shared iCloud sync'd folder.
Except that doesn't actually work because the majority of iOS apps are incapable of using a shared iCloud folder correctly (including apple's notes app, most of apple's apps) because apple tries to hide the filesystem so much, that even saving a file into a folder is basically impossible for most apps.
That also doesn't work if anyone uses linux or windows because apple refuses to play nice with other ecosystems.
If everyone _doesn't_ use iOS devices, there are dozens of solutions that work well, from a shared google drive folder, to syncthing, but if even one person uses an iOS device, then suddenly none of the shared folders work, because apple has made it so creating a shared folder on iOS is bad for iCloud, but even worse for any third party app (be it google drive, syncthing, an FTP based solution, etc etc).
I guess what I'm saying is that apple tried to kill the filesystem, and in doing so has made it so the very idea of just sharing a folder of files securely seems like a per-app luxury.
Instead you need a shared photo album for photos, a shared notes folder for notes, a shared "apple invites invite" for a calendar event, etc etc. Apple has a lot to pay for, and a hatred for folders that has caused the entire industry to move away from simple secure app-independent sharing is one of them.
Instead, we have a jumble of apps being forced to implement their own sharing concepts poorly and often insecurely.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#95Earlier quoted context omitted.
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
"Hey llm how do I open this file?" It's kinda ludicrous to think we'll lose the ability for something so simple.
Sorry, but I already have to google each time I want to figure out how to open various file formats.
"Google, what ffmpeg flags do I use to convert this .flv file to .mp4", "what are the flags to losetup or kpartx to mount 'disk.img' as a loopback device?", "how do I extract an '.ab' backup from 'adb backup'?"
These are all things I googled before llm.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#96Earlier quoted context omitted.
It would probably be more accurate to say that LastPass has the information to decrypt your vault if they can guess your password. By contrast 1Password would need to both guess your password and guess your personal secret key. The latter is effectively impossible assuming the key generation was well-implemented. The trade-off is that users must keep track of their own secret keys.
How does that work with sharing vaults between devices?
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#97Earlier quoted context omitted.
Bitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypt…
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
I know reading the docs is considered uncool for some reason, but it really does work.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#98What do security minded people do about passwords? It seems like you either use the same password for everything, or you need some kind of password manager, but then I'm always worried about having all my passwords in one place meaning they all get compromised instead of just one. It also feels like there's a convenience tradeoff with a lot of solutions. I could keep a physical binder full of passwords in my home off…
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#99Sharing a short post I posted a year ago with some thoughts on password managers. ## The password-management promise > I don't buy the promise behind 1Password or LastPass. > You only need to remember one password. The last password you'd need to remember. > They don't tell you that you're also building a one-stop shop for hackers to steal it all at once. > The solution? > Store hints, not passwords. > Don't reuse pa…
So even if they know my 1password username and password they still can't really do anything with it. And if they steal my device, they would need to know my login password. Or cut off a finger, I guess, but I've got bigger issues if that happens.
They don't all work this way, but 1Password seems to be by far the best and most secure option, and IMO the convenience of an online password vault simply outweighs the tiny risk with a proper vault like 1password.
No idea why anyone has stayed with LastPass after the fiasco a couple years ago though.
Re: Feds Link Cyberheist to 2022 LastPass Hacks
#100Earlier quoted context omitted.
>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
"Hey llm how do I open this file?" It's kinda ludicrous to think we'll lose the ability for something so simple.