12 ms·
Flaws in deterministic password managers
- libeclipse 10y agoI'm the creator of visionary[0], a deterministic password generator that the article links to. When I thought of the idea (quite a while ago), I thought it was a good idea, and I thought I was the first one there. I was wrong on both accounts. The points that the article makes are right, and people should use conventional passwords over deterministic ones. But I guess it appeals to a certain small subset of people. For some servers and things that I own I find myself using it sometimes: it turns a relatively strong password into a monster of a password. Another useful use is that it's good at sharing passwords for things with friends, and for that, it's surprisingly handy. For the average person however, the disadvantages and the things that could go wrong outweigh the advantages. Keepass is what you should be using. [0] https://libeclipse.me/visionary/ https://libeclipse.me/visionary/
- tprynn 10y agoNot to be too pointed, but would you consider adding this disclaimer to your blog post and github repo? Hopefully that will inform potential users before using a system that could leave them less secure.
- ogrisel 10y agoFunny, I also implemented mine a while ago (mostly un-maintained but I still use it): https://pypi.python.org/pypi/virtualkeyring/ https://pypi.python.org/pypi/virtualkeyring/ I also thought I was clever and the first to do it ;) I have been thinking about adding support to keep some state info in a yaml file to deal with revocation and specific varying password policies (e.g. in a dropbox synced folder) but I was too lazy to implement it. If someone wants to do it please feel free to send a PR. The compromised master password issue is a real issue though.
- Nomentatus 10y agoUse a photo as the master password. It can't be confused with text.
- minitech 10y agoThis change seems kind of worrying: https://github.com/libeclipse/visionary/pull/40/files#r79336188 https://github.com/libeclipse/visionary/pull/40/files#r79336... The distribution of characters in “complex passwords” isn’t even?
- libeclipse 10y agoThat doesn't matter. I could just put a full stop at the end of the string and call it a complex password. The point of it was for sites that require symbols. The complex password doesn't add a meaningful amount of entropy to a sufficiently long normal password; a 32 character normal password already has log2(16^32) = 128 bits of entropy. We rely on the seed for security, the seed being the hash that scrypt spits out
- minitech 10y agoSo it’s way too complicated for that purpose, then.
- libeclipse 10y agoThat's not an argument. Keep in mind that entropy is a property of password generation, not the result of the generation.
- minitech 10y agoI mean, what do you want me to say? It is way too complicated. Why are you using a pre-shuffled character set and getting a permutation of it by index when the index is always extremely low compared to the number of permutations just to get some symbols in your password? Just base64-encode with a custom alphabet or something. I never said anything about entropy, either.
- ythn 10y agoThe only deterministic password manager you need is your own mind. Come up with a set of password rules that are generic enough to accommodate all these issues. For example my deterministic password manager might be: 1. random english wordx2 + first 4 letters of registered domain, all caps + remaining lowercase + number of letters in domain (integer) + symbols associated with digits of the integer digits 2. If site doesn't allow special characters, remove them 3. If site requires a shorter password than the generated one, trim the minimum number of characters from the front of the password until the criteria is met. So, using my above rules my password for Ycombinator would be: coppercopperYCOMbinator11!! If the site restricts passwords to max 12 characters, it would become: Mbinator11!!
- deleted 10y ago[deleted]
- IshKebab 10y ago> If the site restricts passwords to max 12 characters The problem with this is that most sites are designed by idiots and don't state their pointless password rules on the login page - only on the 'change password' page. So you can be trying your coppercopperYCOMbinator11!! password and thinking "why the hell doesn't this work?", then after 10 minutes you give up and go to change it and see "Your password must be between 8 and 12 characters and contain a symbol." So infuriating.
- ythn 10y agoThat's very true. I forgot to mention that I also have a spreadsheet that has site-specific password rules so that I can do a lookup and see how I need to adapt my generated password. Maybe what we really need instead of deterministic password generators is an authoritative database that tracks the password rules of all the different sites on the internet so we can easily look it up and/or publicly shame companies with asinine password policies.
- pavel_lishin 10y ago> I forgot to mention that I also have a spreadsheet that has site-specific password rules so that I can do a lookup and see how I need to adapt my generated password. So you do have a password manager. > Maybe what we really need instead of deterministic password generators is an authoritative database that tracks the password rules of all the different sites on the internet I'm glad to hear you volunteering to look up all of these policies, and keep them up to date!
- ceronman 10y agoTwo extra advantages of vault based password managers: 1. The manager can automatically change old passwords for you. LastPass support a big set of websites, when Dropbox was hacked this was very handy. I like to change social media passwords every few months and this makes it very easy. 2. You can store passwords that you can remember if necessary. Sometimes I need to access a password for a service or a site in an environment where I don't have an easy access to my password manager, for example when I'm using a friend's phone or when I SSHd into another machine. In those cases is handy to have some passwords that you remember, but are stored in the vault just in case you forget them. I only do this for a few passwords, but it's a nice feature to have.
- dvdkon 10y agoI don't agree with the author on many of his points. 1 and 2 are "merely" convenience features. Sure, those things make a truly stateless password manager harder to use and a very niche tool, but they're by no means fatal flaws. 3 is a good argument, but storing existing secrets is by definition out of scope for password generators. It is a usability problem, which makes using a truly stateless password generator as the only password manager harder, but still not a fatal flaw. The fourth one is in my opinion the only one which could be called a fatal flaw. It's probably the thing that has to be considered the most before using a master secret password generator. The hyperbolical title annoys me, but what annoys me probably even more is that the author then recommends (not directly, mentions as his personal choice, but that counts as a "seal of approval" for me) a closed-source cloud password manager, which could possibly be less secure than a password generator.
- pavel_lishin 10y ago> Sure, those things make a truly stateless password manager harder to use and a very niche tool, but they're by no means fatal flaws. If the Deterministic Password Generator does not generate a valid password for a given site, it's certainly a fatal flaw for that site, and a usability nightmare - now I have to remember which sites aren't supported and keep a vault anyway. And I guess point 2 isn't a fatal flaw until you need to change a password for whatever reason, but after that it becomes quite a problem.
- dvdkon 10y agoWe both seem to have a different view of what a "fatal flaw" is. For me (especially when talking about a computer security tool), it means a very serious security vulnerability and nothing less. You seem to have a more relaxed view, accepting things that create a bad user experience as fatal flaws, too.
- the_af 10y agoRegardless of whether it's "fatal" or not, usability is crucial. If it's impractical or impossible to use in common scenarios, that's a huge flaw.
- slaymaker1907 10y agoI thought I'd make an account on contribute on this issue as the author of a (probably pretty bad) password manager https://slaymaker1907.github.io/password/ https://slaymaker1907.github.io/password/, source code at https://github.com/slaymaker1907/password-hasher https://github.com/slaymaker1907/password-hasher. There definitely is an issue with some websites having strange requirements, but the way I get around it is keeping an drive sheet with all information used to generate the password (except for the master password of course). This does add some state, but I find that for common passwords I memorize the method of generation very quickly. There is a central point of failure if the master password is compromised. However, this can be mitigated by first choosing and memorizing a very strong master password as well as versioning passwords by storing the name of the master password used with the rest of the info (though obviously not the master password itself). Additionally, I find the threat model under which such compromises to not be very convincing assuming you choose a strong master password compared to the common case of simply needing to change a password key on the site from linkedin1 to linkedin2 in case of a password database breach. One weakness of password vaults is that they don't have the advantage of working without access to the vault. While my method can store state as mentioned above, it is very easy to memorize this state, particularly for common/important passwords and has actually saved my bacon before. Finally, something that I think is a significant strength to a manager but a weakness for managers is that I can and do use my manager for passwords that I need to type out, most often using a feature that translates the password into a password similar to a diceware password (I use a significantly shorter dictionary since dictionary length does not affect the entropy density of a password very much and it makes them easier to type/remember if only using common words). Using this feature, I've been able to create separate passwords for my desktop, laptop, and phone that are both easy to remember as well as having good entropy (when I compute entropy I do assume that an attacker knows the method of generation).
- clark800 10y agoI've been surprised by how negative the opinions of deterministic password managers have been since I've been using one for over two years and it has been a much better experience overall than using KeePass on Dropbox, and I also think that it's more secure than cloud-based systems (see point 4). My take on the points in the post: 1. Out of the 100 or so sites that I use, only a few have password policies that require tweaks, and it usually just requires disabling symbols and or adjusting the length. These tweaks are cached in my browser, so this hasn't been much of an inconvenience. 2. My passwords are rarely revoked, and when they are it is just a counter bump. This is state, but again it is cached in the browser. 3. It's true that they can't store existing secrets, but this can be viewed as out of scope for a password manager. 4. For the application I use, it's not true that exposing just the master password exposes all of your site passwords. There is a 512bit private key that is synchronized once between devices using a QR code. An attacker would need both the master password and the private key file to generate any passwords. Because the private key only exists on devices I physically own, this should be harder to obtain than an encrypted database that lives in the cloud, so I view this system as more secure than KeePass on Dropbox, Lastpass, or 1Password. My experience over the past two years has been that the advantages are more significant than the disadvantages.
- pwinnski 10y agoIf your browser is caching all of your passwords, I think you've got security problems well outside the scope of your choice of password managers.
- eikenberry 10y agoI'd guess he doesn't mean cached, but instead means that his web browser works with this system keyring (or has its own) to save/use the passwords.
- problems 10y agoWhich is bad. I've reverse engineered script kiddie malware far too many times to find them shipping "iStealer" and similar, which basically just dump browser password stores and send them to a gmail or FTP account. Often these pieces of malware include the SMTP credentials to the same gmail account or FTP access to download the results. And having seen their results, let me just say, these script kiddies can do damn well with this tactic. Do not use a browser/system keyring store under any circumstances unless you can be 100% positive that you won't accidentally run that sketchy exe you came across. If you use Keepass, it presents another layer, they have to actually get your keepass password too, or dump your database when it's logged in. Often something like that won't be hit by script kiddies but certainly would in a targeted attack. The best practice here is to run Keepass on a separate machine to prevent an all-at-once dump. Even a separate machine on the same network where you use Synergy or similar to sync the clipboards would probably be sufficient. Anything worth more than dirt should of course have 2FA, which is why I also suggest a tiered password system (ie: junk password for common and worthless sites, separate passwords for banking, etc) and 2FA as an alternative to a real password manager.
- pwinnski 10y agoToday I learned that many people on Hacker News have really insecure web security practices. :( I don't understand the resistance to using a vault-based password manager. Is it inertia? I mean, if you're using the same one or two passwords on every site, then sure, it may not seem worthwhile to us 1Password. But then, enough password hashes have been leaked this year alone to suggest that you need to do something better.
- Gruselbauer 10y agoFor me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago. Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my own local database is just too nice. I'm using banking software with a HBCI card and have set reasonable limits on all things like PayPal. So if you cracked my LastPass vault - good luck with that, 2FA considered - you'd be well able to ruin my digital life. But you would not get much out of it. The attack surface I offer in total has shrunk a lot, too. Unique, maximum allowed length passwords for every unimportant little account and no need to memorise a single one. It's to Web logins what pubkey auth is to ssh for me personally. Just such a freaking blessing.
- __jal 10y ago> So if you cracked my LastPass vault - good luck with that, 2FA considered Well, the traditional[1] way to break[2] LastPass is to ignore individual accounts and go after poor coding technique[3]. 2FA won't help you there. [1] https://www.wired.com/2015/06/hack-brief-password-manager-lastpass-got-breached-hard/ https://www.wired.com/2015/06/hack-brief-password-manager-la... [2] https://techcrunch.com/2011/05/05/password-manager-last-pass-possibly-hacked/ https://techcrunch.com/2011/05/05/password-manager-last-pass... [3] https://labs.detectify.com/2016/07/27/how-i-made-lastpass-give-me-all-your-passwords/ https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...
- 10y ago
- m3rc 10y agoDo people really complain that size is an issue in syncing password data? The author of this article's file was 512 KB, personally mine is 10 KB. That's basically none.
- Retr0spectrum 10y agoI have an irrational(?) fear of vault password managers. I see it as a single point of failure. Furthermore, the more "useful" they become, with browser extensions etc., the greater the attack surface becomes. Because of this fear, I generate random passwords and memorise them, which is not ideal.
- hackuser 10y ago> the more "useful" they become, with browser extensions etc., the greater the attack surface becomes Also, the more popular the password manager becomes, the more valuable cracking it becomes. One exploit can yield the email, banking, workplace, confidential document, and other passwords for many millions of people. If you are an attacker, it would be worth it to have the exploit on file, proactively, for the next time you attack someone using that password manager.
- Gee19 10y agoThis is only true for cloud based password managers. I recommend using 1Password or KeePassX with Dropbox.
- hackuser 10y ago> This is only true for cloud based password managers I agree, in the sense that one successful attack on the supposed centralized database containing all user credentials would have a high ROI. But it also applies to local password managers. If 20 million people use the same password manager and I have an exploit for it, if I'm in the business of stealing data I'm likely to find a use for my exploit.
- Gee19 10y ago'If 20 million people use the same password manager and I have an exploit for it' Someone is going to exploit my local password manager remotely?
- Scaevolus 10y agoAnother flaw: deterministic password managers are inherently vulnerable to brute forcing-- it's basically like sending your password database to every site you log into. Ideally they use a very expensive KDF, but I've seen implementations that use weak derivations like 10,000 round PBKDF2.
- minitech 10y agoUse a master password that’s impossible to brute-force, then. (128 bits.)
- ofek 10y agoThis is a good one (from what I've heard) https://github.com/habnabit/passacre https://github.com/habnabit/passacre
- minitech 10y agoI use a deterministic password generator so all I have to remember is my master password and default password scheme to get access to all my critical accounts (critical ones generally don’t have silly password requirements). If I were using something that stored passwords and lost my database somehow, I’d lose access to all of those.
- macintux 10y ago"lost my database somehow" I have mine in Dropbox and at least 3 devices. I'm really not concerned I'll lose it.
- lucaspiller 10y agoSame here. Plus my email uses a different strong password I remember, so if worse comes to worse, I can just reset everything.
- minitech 10y agoIf I were out of country and my laptop got stolen, for example, I’d lose it. Sure, you can use a separate password for your Dropbox/email/etc. that you remember, but that’s pretty much the same thing as generating based off a master password. (With the exception of your master password being brute-forceable based on any password you generate, but you just use a master + KDF combo that’s unbreakable to prevent that.)
- bradvo 10y agoI agree with the author's opinion with the master password being compromised, you're done. I have found an elegant solution for managing my passwords with http://masterpasswordapp.com/ http://masterpasswordapp.com/ the iOS app is a breeze and I also use the export feature to backup my login names, hashed passwords, custom passwords, and stored secrets. This app in particular solves the author's third point. For the second point, I save the iteration X of a password as a stored secret when I need to revoke a password. It doesn't sacrifice the user experience in my opinion.
- BuuQu9hu 10y agoWhen will we stop using passwords?
- kristianp 10y agoOn a related topic, a number of Bitcoin wallets have moved to hierarchical deterministic (HD) addresses and they market that as a positive.