4 ms·
For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anythi
by Gruselbauer 10y ago
For me it was a case of thinking I know better. As in, "no way I'm giving you my passwords" and "who knows how tight their opsec is" ... never even tried anything like LastPass or 1Password until six months ago.
Now I cannot imagine going back. My LastPass subscription is among the most vital services I pay for and the sheer freedom of having to remember one diceware-style master password instead of maintaining my own local database is just too nice.
I'm using banking software with a HBCI card and have set reasonable limits on all things like PayPal. So if you cracked my LastPass vault - good luck with that, 2FA considered - you'd be well able to ruin my digital life. But you would not get much out of it.
The attack surface I offer in total has shrunk a lot, too. Unique, maximum allowed length passwords for every unimportant little account and no need to memorise a single one.
It's to Web logins what pubkey auth is to ssh for me personally. Just such a freaking blessing.
- __jal 10y ago> So if you cracked my LastPass vault - good luck with that, 2FA considered Well, the traditional[1] way to break[2] LastPass is to ignore individual accounts and go after poor coding technique[3]. 2FA won't help you there. [1] https://www.wired.com/2015/06/hack-brief-password-manager-lastpass-got-breached-hard/ https://www.wired.com/2015/06/hack-brief-password-manager-la... [2] https://techcrunch.com/2011/05/05/password-manager-last-pass-possibly-hacked/ https://techcrunch.com/2011/05/05/password-manager-last-pass... [3] https://labs.detectify.com/2016/07/27/how-i-made-lastpass-give-me-all-your-passwords/ https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...
- Gruselbauer 10y agoI'm probably the least knowledgeable person on HN so please understand these as questions more than objections, okay? I would think the first link doesn't affect me since I use a fairly strong unique master password and haven't set an insecurity question. As for the second link, much the same. I mean I'm fairly certain I can create an encrypted plaintext file that withstands extensive cracking attempts with standard Linux tools. These kinds of attacks would suck for people using 'lastpassword' as their master, if the stored vaults were unhashed and unsalted. Even then, how would that circumvent 2FA? Without my phone or Yubikey or whatever, you still don't get in. As for the last one, and generally for most criticism: these tools give you the means to be more secure, they even encourage you by asking things that must annoy the average user. There's no unlimited trust for devices or browsers, the security checker is actually quite helpful in identifying possible problems - like my banking password being capped at five digits by design... sigh - and telling you when you're getting dumb ideas, like permanently storing your master password on your phone. So in the end, it's up to the user isn't it? It's not using it by itself that makes the concept an increase in security, it's using it thoughtfully that is.
- stouset 10y ago> For me it was a case of thinking I know better. I'm deeply curious: why? When virtually every reputable security practitioner on this site and others has echoed the advice to just use a password manager for years, how do you come to the conclusion that you know better than them? If it sounds like I'm asking judgmentally, please don't interpret it that way. Your experience mirrors that of many others, and if I can understand how this line of thinking happens then maybe we can find ways to combat it. This is just one battle amongst many where, despite endless warnings and examples to the contrary, people seem to think they are qualified to go against encouraged practice for password storage, password management, encrypting data at rest, encrypting data over the wire, etc. And in almost all cases, people come to the conclusion that they know better, when they absolutely do not.
- deleted 10y ago[deleted]
- Gruselbauer 10y agoIt's cool! I've been wondering too, since it's been an eye opener without equals finding out just how wrong I was. I think there were multiple lines of reasoning going on: - "I don't even use that many logins." I do. I just abused 'reset password via email'. - "I distrust the cloud provider's opsec." Seriously? I'm a self taught amateur. Get a grip guy. - "What if they give my passwords to the NSA?" ... at this point I want to slap myself. - "How can it be secure if it's easy to use?" I blame PGP for this one... So I guess many things. In the end it was the usual mix of uninformed bias, weariness against third parties in security, being very wrong and the assumption that security needs terrible UX. As I said, I never looked back. I've even sat down with friends and family, explained the concept and turned their '$catsname$birthyear' passwords they used for absolutely everything into security they wouldn't ever hope to achieve otherwise. And they're all so freaking happy, too. For their master passwords I used the 'correct horse battery staple' approach and nobody has a problem remembering one of those, especially if it's in their native language. So, yup, you're right in every way. I didn't know better.
- OskarS 10y agoI think the reason is that it just feels insecure. If you keep all your passwords in your head, then you have full control. Using a password manager means handing them off to something else, whether it is a paid service, a piece of software, or whatever. It feels like a "cat's out of the bag situation", that once you let the password escape that first container (your mind), it will inevitably spread everywhere. I'm not saying it's rational (I'm a happy customer of 1password), but there is something a little bit scary about letting go of control of your passwords.