3 ms·
This is only true for cloud based password managers. I recommend using 1Password or KeePassX with Dropbox.
by Gee19 10y ago
This is only true for cloud based password managers. I recommend using 1Password or KeePassX with Dropbox.
- hackuser 10y ago> This is only true for cloud based password managers I agree, in the sense that one successful attack on the supposed centralized database containing all user credentials would have a high ROI. But it also applies to local password managers. If 20 million people use the same password manager and I have an exploit for it, if I'm in the business of stealing data I'm likely to find a use for my exploit.
- Gee19 10y ago'If 20 million people use the same password manager and I have an exploit for it' Someone is going to exploit my local password manager remotely?
- countingteeth 10y agoYes. If you don't think so, then just tell your browser to remember your passwords and don't bother with another tool.
- hackuser 10y ago> Someone is going to exploit my local password manager remotely? I don't know - who are you? Even if you are not an especially valuable target, malware is pretty widespread. It steals credit card numbers and other data; if the attacker had a hack for a popular password manager, why wouldn't they go for it?
- krick 10y agoMaybe I'm paranoid, but it still doesn't feel "safe" to me. Let's assume that KeePassX is truly unbreakable at the moment. I still fear losing my kdbx file, as if someday it will become vulnerable (maybe for technical reasons, or maybe just because of master-password exposure) I'd lose much more than any single of the accounts there: even if passwords there will be outdated already, it will be exposed that all these accounts belong to one person with known identity. All bank accounts, credit cards, email addresses, messengers, accounts on some shady forums. And if passwords are not outdated — oh my God… It may be unlikely, but it's still putting all eggs in one basket. Just one failure, and you are truly fucked.
- noir_lord 10y agoI guess you have to balance the probability of that kind of breach in Keepassx against the probability of fucking up and forgetting a password or reusing passwords (I still see this) across multiple services. If you have an eidetic memory and can remember 20 digit random passwords for every service after securely generating them then keepassx increases your risk. If however you behave like a 'normal' user and use the same one or three passwords on everything I'd estimated keepassx improves your security.
- krick 10y agoFWIW, I do use a password manager. But what you say is pure speculation. I don't see any formula for how should I estimate risks here, and the common narrative amongst security folks is "hooray password managers!". I'm often giving that advice myself, but honestly, I'm doubting it more and more. The truth is that I don't give a fuck about losing 90% of accounts I use (and I guess I'm not the only one). Many of them I could even give you myself as a birthday present. Using password manager as a rule of thumb would imply that these accounts are as important as the most important ones. Which is nonsense. Even if we discard all the disposable accounts, I still doubt that losing your twitter would hit you nearly as hard as losing your main email account or bank account. However, exposing that all these trash accounts are mine might make me feel uncomfortable. If that makes sense, then we must actually stop using the rule "password managers FTW" and start using the rule "consider how important is every given account to you, and treat it accordingly, chosing between several kdbx files". Which is much more complicated rule, obviously. I would even say it creates much higher mental load than remembering several sufficiently complicated passwords.
- incompatible 10y agoI use KeePassX. I think the easiest way to break it (on Linux, at least) would be to get a program running on the user's machine, using a browser exploit or whatever, which would make a copy of the database and also sniff the X keypress events on the KeePassX window to get the master password. I don't know if it has any defence against that.