5 ms·
But single point of failure and also clipboard attacks! :(
by throwaway729 10y ago
But single point of failure and also clipboard attacks! :(
- mattcoles 10y agoClipboard attacks are definitely concerning but with 2FA you can mitigate it being a single point of failure to some extent.
- jwilk 10y agoWhat do you mean by "clipboard attack"?
- xeroaura 10y agoFor sites/apps that can't fetch the password themselves, people usually copy paste the password. This could allow other sites/apps that have access to the clipboard to see the password.
- jwilk 10y agoWhy would you ever let a site or an unstrusted application access your clipboard?
- duozerk 10y agoBecause you usually don't have control over that. On lots of system, any application that can display an UI can access the current clipboard's contents.
- chongli 10y agoIs there any way to globally disable clipboard access in my browser? Jeez, this sounds horrifying!
- duozerk 10y agoI believe the browser is one of the few applications that already take this into account, fortunately. Clipboard access from Javascript is secure, for example.
- maxerickson 10y agoTaking a step back from the problem, users do usually have some amount of control over what is running on a system. I mean, I understand that computers managed by typical users will be a shitshow, but much of the problem in that situation is that they don't really care.
- dcosson 10y agoI think you're more protected in the browser. On iOS any app can access the clipboard without having to ask for any permission. The encryption scheme on iOS is nice, but for how much of a game they talk about privacy Apple had the opportunity to do so much more for security around identity/auth and they did approximately nothing.
- spullara 10y agoAnother good reason to use iCloud Keychain rather than one of the 3rd party ones.
- tmalsburg2 10y agoCorrect me if I'm wrong but if you install a malicious application, aren't you screwed anyway, password in clipboard or not?
- Buge 10y agoOn desktop yes. But on mobile, where every app is sandboxed to some degree, not necessarily. Keepass2Android prevents clipboard attacks by installing a keyboard that autotypes your password, never letting it get to the clipboard.
- amelius 10y agoInteresting approach. But keyboards are quite personal (some people choose their keyboard), and there's quite a lot of technology in keyboards (gestures to text, learning dictionaries, et cetera), so I'm wondering about the quality and user-friendliness of the approach.
- x1798DE 10y agoYou only use the keyboard to enter the password, not in general. When you open the database and select an entry, it offers to switch to the password keyboard for you, then when you are done you switch back.
- eikenberry 10y agoSingle point of failure is mitigated by proper backups. Clipboard attacks are mitigated by your password manager clearing your clipboard after paste (either by event or by time).
- mattcoles 10y agoIt's still a single point of failure if the password manager is compromised.
- eikenberry 10y agoWhat password management solution doesn't have this aspect?
- __ddd__ 10y agoRandom pass phrases written in uv marker on the underside of your desk, in a notebook (bonus: you can burn it once memorized) scrambled and/or hidden among decoy passphrases. Make the phrase long enough (high enough entropy) that you have enough time to memorize it and use it before it should be rotated. Whether you like this implementation or not, the solution is to choose better passwords.
- Buge 10y agoIf your house burns down, you lose your passwords. If somemone (burglar / law enforcement / intelligence agencies) breaks in, they have your passwords. If you are memorizing a lot of passwords (I have 500+ in my password database) you are surely going to forget rarely used ones. If passwords are written down, they can be demanded from you by a warrant/court order. If they are memorized, they cannot.
- landryraccoon 10y agoCracking a piece of paper can't be automated. A human being has to break in and find and steal it. Most of us are high value enough for a script kiddie to want to steal our credit card numbers, few of use are valuable enough for someone to break into our home just to look for a password. If your passphrase is an innocuous phrase, like "red dogs like spicy food", how will they you know you have a password to demand? How do they know you have a piece of paper instead of having it memorized?