9 ms·
Vulnerabilities in Password-Manager Apps
- Globz 10y agoWe need the same kind of investigation for iOS, this kind of research was so much needed because after all this is where we store all of our entire internet identities, good job!
- SeriousM 10y agoWhat about enpass? That would be very interesting since they also promise to be very secure.
- pards 10y agoI'd love to see a similar analysis for EnPass
- tmd83 10y agoMe too. While I'm still not using the mobile app I use their desktop one. Would prefer to know if there were any overall security audit of Enpass or some expert has some thought. But if their android app is good it would at least give some idea of their competence.
- SeriousM 10y agoThe mobile app is nice, I use it every day. The only issue is that it doesn't work that well with Firefox but Chrome.
- pedrogpimenta 10y agoThey all do, don't they? I don't imagine some Password Manager saying "We're kind of secure. We take security seriously-ish".
- hackuser 10y agoTyping "Secure password manager" requires keyboard skills. Developing one requires much more.
- toyg 10y agoI looked at the LastPass ones (all for Android) and they look relatively minor. The only real wtf is https://team-sik.org/sik-2016-022/ https://team-sik.org/sik-2016-022/ - hardcoding keys should be a big nope. Still, it happens only if you use a PIN rather than your master password; I hope this does not happen in iOS if you use TouchID...?
- MBlume 10y agoThe very bottom of that report says the vulnerability was fixed last September, which seems like burying the lede
- Arcsech 10y agoTouchID on iOS uses the Secure Enclave, so hardcoded encryption keys are unlikely for anything that uses TouchID.
- bad_user 10y agoI have such a strong password that typing it repeatedly on a mobile device isn't doable. And so I use PINs or fingerprints, depending on device. I find this acceptable because I worry less about physical access to my device, versus somebody gaining access to my encrypted database, which is also stored on Dropbox. But I still expect that storing the master password locally is secure, otherwise why the fuck am I paying them for? Speaking of LastPass, I've noticed them doing stupid things like this in the past and the problem is that I feel those bugs wouldn't have been discovered and made public if they weren't so popular. And I expect such a company to take security seriously, because this is what they sell. Hard-coding a symmetric encryption key isn't a minor slip up, this is the kind of mistake that I for one couldn't do, even though I'm no security expert. If they could do such an obvious mistake, then I can't trust them, regardless of their response time.
- bgentry 10y agoSite's down. Text-only cached version at least lets you read some of the content: http://webcache.googleusercontent.com/search?q=cache:kJ5Zk-7KPswJ:https://team-sik.org/trent_portfolio/password-manager-apps/&num=1&hl=en&gl=us&prmd=ivn&strip=1&vwsrc=0 http://webcache.googleusercontent.com/search?q=cache:kJ5Zk-7...
- AdmiralAsshat 10y agoSo, all three of the LastPass issues have been fixed, and within two weeks of being reported, to boot: * 2016-08-22 Vulnerability Discovered * 2016-08-24 Vulnerability Reported * 2016-09-06 Vulnerability Fixed
- ejcx 10y agoThe folks over there work really hard and care a lot. I'm sure that's the same with all the password managers too, but I know personally having worked at LastPass how much the founders care.
- bad_user 10y agoHard-coding the symmetric encryption key used to store your master password isn't just a minor slip up. This is the kind of mistake that I for one wouldn't do and I'm no security expert. At least for proprietary apps, security is about trust. Given their other slip ups in the past, along with present design choices like making certain administration tasks available only through the web interface, I wonder how people can trust LastPass. Of course, it's better than not using a password manager at all. But one has to admit the bar for that is pretty low.
- lm2s 10y agoI get baffled at how such basic security mistakes are made. Either who did them doesn't care or doesn't know, of which neither is good for - at least - applications that store such sensitive information.
- Zombieball 10y agoTo be fair, unless I misunderstood, the symetric key is only used when you save your master password (so you don't have to re-type it) and use a PIN instead. I believe LastPass app encourages you to NOT do this. This obviously doesn't excuse the implementation (it shouldn't of gotten past CR). Just pointing out the attack vector is not as severe as it seems (at least from the issue's title).
- cjCamel 10y agoLooks like all of the 1Password issues were discovered and fixed last September.
- M_Grey 10y agoThis is why I still go to the trouble of PGP encrypting a file with my passwords, rather than relying on a password manager. I keep wanting to switch, but damn it, I just can't bring myself to have that much trust in them. Edit: Thanks for the informative replies, the links, and the advice. I'm going to explore all of my options and re-think this.
- Xylakant 10y agoYou may want to look at pass, which is pretty lightweight scripting around gpg to store passwords in multiple files. Some tradeoffs required, but works well and fully auditable
- Freak_NL 10y agoPass¹ is very nice, and you can even share a part of your password library with someone else by using their GPG public key (encrypting just those files with both your keys) and sharing the shared directory via some sharing utility such as SyncThing². Pass also supports using git for change management. 1: https://www.passwordstore.org/ https://www.passwordstore.org/ 2: https://syncthing.net/ https://syncthing.net/
- storrgie 10y agowhy use syncthing when pass supports git?
- Freak_NL 10y agoBecause with git you have to explicitly push. Both have their valid uses; I use the git solution for a devops password database shared with a small number of colleagues. I use SyncThing to share a common subdirectory of a private password database with my partner. SyncThing has the benefit of transparently handling the synchronisation behind the scenes for me. Whenever I place something in pass in the 'shared' subdirectory, it will end up in her database as well as soon as both our devices are online.
- deleted 10y ago
- kqr2 10y agoSome older papers on security vulnerabilities of password managers: https://www.schneier.com/blog/archives/2014/09/security_of_pas.html https://www.schneier.com/blog/archives/2014/09/security_of_p... Any thoughts on Bruce Schneier's PasswordSafe password manager?
- stcredzero 10y agoAnother password vault analysis paper found that one to be the safest they found.
- cjak 10y agoWould you have a reference for that?
- stcredzero 10y agohttps://www.cs.ox.ac.uk/files/6487/pwvault.pdf https://www.cs.ox.ac.uk/files/6487/pwvault.pdf
- seanieb 10y agoAnd heres another good one: https://people.eecs.berkeley.edu/~dawnsong/papers/sec14-paper-li-zhiwei.pdf https://people.eecs.berkeley.edu/~dawnsong/papers/sec14-pape... "The Emperor’s New Password Manager: Security Analysis of Web-based Password Managers"
- deleted 10y ago[deleted]
- photon-torpedo 10y agoThe good thing about PasswordSafe is that the file format is well documented, so there are several implementations of password managers using this format, which should all be interoperable. For Android, there is the app PasswdSafe. It also offers its own keyboard for entering passwords. Sad to see they didn't test this one...
- spullara 10y agoI just use iCloud keychain. The third party ones can never be as secure. For non-safari usage a little less convenient but worth it.
- growse 10y agoWhy can they "never be as secure"? Especially compared with iCloud, which I believe has a history of being vulnerable to all sorts of attacks...
- 95014_refugee 10y agoWhy do you "believe" this? Is this like a "belief" in the healing power of crystals, or of the bumps on your head being indicative of your personality, or do you have something substantial to share?
- growse 10y agoMy healing crystals are mumbling something about 'social engineering' (https://www.hackread.com/apple-users-icloud-phishing-attack/ https://www.hackread.com/apple-users-icloud-phishing-attack/), 'poor access controls' (http://mashable.com/2014/09/04/i-hacked-my-own-icloud-account/#h8v_cYPZJGq1 http://mashable.com/2014/09/04/i-hacked-my-own-icloud-accoun...) and 'poor authentication controls' (https://www.google.co.uk/amp/www.cultofmac.com/280189/icloud-hacker-calls-apples-response-little-late/amp/ https://www.google.co.uk/amp/www.cultofmac.com/280189/icloud...). Seriously though, I'm more interested in the assertion that any password manager can never be as secure as iCloud, even ones which don't upload data to the 'cloud'.
- pfg 10y agoiCloud and iCloud keychain are not really the same thing. iCloud keychain is designed not to disclose user passwords in the event of an iCloud account compromise, for example, among other things. The iOS Security Guide[1] has more details on this topic, starting on page 45. That's not to say other solutions can never be as secure, but it's a fairly good design nevertheless. [1]: https://www.apple.com/business/docs/iOS_Security_Guide.pdf https://www.apple.com/business/docs/iOS_Security_Guide.pdf
- tptacek 10y agoA theme of this work is vulnerabilities in the "internal browser" some of the mobile password managers provide. Mobile password managers have internal browsers because it's not easy to extend the standard mobile browsers, and password managers want to automate the entry of passwords into form fields. Don't use the internal browser of your password manager, no matter which one you use. There's too much that can go wrong, and the small convenience just isn't worth it.
- robryk 10y agoWhich way of passing the password to the browser is better? If I use the clipboard, many apps can read it (there's no foreground-only clipboard permission on Android). If I let the password manager be my accessiblity service, I've given it power to do literally anything on my phone, and introduced a new interface between it and other apps (which can try to exploit it by producing confusing screen layouts). If I let it be my keyboard, I'm giving it everything I type. This might be the least bad option of the three. Are there any other options?
- msarchet 10y agoWell you can just have it show you the password, and then enter the characters yourself. Password management is not equivocal to automated password input. Even if that seems to be the primary feature of many password management apps.
- drampelt 10y agoI think a lot of people (myself included) use password managers to manage very long and random passwords. Typing in 100 random characters every time I need to login to something (especially on a phone) would be pretty annoying.
- tedunangst 10y agoReconsider how much entropy a password really needs and why?
- JimA 10y agoAnyone seen anything similar on Roboform? Been using them for years but I wonder how much vulnerability testing it has gotten.
- Velox 10y agoOne of the 1Password ones (https://team-sik.org/sik-2016-040/ https://team-sik.org/sik-2016-040/) about leaking URLs is marked as fixed, however, that's a little misleading. It's fixed if you use their newer vault format, which has limitations, and is not selected by default when you create a new vault. I wrote this about it a while back: https://myers.io/2015/10/22/1password-leaks-your-data/ https://myers.io/2015/10/22/1password-leaks-your-data/
- micampe 10y ago> and is not selected by default when you create a new vault. I just tried creating a new vault and it created a .opvault. It became the default with version 6.1, released in Nov 2015 https://app-updates.agilebits.com/product_history/OPI4#v610012 https://app-updates.agilebits.com/product_history/OPI4#v6100...
- DavideNL 10y ago> It became the default with version 6.1 yea, but still the problem is that all users who created a vault before Nov 2015 never got any message neither is their database upgraded automatically. They will unknowingly keep using the old database format. Seems alarming for a company who's business is security/privacy.
- micampe 10y ago> and is not selected by default when you create a new vault. I was clearly only responding to this part, which is still useful information. Nowhere I said there is no issue, there is no need to always nitpick on everything. I'll go back to not commenting on anything for another year.
- DavideNL 10y agoi probably worded it poorly, in my defence, English is not my native language :) I agreed with your post and was just supplying additional info.
- Sir_Cmpwn 10y agoTangentally related: https://github.com/SirCmpwn/pass-rotate https://github.com/SirCmpwn/pass-rotate I posted it on here the other day but it didn't go far. It's like youtube-dl but instead of downloading videos it changes your password on various online services. If you get your password compromised by vunlerabilities or whatnot it makes it easy to mass-rotate your passwords. Could use some help adding support for more websites if you're interested. </shameless promo>
- deleted 10y ago[deleted]
- tehabe 10y agoPassword Safe is missing …
- circa 10y agoI have moved from LastPass to Dashlane and rarely have issues. Its been fairly solid for me the past year or so. Anyone had issues with Dashlane?
- hackuser 10y agoHow do you know if it's secure? How do you know if someone is accessing your passwords?
- jondubois 10y agoNot surprising. Password manager give you convenience at the expense of security.
- jsilence 10y agoWell, yes and no. If it leads to you using more secure passwords than without, then in theory you'll have higher security.
- jquast 10y agoJust my brief experience of 2-3 hours with LastPass today. Broken javascript errors when trying to import. Searched for customer support, couldn't find any! How do I file bugs? Sign up and post to their web forum? I noticed their website is made entirely in php. Not that php is bad, but this is possibly the worst choice for a web platform that holds secrets. At only $12 a year, they probably aren't trying very hard.
- deleted 10y ago[deleted]
- nommm-nommm 10y agoEhhhh...? Took me less than 30 seconds https://lastpass.com/support.php/support.php?cmd=showfaq&id=5616 https://lastpass.com/support.php/support.php?cmd=showfaq&id=... >you can find the link to open a support ticket in the bottom right of this FAQs page under "New Ticket".
- no_wizard 10y agoshocked I didn't' see bitwarden in here? I use Bitwarden for some things (lots of testing, nothing serious). Given its OSS nature, i thought it might have had more traction. For reference: https://github.com/bitwarden https://github.com/bitwarden
- chj 10y agoToo bad 1Password doesn't encrypt title and URLs.
- jamesdwilson 10y agohttps://ssl.masterpasswordapp.com/ https://ssl.masterpasswordapp.com/
- jamesdwilson 10y agohttps://ssl.masterpasswordapp.com/ https://ssl.masterpasswordapp.com/
- andybak 10y agoAvast are still working on vulnerabilities reported in November 2016. They seem by far the least responsive of the apps mentioned.