7 ms·
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager? This is the case
by bqe 10y ago
Here's a question you should ask yourself: do you want malicious webpages or malvertising to have direct API access to your password manager?
This is the case with all password manager browser extensions. A desktop-based password manager without the browser extension does not have this risk vector. And, as we've seen with the dozens of extremely critical LastPass bugs, they're not even particularly good at securing said API. Other products may be less bug ridden, but they share the same risk vector.
I use pass[1], and I recommend it if you can stand copying and pasting. It's really not much of an inconvenience for the dramatic increase in security you get.
[1]: https://www.passwordstore.org/ https://www.passwordstore.org/
- SubiculumCode 10y agocopying and pasting seems to be a vulnerability..especially if you get distracted for a moment, or haven't had your coffee and paste it into your search bar.
- bqe 10y agoIt's a risk, albeit a small one. Individual passwords are easy to change if compromised. I have personally never miscopied them. Both pass and KeePass will automatically clear your clipboard a little while after copying the password. However, losing every single password at once, without your knowledge, direct to an adversary due to a LastPass vulnerability is a much more severe problem.
- deleted 10y ago[deleted]
- OJFord 10y agoIf you paste a long, random password in your search bar, what's going to happen in the time between then and changing it?
- AdmiralAsshat 10y agoIn Firefox, I believe there's a way to turn off asynchronous searching so that it won't attempt to search as you're typing. Even though DuckDuckGo is my search provider, I have that enabled anyway; I figure I'm okay with having to press ENTER to see results as a trade-off for not having my data sent to someone as soon as I start typing. Not sure if this is an option in Chrome/Chromium.
- mixedCase 10y agoWhile I don't use pass, KeePassXC and KeePassDroid clear the clipboard shortly after use.
- cookiecaper 10y agoYep, KeePass has a (too short) default timeout to erase the password from the clipboard, I think it's something like 10 seconds? I increased it to 90 seconds.
- sprucely 10y agoKeePass also has a handy feature that bypasses the clipboard and sends {username}{tab}{password}{enter} keystrokes directly to the browser window. The keystrokes can also be customized per web page.
- amackera 10y agoI would love to use pass but I can't figure out a decent way of getting it on my iPhone. Sometimes I don't have my laptop with me.
- bqe 10y agoHaven't used it, but it looks like there are a few apps for iOS: https://mssun.github.io/passforios/ https://mssun.github.io/passforios/ KeePass is a good solution, too. It also has iOS apps.
- jethro_tell 10y agoI use password safe which is a windows app but also has a database format so there are lots of cross platform apps that can act on the safe file. I sync it with Google drive and have a Linux and Android app that I use to access the safe.
- deleted 10y ago[deleted]
- cookiecaper 10y agoHere's another question to ask: "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" Good security is hard in practice because people are always going to default to the most convenient/simple way to accomplish their goal, and at this point, most of our security measures require someone to expend extra energy. That means it's going to be very hard to get people to do it. We have decades of experience with this just with regard to one layer of passwords. Adding an extra layer, like a password vault, is not going to make things better. While it absolutely true that there is more risk involved in using a third-party extension to manage a password vault than not, the actual net effect is likely better security, because if you make things too hard, people are just going to say "Fuck those annoying nerds, we're going to make every password 123456", or whatever the next-simplest answer that the system will permit is. As for LastPass making mistakes, that's true, but the benefit you get by using a well-known product like LastPass is that Project Zero has hardened it. That's not the case for most other password vault extensions, especially those made as shims for external vaults like KeePass.
- bqe 10y ago> "Is everyone really going to open a separate application, unlock the vault every time they want to use it (due to timeout), Ctrl+F for the URL, and then Ctrl+C out the username and password every time they want to visit a site? Also, is everyone going to create a correlated entry every time they make a new account?" This is not how pass or KeePass work. I recommend you try them out and see if they're really that hard to use (hint: they're not). If you really like browser integration, I also sometimes recommend using the built-in Chrome or Firefox password managers with good master passwords. They're actually easier to use than LastPass and its insecure ilk.
- cookiecaper 10y agoI've used KeePass for years. Am I using it all wrong or what? That's how it works on my computer. Yes, you could install a browser extension that interfaces out to KeePass (and I've used those in the past too), but that doesn't give much, if any, security benefit over LastPass; you're still exposing the attack surface to the browser's environment. I do actually also use Chrome's built-in password manager so that I don't have to copy and paste as much.
- hdhzy 10y ago> I use pass[1], and I recommend it if you can stand copying and pasting. Try browserpass. It uses pass internally. https://github.com/dannyvankooten/browserpass https://github.com/dannyvankooten/browserpass
- runamok 10y agoThat's a good point. Might be a good workaround to sort of "sandbox" the password manager from your active web browser. Have a second browser with the plugin installed that you use only to copy the password to your clipboard and then paste into the password field. I can usually remember by username for 99% of websites.