11 ms·
>Embrace Password Managers I disagree. Author pointed out "all eggs in one basket" issue, but it doesn't look like he completely understands the whole problem.
by ss248 9y ago
>Embrace Password Managers
I disagree. Author pointed out "all eggs in one basket" issue, but it doesn't look like he completely understands the whole problem. The main problem is that passmanager holds a lot of metadata.
For example, you use unique password with high entropy for every service you use. Once attacker gets your one master password (through zero-day or just by watching you type it), potential damage is massive. He doesn't have to try to find where you are registered, password manager will tell everything, about every single account and possibly more; some people even store credit card/banking info in passmanager. At that point it's over, you lost.
"... if (password manager) gets compromised it's going to be bad news. But this is an exceptionally rare event compared to the compromise of an individual service which consequently exposes credentials."
This is not an argument at all. Let's consider the situation when individual service gets compromised. Attacker has thousands of salted hashes. With good hash algorithm, he have to spend considerable amount of time cracking every single hash. He doesn't target you in particular. You are just one of many. If attacker cares about you, after cracking hash and getting your password, he has to do a lot of research (trying to find other sites where you used that password and hope you didn't change anything there) to make any use of it. Objectively, he doesn't actually have much. So going after popular services you use, just to get your password, doesn't look like a good attack vector in the first place.
People should know, that password manager is just a glorified notepad file with one password. By using them you are trading safety in situations when attacker targets you, for safety in situations when attacker targets someone else and you are just a collateral damage. If you must, use them only for information you don't care to lose.
- squaredpants 9y agoWhat about a Password Manager combined with 2FA? A bit of redundancy in case your master password is somehow compromised, so that you can individually still change each websites' passwords and store them in a new password manager with a different master password. The same applies if your 2FA device is stolen, you may store their recovery passwords on a separate password manager that isn't accessed as often.
- ss248 9y agoWhat kind of "2FA"? SMS 2FA is not secure. Stand-alone device for every single service? Secure, but acquiring one is not so simple and not every service provides them. And do you really need to bother with multiple passmanagers at that point? Just store accounts you don't care about in one. For accounts you really care about, you should make strong unique password yourself and use stand-alone 2FA device.
- squaredpants 9y agoTOTP codes?
- seppin 9y ago> Once attacker gets your one master password (through zero-day or just by watching you type it A bit off-topic perhaps, but can a keylogger really grab your master password as you type it? 1password and OSX has secure entry for entering a system password, no?
- ss248 9y agoI don't know much about OSX, but do you really think it will stop him once he is already in the system and has kernel access? If i understand correctly, "secure input" just tells operational system to stop sending keyboard events to other programs. If that's the case, then it doesn't help against zero-day at all.
- scott_karana 9y agoKey loggers don't need to be software. A USB interception, a weak proprietary 2.4GHz radio interface, or a badly implemented Bluetooth keyboard can all leak password plaintext directly to an attacker.
- seppin 9y agoso very specific, targeted attacks. In other words, unless pros are going after you do enjoy (relative) security
- deleted 9y ago[deleted]
- gvx 9y agoI don't think that's true. The scenario you presents requires the user to already be compromised by the attacker. What does it matter if they use a password manager or remember and type their passwords manually, if the attacker has access to your machine? Of course there is a trade-off with the master password, but on the whole, I'd say it's a definite security win, because the user only has to remember one strong password instead of many, and an attacker only has an advantage if they've already won anyway.
- ss248 9y ago>What does it matter if they use a password manager or remember and type their passwords manually The main difference is amount of information attacker will get. With passmanager, he will get everything instantly once you type master. With manual typing, he will have to wait until you tell him about every single account, one at a time, so it's a bigger risk for him to get caught. And password managers, in general, give average Joe false sense of security. So he starts storing everything in them. Bank accounts, credit cards, you name it. And once he gets hacked, amount of damage he receive will be much greater.
- NMDaniel 9y agoIf an attacker has root access to your machine, he can easily: * Extract passwords and session tokens from your browsers * Keylog your system and wait for you to type a certain password * MiTM your TLS connection to grab credentials >This is not an argument at all. Let's consider the situation when individual service gets compromised. Attacker has thousands of salted hashes Wait, who said they are hashed? Perhaps an irresponsible webmaster stored them in plaintext. Now, even if that service itself isn't very important, it's likely that certain users re-used the same(or a similar) passwords in more important services, such as Google. Now, while you're right that using a single master password does pose a risk, there aren't other viable solutions to secure password authentication, unless you; Memorize a strong password for every service that you use Never share passwords among the services Don't store saved logins in your browser Never link your services to your email (because then if your email account is pwned, your accounts in those services would be pwned too, another "all eggs in one basket" issue) If you can do all of the above, then great, but most people can't.
- ss248 9y ago>Memorize a strong password for every service that you use I keep hearing this argument and i think people who use it just don't understand why password has to have high entropy (e.g. strong). It's not to stop attacker from bruteforcing login page (nobody is doing it nowadays), it's to stop attacker from cracking hash, if he gets it. If password is unique, it doesn't have to be strong. >If you can do all of the above, then great, but most people can't. And this stuff again... "Security is hard, just use this password manager, dum-dum." All you have to do, is divide your accounts into two groups: accounts you care about and accounts you don't. Most people would not have more than 4-5 accounts in the first group. Create and memorize strong password for them. For the second group, you couldn't care less, so use passmanager, that is the only good use case for it anyway.
- another-dave 9y agoIt's about the attack vector though, right? My dad has passwords written in a notebook, but to compromise that you'd need to break into his house & find it. If the alternative to not using a password manager is password reuse or enumeration (sup3rMan!_gmail), it becomes for attackers even if they're not explicitly targetting you, as they can run patterns against the whole DB against Gmail/Hotmail/Facebook etc