3 ms·
A hack against your password manager isn't going to be targeted at you as an individual. It will happen to one of the major companies who develop the software.
by developer2 9y ago
A hack against your password manager isn't going to be targeted at you as an individual. It will happen to one of the major companies who develop the software. The security of the product is only as good as the weakest link at the company.
Where is their source control stored - GitHub? How strong are the passwords of the developers (and managers, etc.) who have access? Do they use two-factor auth? How easy is it to social engineer one's way in, and add a commit to the app so that the next release decrypts all credentials and sends them to the hacker's remote endpoint? It's probably 3-5 lines of code to sneak in. The possibility of a "disgruntled/ambitious employee" exists, too.
There's also the browser extensions. I know web extensions are sandboxed, but does that include preventing a malicious extension from capturing the keystrokes from your password manager's master password text box? Each of these companies also has a website UI where you can view/manage your passwords; they load data into local storage - thus not being decrypted on the server side - but these are still vulnerable to cross-site scripting attacks, etc.
I think it's inevitable that one of the major password managers will wind up being compromised. Such an event would be catastrophic.
- kerkeslager 9y agoSure, it's possible to use a badly-designed password manager, such as using a centralized or closed-source password manager. I'd say this is still more secure than using the same password everywhere, because it only involves trusting one entity with the keys to everything, rather than trusting multiple entities with the keys to everything. But it's definitely a bad security practice. The password manager I use is KeePassX. In both the KeePass and KeePassX varieties it stores the passwords locally, so the only vulnerability you mentioned that it's vulnerable to is that malicious code would get into the source. One would hope that this would be caught by auditing, but of course it's always possible it wouldn't be. However, this is a only a possibility: it's guaranteed that one of the sites I log into with a password will leak that password at some point. So using KeePassX is definitely safer than using the same password everywhere. > I think it's inevitable that one of the major password managers will wind up being compromised. Such an event would eclipse the Equifax breach. Sure, if it's one of the password stores that stores its passwords centrally. But that idea is so backward that I barely consider such systems to be password managers--I'd file those under the "Joe's totally-not-a-password-collection-scheme website". The simple answer is don't use those. If it's one of the password stores that stores passwords locally, then it will only leak passwords of users who update their password store software between the breach and when the breach is discovered. You can come up with scenarios where any password scheme will be broken if a user does completely the wrong thing, like posting their password publicly. That doesn't mean password managers are a bad idea, it just means there's no such thing as an idiot-proof security system.