7 ms·
> First and foremost, password managers are a good thing. All password managers we have examined add value to the security posture of secrets management, and as
by everdev 8y ago
> First and foremost, password managers are a good thing. All password managers we have examined add value to the security posture of secrets management, and as Troy Hunt, an active security researcher once wrote, “Password managers don’t have to be perfect, they just have to be better than not having one”
I would assume that a pseudo-random moderately strong password per site stored in your brain would be more secure than a random strong password that's stored electronically and vulnerable to attack, but maybe not?
- nkrisc 8y agoStoring it in your brain is likely better. Unfortunately I can't remember a pseudo-random moderately strong password per site for as many sites as I use, I am just a lowly human.
- Ajedi32 8y agoDepending on what you mean by pseudo-random, you may be correct. Most people can't remember very many random passwords however, which makes that an untenable alternative.
- donaldknuth123 8y ago>I would assume that a pseudo-random moderately strong password per site stored in your brain would be more secure than a random strong password that's stored electronically and vulnerable to attack, but maybe not? Well obviously, but is it actually reasonable to expect your average person to not only have that kind of password discipline but then actually remember a dozen of them that they often use?
- dontbenebby 8y agoI have 50+ entries in my password manager. Even if I use passphrases, I couldn't remember them all. There's no such thing as perfect security, and IMO a good middle ground is memorizing a long, strong passphrase to unlock a password manager full of random PWs for individual sites. I guess you could write them down instead, but personally I'm much more worried about someone stealing a physical notebook than getting malicious software onto my computer. (For example, what happens when you cross a border and an enterprising young border officer photographs the contents of your passwords notebook? This would be perfectly legal in most countries.) I would assume if that were the case they can intercept the password from the paste buffer anyways.
- SlowRobotAhead 8y ago50+, that sounds nice. I have 300+ and they are all 20 char random except where dumb sites required special rules like 14 char max. Asking someone to brain more than 5 good passwords is entirely pointless. We just aren’t wired for that. I’ll agree that secure paper is best for security, but not many people understand what “secure” is. A notebook on your desk isn’t, in a safe is. If I need to log in to AWS at the supermarket, that notebook does me no good.
- dontbenebby 8y ago>I’ll agree that secure paper is best for security, but not many people understand what “secure” is. A notebook on your desk isn’t, in a safe is. If I need to log in to AWS at the supermarket, that notebook does me no good. I agree, what is "good enough" security depends on your threat model. For example, for an older adult who previously used one dictionary word on every site, a small notebook with a list of PWs in a locked desk drawer is a big step forward. I like to tell people to treat passwords they have written down like they would a hundred dollar bill. (You keep it on your person, or lock it up when not in use).
- SlowRobotAhead 8y ago>I like to tell people to treat passwords they have written down like they would a hundred dollar bill. (You keep it on your person, or lock it up when not in use). Does that system fall apart if you need to securely and remotely share a password with your mom? Because that is the standard of usability I've been considering.
- dontbenebby 8y agoWho is your threat model when sharing a password with your mom? If it's not the government, isn't a phone call sufficient? Harder to tap, and presumably she knows your voice.
- 8y ago
- astura 8y agoThe only way I can realistically operate without a password manager while keeping a unique password per account would be to reset my password every single time I use an account. Which would be... very tedious.
- AnIdiotOnTheNet 8y agoFor important things you can use the Munroe method and randomly choose several words from an appropriately large dictionary. The result has the advantage of being much easier to memorize as it lends itself to mnemonic techniques. The method has detractors who would argue that the word choice wouldn't be random enough, but that's because they employ a strawman who insists on either choosing their own words or using only words they are familiar with. If you actually pull words randomly from a really big dictionary, it has plenty of entropy. Having some obscure words in your passphrase only make it even more memorable anyway. For unimportant things, like your HN account, who cares.
- astura 8y agoNo, I can't remember that for more than maybe 1 -2 sites that I use every day. I got more than two financial accounts and two emails. Totally infeasible. That not even taking stupid password requirements into account (15 chars max or some shit)
- ocdtrekkie 8y agoPassword managers are universally terrible, but until security experts stop telling people to use them, everyone's going to dump their sensitive passwords into incredibly poor apps written to put all your access in one place secured by one single password. A lot of password advice today is bad. You only should be making valuable passwords (those that control sensitive data or access) unique. Forum accounts do not need that level of security and you waste cognitive power by doing so. Banks, email accounts, and a handful of others are the only ones worth truly securing. And passphrases can be incredibly easy to remember, unlike passwords.
- ubercow13 8y agoHow is it more secure to have a passphrase in your head? If an attacker is in a position to exploit your password manager in the way described in this paper, they are in a position to sniff your bank password as soon as you type it
- hombre_fatal 8y ago> Forum accounts do not need that level of security Though it's also in the platform's best interest to defend itself from weak passwords because there are usually a lot more defenses against fresh accounts than existing accounts that get taken over. We're seeing websites becoming more and more proactive here like rejecting passwords that appear on haveibeenpwned. Also, I recognize your username from your extreme stance against password managers in the past and you seem to make the mistake of not acknowledging trade-offs. I think it weakens your point, especially when talking about end-user security where 90%+ of people are reusing passwords, not debating whether they should use a password manager or roll their own physical password pad scheme. If you reject current password managers, can you envision a digital solution that would satisfy you?
- ocdtrekkie 8y agoWhy is a "digital solution" a requirement? Storing all your passwords on a computer, or worse, in the cloud, will never be a good solution.
- 8y ago
- UncleMeat 8y agoNope. Password strength barely matters and password managers with autofill help prevent phishing, which is an actual threat.