4 ms·
I have a tangentially related question. During this LulzSec situation, I stepped into 2009 and started using LastPass. I generated 16 character random passwords
by brianleb 15y ago
I have a tangentially related question. During this LulzSec situation, I stepped into 2009 and started using LastPass. I generated 16 character random passwords for every place that I've been visiting. As I understand it, these passwords are encrypted on my machine and then uploaded to LastPass servers. When I login with my master password, I have access to all of these passwords unencrypted.
My question: is there an intrinsic weakness in storing these passwords at a central location? E.g. would it be feasible that LastPass gets targeted by a complicated blackhat attack, and then instead of losing just one of my passwords I lost them all? Or is the manner in which they are encrypted and transmitted secure enough to prevent this?
Thanks.
- bonzoesc 15y agoIf LastPass uses good cryptography your passwords should be safe for a very long time.
- Acorn 15y agoIf someone managed to compromise LastPass' servers, they would be able to modify the content that was sent to your browser, and thereby do anything they wanted with your master password after you typed it in. That's the weakness of services that are supposedly "Host-proof". If the host is sending you the webapp/javascript/webpage in which your data is decrypted, each and every time you visit their website, you have to trust that they wont (or someone else wont) modify it in a malicious way in order to gain access to your data. The only way to be safe from this kind of attack is to use the same trusted copy of the code, and not use any new versions until you trust that it is also safe, or to somehow verify that the webpage sent to your browser is exactly what you expect it to be. Cortesi has a very good write up on this issue: http://corte.si/posts/security/hostproof.html http://corte.si/posts/security/hostproof.html
- rakkhi 15y agoYes you have centralized your risk. http://www.rakkhis.com/2010/12/why-you-should-use-password-vault.html http://www.rakkhis.com/2010/12/why-you-should-use-password-v... An alternate option to reduce some of this: http://www.rakkhis.com/2011/06/i-was-hacked-mtgox-bitcoin-3-reasons-i.html http://www.rakkhis.com/2011/06/i-was-hacked-mtgox-bitcoin-3-...
- shinratdr 15y agoYes, it is. Use 1Password or KeePass because they aren't centrally hosted. 1Password even provides a little security through obscurity by using DropBox for its optional keychain syncing. People store a lot of uninteresting crap on Dropbox, filtering through to gather .agilekeychains would be a real PITA.
- bluesnowmonkey 15y agoIf only there were a device that could automate computational tasks, such filtering would no longer pose a challenge. Some sort of compute-er...
- shinratdr 15y agoIf it was simple as filtering for those files, you would have a point. It's not though. If you can't see the difference between a big compiled database of 1 million+ users password DBs vs a multiple petabyte mess of all types of files including a handful of agilekeychains, then it's not worth discussing further.