23 ms·
Password Managers
- freitasm 5y agoMalicious site
- freitasm 5y agoSorry, to clarify Norton raised an alert on this domain. So proceed with caution.
- ptomato 5y agoyeah, funny how antivirus software would complain about the website of somebody known, among other things, for demonstrating a lot of security flaws in antivirus software.
- throwaway192874 5y agofyi Tavis is a very well known and respected security researcher from Project Zero, and this is his site so it's nothing to worry about :) I mean he _could_ hack everyone if he wanted but he'd pretty quickly be in a whole lot of trouble You can see that he links to this as his site on Twitter here: https://twitter.com/taviso https://twitter.com/taviso Interestingly, I wonder if Norton doesn't like it since the name is related to an old vulnerability. From his site: > Q. What is the origin of your domain name? > There was a bug in early Pentiums called the f00f bug, it would cause a deadlock if you used in invalid operand with cmpxchg8b with the lock prefix. It was an important vulnerability at the time, and I thought it would be fun to own lock.cmpxchg8b.com.
- austinkhale 5y agoHow is Tavis Ormandy's blog a malicious site?
- deleted 5y ago[deleted]
- ferdowsi 5y agoIt's curious that we haven't seen dedicated effort towards a consistent password autofill API in browsers, like what is present in Android. Even the Credential Management API seems to have not picked up traction for passwords, though it was extended for use with FIDO2 security keys.
- scrollaway 5y agoIs there one present in Android? My understanding is password managers on Android and iOS abuse a11y interfaces. (I'm not a mobile dev)
- cianmm 5y agoiOS has a dedicated API for password managers - Password Autofill (https://developer.apple.com/documentation/security/password_autofill/ https://developer.apple.com/documentation/security/password_...). It presents passwords in password managers the same way it would passwords in iCloud Keychain. You still sometimes need to use the interfaces you mention, but increasingly rarely.
- InvertedRhodium 5y agoThe latest version of Android does, yes. Though they can still abuse the accessibility API for injecting password into applications that don't support this API.
- pta2002 5y agoThis used to be the case, but somewhere around Android 7 (might've been 8 or 9) added proper support for autofill services.
- kiwijamo 5y agoBitwarden doesn't seem to do this even in Android 10. The Bitwarden UX on iOS is fantastic though, it behaves excatly as you'd expect from a native solution. Any examples of good password managers on Android that uses the proper support for autofill?
- 627467 5y agoI share the conclusion and for those friends and family who use chrome across devices I've been recommending to just activate 2FA (not sms) and use the built in password manager. But relying on chrome as password manager - even on Android - has drawbacks as it seems not to support all apps and fields one needs to. I personally use bitwarden because it seems to work - when I enable all assistive tech - on 99% of situations. I also don't use chrome anymore so using Google password manager isn't as useful.
- dtx1 5y agoThis does not reallz discuss offline password managers like keepassx except for this one sentence > Conceptually, what could be simpler than a password manager? It’s just a trivial key-value store. In fact, the simplest implementations are usually great. Good examples of simple and safe password managers are keepass and keepassx, or even pass if you’re a nerd. I think keepass synched via nextcloud is a great solution, e2e encrypted, works basically everywhere (windows mac linux osx ios android) and it keeps the sync and backup in your hands. If copy and pasting a password or using autofill for keepass is too much to ask, then you propably don't care about security.
- randomlurking 5y agoWhat’s is the difference between keepass synced by X and another service which is completely online? Simplified with keepass I have a) the database and b) an online accessible Location for storage. If I use Bitwarden, I still have a) and b), right? So for keepass to be better it would need to be better (as in safer) for one of those. I’m not sure if that’s the case (you can even selfhost both Bitwarden and nextcloud to have „trusted“ storage, although it shouldn’t matter). But: if you don’t need multiple devices, Keepass is the surest choice. With that in mind, I’m rolling with Bitwarden (maximal security afaik and great usability - it’s even linked with my iPhone) for personal stuff and keepass for work as I only have one machine I need passwords on. I don’t like Setting up something to sync a file if I don’t need to, so I’d never use keepass for multiple devices
- JackGreyhat 5y agoUsing keepass would decouple password management from your browser. Bitwarden, for example, usually runs as a browser addon.
- gruez 5y agohttps://bitwarden.com/download/ https://bitwarden.com/download/ They seem to have desktop/mobile apps as well?
- dtx1 5y ago
- mgarfias 5y agoI tried to read this, but my head is too swimmy from all the allergy meds. I’ll have to come back to It.
- prophesi 5y agotl;dr: browser extensions are bad therefore all password managers are bad Also find it odd the author uses Chrome, which doesn't even let you set a master password to E2E encrypt its password store.
- arkadiyt 5y agoThat's not true, you can set a sync passphrase which e2e encrypts your synced content (all of it, not just passwords).
- prophesi 5y agoNice, that wasn't the case when I was still okay with Google. In that case, I find it odd that the author doesn't recommend setting a sync passphrase, as that's not enabled by default.
- richardwhiuk 5y agoIt's usually encrypted with your Windows / Mac / Linux login password.
- MonaroVXR 5y agoI use Linux ( Fedora) and it doesn't do that? * *I have a password sentence. Maybe because my disk is encrypted and I need to fill in a password when I login. When I had auto login enabled, I had to fill in the Chrome password.
- RcouF1uZ4gsC 5y ago> If you want to use an online password manager, I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. What would be really great if the major browser vendors would get together and come up with a way to reliable, secure, cross-browser syncing of passwords. The main reason I use a password manager instead of the browser’s password storage is because I use different browsers both on the same device and an different devices. I might use Firefox in my Linux desktop and Safari on my Mac. Using a third-party password manager allows me to have the same set of shared passwords on both.
- cosmotic 5y agoThe blog suggest using Chrome's password manager. I used MacOS KeyChain as my primary store and Chrome's password manager for my secondary store for years and finally gave up because KeyChain didn't work with Chrome or sync with anything (unless maybe I used iCloud) and Chrome only synced with and worked with Chrome and too often it didn't save passwords properly. For all other browsers, apps, or uses, Chrome password manager is useless. Fortunately I could export Chrome to CSV and use some third party applescript to export KeyChain and import into KeePassXC. It's not perfect but it's better than the built in stuff. Maybe W3C could standardize a protocol for password managers so we don't have this insane vendor lock in.
- foobarbazetc 5y agoFor what it’s worth, the keychain now syncs with iCloud and across all your Apple devices and it’s end to end encrypted by your system or phone passwords. The password interface in iOS has improved a whole bunch (tells you about weak passwords, reused passwords, etc) but doesn’t support attaching a TOTP to an entry. Which may or may not be a big deal now what everyone is moving to U2F etc.
- cosmotic 5y agoUntil Keychain works with Chrome, Windows and Android, I don't consider it a viable alternative.
- rendall 5y ago> The blog suggest using Chrome's password manager That's not what the article said
- tomger 5y agoGiven this advice I would - turn off any webpage integration LastPass does - still use LastPass to store my passwords in the cloud so I can share passwords between iOS apps and web.
- dandarie 5y agoYou still have to trust your passwords being stored elsewhere, with weak encryption, if at all.
- A4ET8a8uTh0 5y agoAfter building my new rig, I also made a successful jump from Windows 7 to PopOS. It was mostly a very smooth transition, but I am having real problems with replacing Password Safe I used on Win. I eventually defaulted to using FF for passwords, but it still feels wrong. Password Safe had password generators, space for notes.. lil things that I keep missing.
- hobos_delight 5y agoI recently moved my passwords from an expired 1Password account to Bitwarden (right at the time they announced linux support actually, which was always the biggest thing I missed). Bitwarden has a FF extension and allows me to use it across mac/windows/linux.
- dijksterhuis 5y agoI was looking at Bitwarden yesterday as I've been putting off moving over from LastPass and 1Password seemed weird with importing from it. Is Bitwarden decent enough? The fact that it has a cli, FF extension etc. on a free plan is pretty tempting.
- curmudgeon22 5y agoI’ve been a happy Bitwarden user for 2 or 3 years. Recently upgraded to the family plan for shared passwords and that is working well.
- howolduis 5y agoBitwarden is ALL what you need. It's much better than all these paid apps.
- kiwijamo 5y agoIt's fantastic. I use the Firefox extension on my laptops. On my Android I have the app. It is very convenient having access to the same password store across multiple devices. If you have iOS it's even better as it hooks into the iOS password manager API so apps and websites that present a login screen can be autofilled using Bitwarden. Android has something similar but doesn't work quite as well but it's easy enough to copy and paste from the Android app. Very happy with it.
- stunt 5y agoIf you are paranoid enough, you would think of Password Managers as an obvious must-have business to tap into for the NSA.
- Santosh83 5y agoCloud based or auto updating password managers have this risk. The org behind it could push a compromised update any time. Standalone password managers would need the local machine to be compromised, which means a targetted attack. Far harder. Not beyond NSA types, but beyond a malicious employee or MitM actor.
- chrisan 5y ago> This problem is pervasive among online password managers, you can never be sure if you’re interacting with a website or your password manager. Isn't this true for any scenario, password manager or not? If a site has been compromised without you knowing and you enter your password from memory, paste, or a password manager, that password is at risk. Is the author saying that he is able to access ALL passwords in the password manager via a single malicious site?
- richardwhiuk 5y agoThat's the vulnerability he's targeting, yes.
- kiwijamo 5y agoI wonder if the author has used bitwarden at all? I always access bitwarden through the browser toolbar which for me guarantees that I am dealing with the Bitwarden extension and not the website itself. It seems from the article other password managers inject themselves into the webpage which I can agree is a concern. However this is not how all password managers operate--Bitwarden being one example disapproving that assumption.
- 1cvmask 5y agoI worked on the design of adding passwordless 2fa to the Saas Pass password manager. In addition the saas pass password manager identifies websites that you can add 2FA to as well.
- 1cvmask 5y agoMore details on adding 2fa to a password manager and figuring out websites and services you can add it to: https://blog.saaspass.com/saaspass-password-manager-authenticator-e44b51de46c8 https://blog.saaspass.com/saaspass-password-manager-authenti...
- makach 5y agoFirst of all, a very interesting topic! Author is obviously someone with a lot of knowledge. Nevertheless he is employed at Google(https://en.wikipedia.org/wiki/Tavis_Ormandy https://en.wikipedia.org/wiki/Tavis_Ormandy) and recommends Chrome? ..combined with lack of references and research material this all seems a little bit sus to me.
- xyse53 5y agoIt says it's an opinion piece. He's written other more technical things elsewhere. One takeaway you can have is to combine the opinion with impressive track record... I think the opinion alone carries weight. I may be biased though because I agree with the opinion. I use a combination of my browser's support and `pass`.
- thomascgalvin 5y ago> I use Chrome, but the other major browsers like Edge or Firefox are fine too. There's nothing sus here; he's saying that the password managers built into the browser use a more secure model than a plugin that uses javascript to communicate with a web page. That seems to be 100% accurate. If a Chrome dev had said we should use Chrome's password manager because Mozilla's in fundamentally broken, I would want more proof of that claim, but he did a fine job of explaining the vulnerabilities of a plugin versus a native manager.
- quesera 5y ago> I use Chrome, but the other major browsers like Edge or Firefox are fine too. They can isolate their trusted UI from websites, they don’t break the sandbox security model, they have world-class security teams, and they couldn’t be easier to use. This is about as low-key of a recommendation as you can construct. Curious that he omits Safari though.
- xaduha 5y agoPasswords are a lost cause. This doesn't mean that you need to give up on using good practices, just don't go overboard trying to plug all the theoretical holes. It's not all or nothing, sometimes it's OK to be good enough. For everything important you oughta use 2FA anyway.
- KronisLV 5y ago> Passwords are a lost cause. I never really understood this. Ed25519 keys use SHA-512 and are considered secure. They're still just long secrets, aren't they? What's to prevent me from using a similarly long, randomly generated secret as my password, using a different one for every site? Because that's what I'm doing with KeePass. Backing up the auth database/file and having enough redundancy in place, as well as having a sufficiently secure master password take some effort, but the rest is just copying and pasting those long secrets when you want to log in. Of course, 2FA is a necessity for everything important as well, but it feels to me like the kinds of passwords that many people use are the problem, not the concept of passwords.
- nicoburns 5y agoThere is a difference between passwords and certificates: you have to send the password over the network every time you login, whereas the private key is never shared. But in general I agree with the rest of your comment.
- xaduha 5y agoDon't cherry pick, read the rest of my comment. It wasn't at all about any individual password complexity, it was about password managers that work with browsers in context of the blog post. Out of curiosity, what does haveibeenpwned.com say about your most used email?
- KronisLV 5y ago> Don't cherry pick, read the rest of my comment. It wasn't at all about any individual password complexity, it was about password managers that work with browsers in context of the blog post. That's fair, but the aim of my response was to have a short discussion about the idea behind passwords and the fact that they're sent over the network, maybe someone has any input on that and why that's still such a popular approach. As for the exact topic of the post, password managers within browsers feel too limiting as opposed to standalone software like KeePass, which can be used for desktop applications, servers (including certificate storage) and anything else, really. But talking about that wasn't my goal. > Out of curiosity, what does haveibeenpwned.com say about your most used email? "Good news — no pwnage found!" Mostly due to using about 10 different e-mails for different purposes and throwaways for questionable sites.
- amachefe 5y agoI used to like Chrome password manager, but since moving back to Firefox, I like their password manager more. I havent been comfortable with other 3rd party password managers and their integration feels forced
- yurlungur 5y agoI have no complaints of keepass on my desktop. I tried using it on mobile but decided it wasn't worth the trouble to get it working as I wanted in terms of syncing and autofill. Instead I just use a select few logged in apps that I either memorize the password or use fingerprints. I don't really like the idea of syncing all my passwords with any online service.
- blfr 5y agoThe built-in browser password manager is the only one that ever made sense for me. You want the machine to verify the domain for you so you don't enter your credentials into some other site (no copying and pasting) and all third-party scripts are always clunky. I use Firefox with Lockwise[1] for Android and pass[2] as overflow for more involved secrets. This is a solo solution though that doesn't solve sharing these secrets with others. [1] https://www.mozilla.org/en-US/firefox/lockwise/ https://www.mozilla.org/en-US/firefox/lockwise/ [2] https://www.passwordstore.org/ https://www.passwordstore.org/
- treszkai 5y ago> and all third-party scripts are always clunky > I use [...] pass as overflow for more involved secrets Why don't you consider pass a third-party script here in this context? Don't you use the Firefox plugin passFF?
- blfr 5y agoNo, I use pass natively only, from the command line, for stuff like tokens, code lists, PINs, etc.
- teeray 5y agoIt’s irritating to me that there’s no standard integration between password managers and authentication elements on a page. We can do this correctly if we want. Furthermore, I’d love some standard programmatic way to change passwords and communicate complexity and rotation timelines. If I use a password manager anyway, it should just deal with changing my password if some organization decides to use a backwards rotation policy with specific special characters.
- xyse53 5y agoI agree that there will always be a need due to other bits of information, but IMO if you follow this train of thought for authentication specifically you wind up at "passwordless" WebAuthn.
- Ajedi32 5y agoSounds like you're describing the Credential Management API: https://developer.mozilla.org/en-US/docs/Web/API/Credential_Management_API https://developer.mozilla.org/en-US/docs/Web/API/Credential_...
- devoutsalsa 5y agoOne attack vector is consolidating all your passwords into a password manager, and then being able to unlock the password manager on your phone w/ biometrics (e.g. face, fingerprint).
- foobarbazetc 5y agoYou still have to unlock your phone and any competent password manager makes you type the password at least once and has options for how often you have to. If someone has your phone and your phone passcode you’re kind of hosed anyway.
- devoutsalsa 5y agoWell someone can drug you and use your face while you’re passed out, but they can’t make your unconscious self share your pin code. This all assumes your attacker doesn’t think to just scare you into sharing by threatening you with a hammer. I was actually thinking more about law enforcement being the most likely to try gaining access to your phone. They can make you use your face or fingerprint, but they can’t force you to reveal your pin code.
- theshrike79 5y agoIf your threat model includes someone using drugs/violence to get your passwords, then choosing the correct password manager is the least of your problems =)
- devoutsalsa 5y agoWell the only time I’ve been mugged was by a cop, so there’s that.
- kbuck 5y agoI'm a little disappointed in the conclusion because there are more secure password managers out there that still offer the same level of convenience as the browser built-in password manager. Yes, if you use a password manager that's implemented entirely as a browser extension, you may as well use the browser's built-in password management features. However, if you're an advanced user and are comfortable using a separate password management application, there are options out there that don't force you to choose between a difficult-to-use app and the convenience of something in-browser. For example, exploiting a browser-based password manager likely means escaping the sandbox that contains web pages and accessing the shadow DOM. But this is still a larger surface area than 1Password, where the password selection menu (on Windows at least...) is actually rendered by an entirely separate process on the system. (I.e., clicking the icons that the extension displays triggers the 1Password desktop application to display UI at the cursor's current position. Picking a password from this UI will transmit it to the browser extension for filling. The password is only present in the browser's memory once you've interacted with the desktop application's UI.) As always, do your research. Don't get suckered into paying a subscription fee for a browser extension that offers the same functionality your browser has built-in. But realize that there are other options out there that may actually be worth investing in. Disclaimer: I've been a happy 1Password customer for a few years now.
- kennywinker 5y agoHis conclusion seems off to me too. I got "Password managers that use content scripts are bad" not "password managers are bad". Edit: I just cracked open the 1password extension, and it does indeed use a content script. Glancing over the code I only see stuff related to locating which fields are the username and password field - but I was mistaken in thinking that they didn't use a content script.
- cordite 5y agoWhat if browsers exposed the capabilities to locate the inputs, act upon user input, supply generated passwords, etc. in a sandboxed manner?
- ajsnigrutin 5y agoFor my parents, i tell them to just write the password down on a piece of paper. If someone breaks in their house,they have a bigger problem than someone reading their emails, and since they live off givernment pensions, there is not a lot of money that can be stolen via the internet.
- deleted 5y ago[deleted]
- Wowfunhappy 5y agoI wouldn't be worried about someone breaking in, so much as the paper getting lost.
- massysett 5y agoFor most people who need advice on how to manage passwords, they're a lot more likely to hose their computer in some way than they are to lose a piece of paper.
- jefftk 5y agoSure, but it does not protect against phishing. If they visit something that looks like their bank site, but isn't, they will type in the password from the paper. If they were using a password manager with proper integration it would notice the domain mismatch and refuse to fill.
- jdeibele 5y agoThe major problem with the built-in password managers is that they don't store more than the password. If there's a site that has security questions, I use LastPass to keep track of the security questions and my answers. I have to do this because I don't give real answers to security questions. A minor annoyance is that Safari will not let me treat sites which use multiple domains as equivalent. So Discount Tire uses dt.com and discounttire.com but Safari flags this as a security problem because I'm using the same password with both. LastPass lets me set them as equivalent domains, though the process is probably too difficult for most people. LastPass made free users decide whether to use it either on computers or phones & tablets but not both. Because I use FireFox on my Mac, I used LastPass on computers. I rely on Safari to sync for my phone and tablet. I think it's inevitable that LastPass will continue making life more difficult for free users and I may end up with a flat file or Apple Notes file to store the security questions and answers.
- lamontcg 5y ago> I think it's inevitable that LastPass will continue making life more difficult for free users and I may end up with a flat file or Apple Notes file to store the security questions and answers. Why not just pay for it? If it prevents a hack which impacts your finances, then its more than worth it and not worth the waste of your time trying to avoid paying them.
- pimlottc 5y agoHow do you add multiple domains in LastPass? I couldn’t figure out how to do it.
- pleb_nz 5y agoPersonally using a browser based password manager is too restrictive in that you need a browser to access passwords. I use passwords in a lot of places outside of browsers and often the interface I'm using has no browser capabilities. Understand using browser based password management if you only ever use passwords on the web. But I'm sure a lot of others, like me, need them outside of that context.
- noisem4ker 5y agoIn the case of Firefox, at least, the Lockwise application allows you to use your credentials even outside of the browser, on mobile devices. On the desktop, both Firefox and Chromium allow you to copy passwords so you can paste them in any application.
- mdaniel 5y agoMaybe so, but what website do I have to load to get Chrome to offer the password for the app that's in the foreground of my phone? The 1P keyboard knows what app I'm using, and auto fills accordingly
- noisem4ker 5y agoIf we're talking mobile OSs, Lockwise can be set as the system autofill service and provide passwords to the running apps. There's also a Google autofill service which I believe shares its credential store with Chrome. My experience is with Android, but I think iOS works the same way.
- ramraj07 5y ago"a lot of others" seems unsubstantiated. I'll argue the majority of folks (even technical) rarely need access to passwords outside of the browser. The only times I need a password outside of chrome is my Macs password, and dockerhub but I've memorized just those two. Occasionally I need the password for Microsoft or intelliJ accounts, but even then I just use my phone to lookup the password in my manager visually and then type it, I'm never letting any password I care about go into my Macs clipboard!
- raldi 5y agoI don't understand the Nordpass demo. What would double-clicking actually do?
- gruez 5y agoSeems like a clickjacking attack. Presumably you can use this to reveal passwords for other sites, depending on how the ui is coded.
- raldi 5y agoSure, but where do the clicks actually end up?
- gruez 5y agoThe ui of the password manager, as demonstrated in the demo.
- raldi 5y agoWhat parts of the UI of the password manager? What do the clicks actually do? The demo doesn't show that; it just shows the mouse being followed by a "(i)". So what? What does clicking "(i)" do?
- throwaway192874 5y agoit would have the password manager insert the password into some element on the page, and then probably send that password off to some site for exfill, but it wouldn't show you it's doing any of this the image attached to this issues actually shows an example, using an alert to show you the JS had access to your PW https://bugs.chromium.org/p/project-zero/issues/detail?id=1481 https://bugs.chromium.org/p/project-zero/issues/detail?id=14...
- Wowfunhappy 5y ago> If you want to use an online password manager, I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. Unfortunately, it also means I can basically never switch web browsers again, so it's an absolute non-option for me. I don't want to be locked into Chrome forever.
- jsnell 5y agoChrome's password manager has an export feature. Are you perhaps thinking of some other browser?
- Wowfunhappy 5y agoCurrently, I use Chrome on my desktop, mobile Safari on my phone, Safari on my Macbook, and Firefox on another machine. I need to sync my passwords across them!
- trollian 5y agoIf you install chrome on iOS you can use it as a password manager while you're using other apps, including Safari.
- shawnz 5y agoInteresting to know, this doesn't fully solve all the problems with this approach for me but it might be helpful for some family members. Thanks for the information
- travoc 5y agoIt’s a great way to make sure Google always has access to all of your browsing habits. That way they can serve you the most valuable advertisements.
- shawnz 5y ago
- dogma1138 5y agoThis somewhat overlooks the main threat model that password managers solve - leaked credentials. People can’t remember 80 passwords so they reuse the same one, that password eventually gets leaked and 9/10 times it doesn’t get leaked due to a targeted attack or a compromised machine but rather due to a breach of a service you signed up too. Sure password managers have issues, they don’t solve user related errors and can even add to the attack surface of a machine they are running on but that’s really not important... Using password managers and generating different passwords for each service reduces the blast radius from any breach. This is why I don’t care if the password manager has the best encryption, or does it even encrypts at all or does it uses the clipboard vs some more secure side channel. Yeah that’s nice but that’s not in my threat model. Which is why I don’t care if your password manager is a spreadsheet, it’s a terrible choice for a business because their threat landscape and the fact that a spreadsheet won’t allow you to audit who has access to what but for you or your mom even that is better than using the same password everywhere else. Heck at home print your passwords and store them somewhere safe... put them on a post note for all I care as long as you live alone or at least not with anyone you wouldn’t want stumbling on that list...
- hsn915 5y agoHow does this address the point of the article? Which is that you should use the browser's builtin password manager and not a third party manager that injects user scripts into all websites and break the sandbox model?
- 542458 5y agoThe point is that while yes, many 3rd party password managers have issues, the overwhelming majority of attacks are not against password managers but against reused passwords - so honestly either the 1st or 3rd party choice is a win over using neither.
- H8crilA 5y agoOk so: 1) not use any manager => bad 2) use a 3rd party => pretty crap as the article says 3) use a built-in => great Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy. I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additional code into the website itself. I thought there's a dedicated browser API or something.
- zmmmmm 5y agoI use unix pass as my "source of truth" and then individual browser password managers (mostly Firefox) as a local "cache" for sites where it is painful to manually go out to pass too often. Honestly it works brilliantly, pass syncs using git which I do to a bare ssh repo on a server I control (although it would be perfectly safe to put on github tbh). I really feel like people overthink this sometimes.
- nextaccountic 5y agothere is also https://addons.mozilla.org/en-US/firefox/addon/passff/ https://addons.mozilla.org/en-US/firefox/addon/passff/ that offer direct integration; but now i don't know if it's susceptible to the attacks mentioned in the link
- MonaroVXR 5y agoI need to share my passwords between multiple devices and browsers, that's why I use a password manager. I have a second one, called: pass. But I didn't check to synchronise it with devices.
- howolduis 5y agowhat about Bitwarden?
- kiwijamo 5y agoMy thoughts too. Bitwarden seem to do things differently to the password manager described in the article which perhaps reduces the attack surface.
- 33Backpack33 5y agoAs far as I can tell Bitwarden doesn't inject any scripts. I know people complain it doesn't have that overlay like LastPass has but Bitwarden not having might be a plus now.
- CyberRage 5y agoAny extension based PM has potential risks. Bitwarden had multiple vulnerabilities reported in bug bounty and there are likely to be more. The most secure solution is a local PM.
- samsquire 5y agoI don't think you need your password manager to inject the password into a web site for you. I think you can just copy and paste from Keepass. I want account management protocols so I can rotate all my passwords automatically via my password manager. That would be awesome.
- jefftk 5y agoA huge advantage of using the one built into the browser is that it will protect you from phishing attacks. It is only going to fill the password if the domain matches. Doing this yourself it's possible to make mistakes, especially with lookalike characters.
- howolduis 5y agopassword managers? more like: why tf anyone would use chrome?
- hmsimha 5y agoSpeaking to the section on "Vendor claims" > An attacker (or malicious insider) in control of the vendor’s network can change the code that is served to your browser, and that code can obviously access your passwords. This isn’t farfetched, altering the content of websites (i.e. defacement) is so common that it’s practically a sport. Is this actually true? For Lastpass, I would assume the code run in the browser comes from the extension directly, and (for Chrome), the extension comes from the Chrome Web Store. There are some problems here, but in theory the system could be improved so that modifications to the extension in Google Web Store are very obvious, and an attacker couldn't just inject code into the extension and update it without someone noticing immediately.
- sneak 5y agouncharitable tldr: Google employee says that for Chrome users, using the password manager in Chrome is your best option. He's a brilliant researcher, but I think he's wrong on this one, and the blog post is an appeal to authority and ends with basically a 'I've already heard your counter arguments and you're wrong'. He should show his work.
- thekyle 5y ago> I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions. I haven't used the browsers built-in password manager for years, so I don't know what features they have, but I find it hard to believe that they can provide the same functionality as a dedicated password manager. Some of the top features of dedicated password managers include: * Generating random passwords/passphrases (this is pretty basic) * Storing and generating two-factor authentication codes (TOTP) * Filling out passwords into mobile apps as well as websites * Storing security questions, back up codes, any other site specific data that needs to be secure * Storing credit card information * Platform agnostic syncing * Sharing passwords with friends, co-workers, or family * Weak password checking / HIBP integration I'm sure that the browser password manager can do some of these things, but I doubt it can really do all of them.
- tunesmith 5y agoPlus, at least for Safari, it's only protected by the computer password, which is much less secure than the kind of pass phrase that password managers ask for. My mother-in-law has her computer password on a post-it that is stuck to the monitor. Using that, I can go into her browser preferences and see the plaintext value of all her browser-stored passwords. I never use it, myself.
- marcan_42 5y agoPlease don't put TOTP codes or back up codes in password managers. The whole point of 2FA is to have two factors protecting you. If you do that, you're back to 1 factor (your password manager master password).
- mdaniel 5y agoI have that debate inside my head often, but ultimately it boils down that "security" is a spectrum and convenience is on one end of the spectrum. Having all passwords be "asdfasdf" is massively convenient, massively insecure. Having to carry my titan key with me all the time (assuming my suck ass financial institutions even allow WebAuthn) is massively inconvenient, and pretty secure. I'm 100% on board with not using 1P's TOTP for guarding the AWS Master Payer Account for my company, but my GitHub account is not a nation state threat, so having 1P autofill the code after it autofills the long password is very convenient I have also experimented with passwords in one manager, TOTP in another, but ... as I said about that convenience spectrum --- Kind of related to that last item, I also have gotten a lot of mileage out of KeePassXC's autotype feature for having it type my GPG pass phrase into pinentry. It stays out of the clipboard, I only have in use it within the pinentry timeout, and it's convenient. I wish 1P had similar behavior on sane OSes (1P will autotype into certain fields on Windows 10 but that convenience extends only to my gaming accounts because I'm not going to use Windows)
- up6w6 5y ago> I use Chrome, but the other major browsers like Edge or Firefox are fine too. They can isolate their trusted UI from websites, they don’t break the sandbox security model, they have world-class security teams, and they couldn’t be easier to use. I know its about browser integration, but take a look at the repository of Lockwise android app[1] that released the last version 6 months ago and Bitwarden app[2] with last release being 1 month ago (I tried to find the firefox browser version but its a mess to analyse the activity of it). I know firefox has a much larger team but I it doesnt necessarily mean that more competent devs taking are taking care of the browser password manager's security than 1Password for example - maybe this is true for Google Chrome but who knows about Firefox and Edge. [1] https://github.com/mozilla-lockwise/lockwise-android https://github.com/mozilla-lockwise/lockwise-android [2] https://github.com/bitwarden/mobile https://github.com/bitwarden/mobile
- Dedime 5y agoHere's a the best solution I've found for those looking for password manager recommendations. It's secure, free open source, easy to use, and syncs to all of your devices 1. Password manager for PC / Laptop: KeePassXC. It's not built into your browser, it's a seperate application. It's totally open source, and trusted by many. It also supports two factor authentication, I use a passphrase and a key file. Supports TOTP. Has a ton of "premium" features, totally free. It's awesome. 2. Syncing application: Google Drive. Sync your KeePass database using Google Drive (or whatever other sync application you want). KeePassXC supports merging databases if there's ever a conflict, as rare as those are. This is secure, because the KeePass database file is encrypted, and Google Drive / Google will never see the unencrypted database. 3. Password manager for phone: KeePass2Android. Not sure what the options are for Apple, but I'm sure they exist. Allows you to open your KeePassXC database from Google Drive. 4. Browser support: KeePassXC-Browser. Allows you to autofill your username / password / TOTP from your KeePassXC application to Chrome / Firefox. Totally free, secure, convenient, and syncs to all your devices. Also comes with excellent redundancy for your password database so you'll never lose it. I've been using this setup for years flawlessly.
- FooHentai 5y agoMy setup is almost identical, though I skip the browser plugins and let the password manager auto-paste into the browser. Keepass inside GDrive, job done. Very occasionally I'll make a copy out to a portable drive. I've been running this setup for about a decade,since some big breach (I forget which one) made it clear to me that using the same or similar passwords across multiple sites was not gonna fly any longer. The initial time investment was surprisingly heavy - I iterated through every online login I could find for myself (searching through email history mostly for signups confirmations) and changed the password on every account I had. Took about two full days.
- ramraj07 5y agoAfter realizing how every program running on your machine can Snoop on your clipboard I'm never allowing any program to send my password to the clipboard again.
- gumby 5y agoThe “built in” password manager in your browser only addresses use of a browser. Password managers like 1Password are useful in other contexts as well.
- Black101 5y agoIf you use a password manager and your computer gets compromised, you are screwed either way, whether you use a password manager or not.
- marcus_holmes 5y agoI get that nowadays the alternative to password managers is browsers. But they were mostly developed when the real alternative was trying to remember all those passwords, or duplicate them, or write them down somewhere. I used to have random passwords scattered over multiple browsers, because I change browsers. Then I got a password manager, and imported all my chrome passwords... and there were hundreds of them. All the old ones, all the weird little ones that I never cared about. It took me ages to clean this data set and delete all the crap. So no... never going back to storing passwords in the browser, thanks. I realise that technically a malicious site could possibly mess with my password manager. But I'm more worried about what the browser is doing.
- Syzygies 5y agoThe "attack surface" I worry about is forgetting to lock my screen before going down the hall to get some water, and someone slipping in to obtain a sensitive financial password. I've never succeeded in explaining this to any password manager's tech support. They stay in business because their tools are convenient to use. I've migrated from 1Password to a Dashlane family plan. I use two separate accounts for myself. I log in to one account to access sensitive financial sites, and log out explicitly before leaving my chair. I log into another account for everything else; do I care if my subscription to the Washington Post gets compromised? That account stays open for convenience. Each password manager has a theory on how best to offer similar security/convenience with one account. None work as smoothly as having two accounts.
- jefftk 5y agoIf you're worried about that kind of attack, once someone has access to your computer they can install a key logger. Better to get in the habit of locking your computer every time you stand up.
- bombcar 5y agoApple Watch supports this - lock upon getting a certain distance from the device. I believe 1Password also lets you lock itself after a period of time which can be very short.
- qot 5y agoI recommend adding a constant "PIN" you remember in your head to the end of each password in your password manager. It only takes a couple seconds to type it after the password manager auto-types the stronger, longer password.
- NewEntryHN 5y ago> Second, everyone needs to be using unique passwords. You don’t have to use a password manager to do that, whatever system works for you is fine. If you want to use a notebook in a desk drawer, that’s totally acceptable. You don't need a notebook for unique passwords. Just use the service's name. Unless you also meant unguessable, in which case a notebook is probably going to be insufficient because your brain-powered password generator will soon run out of entropy. > The tech press can review usability and onboarding experience, but can’t realistically evaluate any security claims, so how do you propose users tell the difference? "Security at the expense of usability, comes at the expense of security." Users don't need to know the difference because the only danger they need to protect themselves from is "my gmail was hacked" and the only requirement for that is that they use an un-guessable password saved somewhere unsophisticated attackers can't access. Any password manager accomplishes this. > An attacker (or malicious insider) in control of the vendor's network can change the code that is served to your browser Password managers have servers sending code over to the browser? After the installation process?
- throwaway192874 5y ago> Password managers have servers sending code over to the browser? After the installation process? Yes, LastPass is all web based IIRC, even 1Password switched to a web based offering when they switched to a subscription model. I'm still a happy customer of their previous product which was a one time purchase and uses software installs instead, database synced with w/e you want (Dropbox, GDrive, etc)
- coldtea 5y ago>There are two primary components that make up your browser interface, the chrome (confusingly, the term has nothing to do with Google Chrome) and the content area Actually it has, since the Google Chrome started as a different "chrome" on top of webkit (hence the name).
- miedpo 5y agoI think this guy is missing one reason you definitely want to run browser based password managers, especially at a business. And that is... phishing. Not every one is tech savy enough to notice a phishing site and some phishing sites are hard to notice even for those who are aware. Browser based password managers fix this problem. Yes, the browser vendor and the password manager vendor are weak points, but it's oftentimes safer than dealing with phishing especially for those not as aware of it as you are. Also the other guy who mentioned re-used passwords has another good point.
- tialaramex 5y agoPrefer WebAuthn to fix phishing. The problem your approach has is that the user always really believes this is the BigCorp site - from their point of view the stupid password manager isn't working as intended, they need their BigCorp password and it isn't being filled out. The user will definitely figure out how to work around this (e.g. with cut-paste), almost always before they realise (if they ever do) that it's actually a phishing scam. Because the user simply cannot work around the mystery problem with WebAuthn on a phishing site you have two advantages. Obviously firstly your users can't give away their credentials to phishing scams, because there's just no way to do that even if they are 100% certain that's what they need to do. So that's nice. But the more subtle advantage is for site owners. When the new Big Boss wants to replace bigcorp.example with new-brand-name-awkward-suffix.example you can't do that in WebAuthn. "Just make it work". Can't. "We paid brand consultants $1M for this domain name. Make it work". Can't. bigcorp.example will have to exist forever or you'll have to explicitly re-enroll all your users. Contrast the situation with a password manager where I can 100% guarantee somebody will tell you to just basically help phishing scammers to steal all your users credentials, rather than admit senior management are incompetent buffoons.
- miedpo 5y agoMmm... haven't tried WebAuthn, so I'll have to figure that out. Curiously, I haven't had the issue with coworkers at my company using their password where they shouldn't... but the company I'm at is rather small... and I do scare them with a long phishing presentation when they join the company, and show them all the ways they can be phished, and tell them very carefully not to use passwords where they aren't suggested... I bet there are people who are like that though. And that would be a pain =/. I haven't had to deal with the 2nd thing you mentioned, but yeah, I imagine it's quite a bit more secure that way. I bet it's caused a few trouble calls, that's for sure. I'll check out WebAuthn though.
- throwaway192874 5y agoAs it looks like Tavis isn't hanging out and responding to comments here, I thought it'd be worth linking to a question and response he gave on Twitter as most comments revolve around this point. > @diractelda: Based on your thoughts, it seems a more accurate statement is "Don't use a password manager that interacts with your browser automatically unless it's the built in password system. Non-integrated password stores are fine." > @tavis: Yep, that's a fair summary, I was just trying to be punchy https://twitter.com/taviso/status/1401253440622235649?s=20 https://twitter.com/taviso/status/1401253440622235649?s=20
- movedx 5y agoI don’t blame him for trying to be punchy — you don’t get noticed otherwise, to be honest.
- rdpintqogeogsaa 5y agoIt's taviso. He makes a new blog post and it's on the front page of HN regardless of its content.
- movedx 5y agoMy comment was of a general nature, obviously.
- eyelidlessness 5y agoWell that thread has an unfortunate answer to my biggest question at the end of the article: what about iCloud Keychain? >> @colmmacc: Safari seems conspicuously absent from the list, but it has more users than Firefox or Edge. Is that deliberate? superficially it has the chrome problem solved and T1/T2 integration for the password manager across iOS and OS X.[1] > @taviso: Well, it's deliberate because I don't know how it works, not because I think there's something wrong with it! It sounds reasonable from the docs, but I haven't looked at the implementation.[2] As I said in thread, that’s a weird response given the opening paragraph of the article: > I’ve spent a lot of time trying to understand the attack surface of popular password managers. I think I’ve spent more time analyzing them than practically anybody else, and I think that qualifies me to have an opinion! I mean, I think Tavis is qualified to have an opinion regardless. But just blanket ignoring a competitor’s solution that addresses all of the problems in the article, while claiming to have more familiarity with the space than practically anyone else... that doesn’t sit well with me. 1: https://twitter.com/colmmacc/status/1401336209746673666?s=21 https://twitter.com/colmmacc/status/1401336209746673666?s=21 2: https://twitter.com/taviso/status/1401373666328203264?s=21 https://twitter.com/taviso/status/1401373666328203264?s=21
- yowlingcat 5y agoI get that poorly designed non-native password managers introduce extra attack surface, but to conclude that no non-native ones should be used is absolutist, lazy thinking that doesn't seem rooted in reality at all. As other commenters have stated, password managers solve the password reuse problem. More crucially IMO, they solve the password reuse problem /for organizations/ -- the importance of this cant be understated. The content script attack surface issues simply matter less than the giant gaping hole from password reuse combined with spear-phishing and breaches. Anything that makes it easier for the wetware at scale to do the more secure thing is going to increase overall org security by a step function and is a valuable layer. That it's not infallible shouldn't mean it should be discarded. Frankly, I find this article irresponsible. Imagine some organization follows the advice here and actually weakens their overall security posture by following its advice. That would be unfortunate.
- guyoung 5y agomarked
- bruiseralmighty 5y agoI really feel like both the author and the post on HN should specify that these vulnerabilities are specific to browser/online password managers. Got very confused until reaching the end of the article where 'online' was mentioned specifically.
- khana 5y agoan analog black book beats a far away cyber coook.
- strenholme 5y agoI do not use a browser-based password generator, because of the Javascript insecurity issues (edit: And because I’ve been using a system like this far longer than online password managers have existed). I use a shell script, with a small C program to handle the core cryptography, to generate secure passwords. I run the password generator in a terminal window, then copy and paste the password in to the site I am trying to log in to. It’s a fairly complicated shell script, since it also has to deal with nonsense like stupid arbitrary password rules (e.g. Southwest considers an underscore to be a letter, and insists at least one non-letter non-number punctuation is in a password; some places require a password to be 8 characters or shorter; etc.) and also provides login information so I can also remember my username. As recently as 5 or 6 years ago, there were issues with websites which wouldn’t let you copy and paste a password in to their password field; Firefox has always had a “ignore any Javascript which stops pasting” special rule in about:config I had to use. I haven’t seen one of those in a while; developers finally got a clue and realized that password managers exist. One weakness this setup has is that anyone with the “master key” can get all of the password generated by the password generator. My workaround is to use a separate master key in a virtual machine for critical passwords, such as online banking ones. Shameless plug time: https://github.com/samboy/PassGen/ https://github.com/samboy/PassGen/
- mgerdts 5y agoOr openssl rand -base64 12 If a couple attempts at that doesn't generate a password that satisfies complexity requirements, add, remove, or change a character or two before pasting. Change 12 to a larger or smaller number to change the length of the generated pw.
- strenholme 5y agoThat works, but doesn’t account for the long-term storage of already used passwords, or for the synchronization of passwords generated on different computers. The system I use handles long term storage, generates the same password for a given website multiple times (with support for changing the index used to generate a given website’s password for things like password rotation—each index is a completely different password), allows passwords to be regenerated from memory if one memorizes the master key, and allows one to have a secure generated password without there being a record that one has generated a password for a given site. It has protections against trying to guess the master key based on a generated password and the generated password are themselves difficult to crack (a given password has, by default, 60 bits of entropy, but this can be increased if desired). The weak links are the master key, and the fact the passwords are placed in the clipboard. I use filesystem encryption to protect the master key and only have the master key in two locations (two: Just in case one SSD or computer dies, I have a backup). Browsers do not allow easy access to the contents of one’s clipboard (this is why one has to use Ctrl+V instead of Edit → Paste when using Google Docs in Firefox), so that attack surface, while there, is limited.
- ajross 5y agoI just keep a (symmetrically) encrypted secrets file on my main work machine with a strong pass phrase stored in a gpg-agent. It's simple (emacs will happily transcrypt it simply by opening it) and amenable to straightforward backup/duplication wherever I need it, though obviously it does assume a command line and that I'm not exclusively on a phone or whatever (not that that's impossible, but...). It also has the advantage of scaling in a straightforward way to other secrets that aren't "passwords", like credit card and other account numbers, SSNs for my kids, addresses for relatives who keep moving, etc...
- gspr 5y agoSounds like you have a good system. If you ever find yourself wanting some more convenience commands around a system that's just like what you describe, I wholeheartedly recommend Pass [1]. It's exactly like your homebuilt setup, but with a bunch of convenience commands and git integration built in. [1] https://www.passwordstore.org/ https://www.passwordstore.org/
- fukmbas 5y agoKeePass /Thread
- gregwebs 5y agoI think iOS does this right. It helps you get a password from the Bitwarden app when using the browser. No browser extension with injection is required.
- akdor1154 5y agoAndroid can do this too. Platform rivalry aside, you're right. It would be good to see a proper password manager interface in browser extension APIs.
- stjohnswarts 5y agoI'm going to stick with bitwarden. I'm not really doing anything that makes me a target. I guess someday I may regret it but it's a tradeoff of not being able to use a different password for everything and have a centralized attack point and I choose the latter. I guess it is what it is. I'm not doing anything top secret so I'm guess I'll depend on the security through obscurity that everyone rails against. Also I use 2fa wherever available.
- charles_f 5y agoConclusion is that there's a risk with browser extensions, which is pretty much common knowledge at this stage. Don't use them. Bit disappointed in that conclusion, the intro was pitching for more. Been using keepassxc with auto type, owncloud based replica, a certificate and yubikey for a while now. It's a slight more hurdle than the lastpass and such but also not as blackbox,and the fact that it ain't as much mainstream might make it less susceptible to the mass attacks that we've seen leaking personal data by the gb these past few years
- benlivengood 5y agoThe alternative to password managers is federation. If you're going to trust Apple's or Google's or Microsoft's browser to remember passwords in the cloud then you might as well use SAML or OAuth and stop caring about passwords almost entirely. For the few sites where security matters more than trust in browser vendors it's probably better to memorize those passphrases, or use completely offline password managers.
- closeneough 5y agoI would NOT recommend the chrome password manager. If you sync your passwords, they will not be stored encrypted at the google side. You need to specifically set password encryption in the settings. I've also spend a lot of time with understanding password managers in my master thesis. What I can recommend is: https://pfp.works/ https://pfp.works/ The creator was auditing password managers like LastPass, found a lot of issues, and used his knowledge to create pfp, which does it right imho.
- dxld 5y agoCould you share a link to your thesis?
- closeneough 5y agoIt's still in the works and unfortunately I've written it in German. If you're still interested I'll share a link as soon as it's released. Should be sometime this summer.
- whereistimbo 5y agoIsn't it encrypted using the Google Account credential, if you don't specifically set a password?
- IshKebab 5y agoIt is locally, but server side it is less obvious. They don't really say explicitly but this page strongly suggests that they are encrypted server-side too: https://support.google.com/chrome/answer/10311524 https://support.google.com/chrome/answer/10311524
- shawnz 5y agoThat page is referring to their password breach detection feature though, not password sync. The sync pages have language which indicates that the encryption is only end-to-end if you use a passphrase. See: https://support.google.com/chrome/answer/165139?hl=en&co=GENIE.Platform=Desktop#passphrase https://support.google.com/chrome/answer/165139?hl=en&co=GEN... > With a passphrase, you can use Google's cloud to store and sync your Chrome data without letting Google read it. ... Passphrases are optional. Your synced data is always protected by encryption when it's in transit.
- m47h4r 5y agoI have a bash script which takes in name of the website and generates a 64 character long random string(lower,upper,number,symbol), then puts that in a text file and then encrypts it with gpg using aes256 and puts that file in a dropbox synced directory. Whenever I need to use one, another option retrieves the password, and if I want to use my phone, I just use yet another option which uses qrencode to generate a QR code of the password and then display it using `display` by imagemagick so my phone can scan that to copy the password into clipboard. That's the most safe solution I came up with without trusting third-party solutions. Only downside is dependency on a Linux-powered PC.
- isatty 5y agoThat’s a pretty big dependency because it won’t work when you’re traveling/at work without your personal pc.
- m47h4r 5y agoTrue, though having it synced on the cloud makes it possible (but with more effort) to decrypt the file. Maybe using termux in android. But yeah, that's the downside.
- irrational 5y agoWas this written in 2021 or 2001? How could someone in 2021 not even mention mobile at all? I need a password manager that will work across all of my devices and browsers, not just a single browser on a single desktop machine.
- Kiro 5y agoChrome's password manager works seamlessly across devices and all mobile apps.
- CyberRage 5y agoTavis is an amazing researcher that I respect and look up to. However, I would still advocate for a web based password manager for regular people. The benefits overpower the possible risks which are more targeted than generic. For security personal, like myself, a reliable local password manager is unbeatable. yes, it is less convenient no doubt, but removes any remote based attacks from the picture which is a huge deal.
- raverbashing 5y agoGood article This is why, while I do use Password Managers, I hate the tiny widgets and prefer to copy/paste or use a typeable password. Having your password as "@#$!@#-<_" will just annoy you every time you need to type it and/or use it in an automated fashion (because every system gets confused by $, \, /, -, etc, in different ways)
- PufPufPuf 5y agoI use Bitwarden, and to my knowledge the issue raised in this article does not apply to it -- all interaction is through the extension's icon, with no UI elements injected into the page itself. Combined with being completely open-source (including backend), full-featured even in the free version, and $10/year pro version (with features like sharing, encrypted storage, etc.), I can recommend it to practically anyone.
- troyvit 5y agoI use Bitwarden too, and I self-host it so that vector of attack becomes much smaller. But while Bitwarden doesn't add elements to the page it does alter existing page elements by auto-filling your credentials. If I get it properly the gist of the article is the ability to spoof the fields that receive those credentials. Copying out of Bitwarden and pasting into the visible fields would get around that instead of using its auto-fill.
- RealStickman_ 5y agoAuto-fill is disable by default and you should not turn it on.
- 3v1n0 5y agoThe problem is currently that from an UI POV using the icon to complete is a bit annoying, would probably better if a floating complete icon would be added to the fields when a site is recognized. And that should solve the problem, no?
- shawnz 5y agoNo, because adding the floating icon requires injecting code on the page to create the icon. So then the page has a way to interfere with your password manager's UI. That is the problem with the content script approach. Although if the browser provided a specific mechanism for extensions to create floating icons that couldn't be altered by the page (and you make sure to account for hidden fields and other clickjacking techniques), then that might work.
- tarsiec 5y agoThe problem described doesn’t apply at all with external password managers. Pass hosted in a git repo is still the best.
- fredsted 5y agoI've always found password manager browser extensions to be finicky and brittle. They never really seem to work all that good, and as the author writes, the security is bad. I much prefer just copying the credentials from another application.
- chalst 5y agoThe clipboard itself is part of the attack surface.
- jerjerjer 5y agoIs autosync really that important for people? I use keepass (so no custom browser extensions at all) and I always register for new accounts on my main device. Then, once enough entries amass I manually copy my database into all the other devices I own - usually once a quarter or even less often. That's it. Trusting that some third party service would keep your passwords private is a stretch.
- astrostl 5y agoI expected some kind of argument regarding malware and the potential for accessing your entire password vault.
- ammar_x 5y agoBrowser built-in password managers are much less useful for me than some password manager apps like LastPass. I can use it in Chrome, Safari, on iOS, macOS, etc. If I use Chrome's built-in password manager for example and want to get the password for some website in Safari on iOS, I think that would not be as seamless as with LastPass for example.
- DeathMetal3000 5y agoTo me anyone dispensing security advice while using Chrome loses all credibility. Sure, it’s not an insecure browser per se. But it facilitates Google slurping my data and that falls within my threat model.