7 ms·
Good advice. Ever since Tavis Ormandy set his sights on password managers, I have been a very sceptical user. I still use 1Password, but without the browser ext
by mjthompson 5y ago
Good advice. Ever since Tavis Ormandy set his sights on password managers, I have been a very sceptical user. I still use 1Password, but without the browser extension. Putting autofill aside, there's a couple of other concerns I have.
I am hesitant about recommending a password manager to the tech illiterate simply because one piece of malware could compromise the entire vault. In that respect, a sticky note is arguably more secure than a tech illiterate person using a password manager.
Also, I have my usual criticism of client-side browser encryption. Anyone who has the technical ability to compromise a cloud-based service can likely take it a step further and modify JavaScript files enabling total vault compromise. There is no easy way for a user to mitigate this risk.
Password managers must be a stop-gap measure only until webauthn is more widely deployed. I long for the day when phone-based webauthn keys are the norm, and I can stop fielding questions about password managers from friends and family.
- bmurphy1976 5y agoYou still need 2FA and the 2FA absolutely should NOT be a part of your password manager. Use a different app at the very least. This should help alleviate some of the worst password manager risks.
- tialaramex 5y agoUnder WebAuthn you can have 2FA despite only one authentication flowing from your authenticator to the web site. Nice smartphones (say, a modern Pixel or an iPhone) with fingerprint readers, have as the two factors your fingerprint (something you are) and the phone itself (something you have). The phone signs your authentication, the private information (your fingerprint) never leaves the phone, it just warrants that it checked it (UV bitflag in the signed data) Or say you have a FIDO 2 Security Key from Yubico. As well as the features of the cheaper FIDO 1 Security Key products, this has a PIN verifier. The PIN is something you know, while the Security Key itself is something you have, so that's two factors, once again the UV bitflag is signed. It's simpler, it's easier, it's more secure. And yet, right now I bet an HN reader is implementing yet another shitty SMS-as-2FA hack and we're still in a thread about remote authenticating with passwords - an idea that was already terrible in the 1970s.
- valenterry 5y agoWhat if the phone is fully compromised?
- kmonsen 5y agoIs there any realistic scenario that protects against a fully compromised phone/computer?
- valenterry 5y agoI mean yeah, if you use 2FA and both phone and computer are just one factor on their own, then a compromised phone does not matter. So my question is, how about the mentioned scenario - to me it seems that just compromising the phone would compromise the whole, but maybe I misunderstood.
- tialaramex 5y agoWhat about it? If your threat model is "People fully compromised my phone" then you should definitely not rely on the phone in the face of that.
- Marsymars 5y ago> You still need 2FA and the 2FA absolutely should NOT be a part of your password manager. Use a different app at the very least. Recommended if storing 2FA codes in a password manager is to use 2FA for the password manager that isn't stored in the password manager. Off the top of my head, that doesn't seem to really open up any additional risks over storing 2FA passwords outside of the password manager. Personally, it's a matter of practicality - I use my phone for personal 2FA codes, but don't have a work-provided phone and am not going to use my personal phone for work purposes - and as many services now require 2FA, it's easiest to store those 2FA codes in my work-provided password manager.
- emodendroket 5y agoA piece of paper is the most secure solution, sure, but once you get to the point where you have a hundred passwords, even if you've got them all in the same place, it's too unwieldy to use.
- ericd 5y agoTime to revive the rolodex...
- sitkack 5y agoWith a polarizing filter, oled display, vision based user recognition and a nice haptic knob, hopefully in some sort of upcycled oak, alder or white ash.
- geoka9 5y agoDon't forget wifi connectivity...
- lmohseni 5y agoA web based admin interface might be handy as well...
- sitkack 5y agoOhhh, with automatic firmware updates! Maybe it syncs over Bluetooth, or pretends to be a car infotainment system to keep a copy of your mobile contacts. The complexity probably warrants some sort of embedded microservice arch, like microK8S.
- dredmorbius 5y agoThat was going to be my suggestion. I'm a fan of Zettlekasten for notetaking and knowledge management. Filing passwords on index cards or business cards (3.5x2 in, ~9x5cm), with a sensible indexing system, scales up reasonably well. There's certainly extant physical infrastructure. The typical person has on the order of about 100 online accounts. Managing even 1,000 accounts in an index card file is at least within reason. Another alternative is a GPG-encrypted file, though keeping that synchronised between multiple locations might prove a challenge.
- jefftk 5y agoA sticky note doesn't protect against phishing, though, which is a much more likely risk for most users.
- mjthompson 5y agoA password manager only really offers marginal phishing protection, in the sense that 'automatic autofill' (as defined in the original post) is not available with an unrecognised website. The problem is most profound with tech illiterate folk. If you have tried to teach a tech illiterate person how to use a password manager (as I have), you may have encountered the issue that 'autofill' isn't 100% accurate. You will occasionally hit a subdomain or alternative domain which using the same credentials as the saved website (eg amazon.co.uk vs amazon.com). It will appear that no credentials are available for that site. Therefore, you usually have to teach the person how to manually search the vault and either fill manually, or copy and paste credentials. Otherwise, you can expect phone calls for support. And, of course, the original article actually suggests disabling automatic autofill. It suggests filling manually, further opening up the possibility of mistakenly filling onto a dodgy domain. As soon as you teach them a workaround to deal with this case, the phishing vector is basically no different to a post-it. This problem might also apply to a tired, tech literate person, who mindlessly fills manually or copies credentials without checking the domain. In either case, we fall back to Google Safe Browsing doing its job properly, and await solid anti-phishing solutions like FIDO2/webauthn.
- BeefWellington 5y ago> A password manager only really offers marginal phishing protection, in the sense that 'automatic autofill' (as defined in the original post) is not available with an unrecognised website. I don't know if alerting the user that something is wrong could be described as "marginal" for phishing attacks. Sure, they may still make the bad decision but it might seem odd to them that their password manager didn't offer to fill it in for the site and get them to start looking around and double checking things.