5 ms·
>Passwords must be shared to work, therefore they can never truly be secret. Password managers already fixed this. Your password is unique per website so it do
by SilverRed 5y ago
>Passwords must be shared to work, therefore they can never truly be secret.
Password managers already fixed this. Your password is unique per website so it doesn't matter if the service knows it since they could already login as you anyway.
- Xylakant 5y agoAn adversary with network access (looking at you, corporate firewalls) can read your password as well, not only your computer and the service. If the site uses a CDN, then it's likely that the endpoint for the TLS connection is the edge node, not the service itself and that the connection is re-encrypted from the node to the service (or even on an unencrypted connection from there on). An attacker may have breached the service and exfiltrate passwords. The service may have a config error and log plain-text passwords to an unsecured elasticsearch instance. The service provider may have bad security practices and store the password in plain text or using an insecure hashing scheme. All of these problems go away if you use some sort of asymmetric authentication since the public part is by definition public.
- jve 5y ago> An adversary with network access (looking at you, corporate firewalls) Well, if you use corporate device, you implicitly trust them, don't you? Some even sign put signature on a paper agreeing what the corporate body can do to you. Perhaps MITM your encrypted traffic with corporate installed root cert or whatever. Otherwise if you use your own device, in the age of encrypted HTTP and other stuff - No, an adversary or corporate firewall cannot simply read your password.
- blitzar 5y ago> Well, if you use corporate device, you implicitly trust them, don't you Well, if you use microsoft, you implicitly trust them, don't you Well, if you use <insert ISP>, you implicitly trust them, don't you Well, if you use the internet, you implicitly trust them, don't you
- SilverRed 5y agoYes. If you don't trust microsoft and you use windows, than it doesn't matter what authentication system you use. If you used rsa keys for auth then you would still have a problem because microsoft could steal those keys.
- Xylakant 5y ago> Well, if you use corporate device, you implicitly trust them, don't you? Some even sign put signature on a paper agreeing what the corporate body can do to you. Perhaps MITM your encrypted traffic with corporate installed root cert or whatever. I may have to submit to the inspection of traffic whether I trust them or not and even if I trust them to have the best intentions, things go wrong and firewalls get hacked - and all of a sudden that nice capability is in the hands of an attacker. So even if I do trust them, I prefer mechanisms that work asymmetric.