14 ms·
Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to acce
by twostorytower 5y ago
Highly recommend 1Password with Yubikey/TitanKey protection. This means even if somebody had your master password and private key, they'd need a Yubikey to access your 1Password account from a new device. It's pretty much fool-proof unless you're kidnapped and held hostage.
- nathancahill 5y agoAh yes, the $5 wrench method.
- 1001101 5y agoA simple rubber hose would do. https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis https://en.wikipedia.org/wiki/Rubber-hose_cryptanalysis
- cgb223 5y agoCome on, this is hacker news. Some of our skulls are so thick you’d need at least a $10 wrench
- echelon 5y agoAlso known as the "So you think you can escape the FBI [/CIA/FSB]?" fallacy.
- vorpalhex 5y agoI mean, if your threat model is such that you need to consider kidnapping and being hit with a wrench, as opposed to just a drive by breach, then you should in fact account for that appropriately.
- ohyeshedid 5y agoAre you aiming for perfect or have you stopped at good enough?
- kobalsky 5y agoThe xkcd author did a disservice to online security with that comic. You can be forced to disclose your secrets but you will know they were compromised, that's encryption doing its job. There's a world of difference in knowing.
- SV_BubbleTime 5y agoSame in the world of lock picking. I can smash your door in, or simply break a window. The difference is you’ll definitely know I did it. But unless you in the routine of checking your lock pins for scratchmarks, you probably wouldn’t know if someone picked the locks.
- FearlessNebula 5y agoWhat if you’re in another country and your devices get stolen? Should you bring the Yubikey to travel? What happens if there’s a fire at your house and the Yubikey is destroyed?
- jcoq 5y agoYou can add multiple keys to the account.
- FearlessNebula 5y agoSo is the recommendation to get something like 3 keys and keep them in different safe places and bring one when you travel? I’ve been considering getting a Yubikey. Do they work on mobile? Edit: Looks like some Yubikey work via nfc for mobile.
- vorpalhex 5y agoYes, you should always have at least two and keep one in a reasonably fire resistant safe. You may want to enroll multiple and keep them in other places too, but you can't enroll a key you don't have so things like a safe deposit box are not useful for the average case.
- FearlessNebula 5y agoI guess try to follow 3-2-1 backups as closely as possible: 3 copies of your 2-factor, 2 different mediums (a Yubikey and recovery tokens printed on paper), at least 1 in a different location (safety deposit box, trusted family members house, etc).
- gruez 5y ago>You may want to enroll multiple and keep them in other places too, but you can't enroll a key you don't have so things like a safe deposit box are not useful for the average case. That seems like a usability nightmare. Are there plans to improve this? Hardware wallets for cryptocurrencies seem to have it solved. You can keep multiple copies of the keys around (ie. multisig wallets) for maximum security, or you can write down the private key of the device you have and store it somewhere safe. In either case you can retain the public keys so you don't need access to the device if you want to send funds to them (or in the case of authentication tokens, enroll them).
- chumboslice 5y agoYou can do this with LastPass.
- gregsadetsky 5y agoI'm the OP from yesterday's story. I had 2fa enabled on my LastPass account, but didn't have access to the phone anymore. I clicked a link, LP sent me an email, and I was able (through that email) to remove 2fa. It doesn't make their 2fa completely useless, but it's not great.
- staticassertion 5y agoThat sounds fine to me tbh. It's worth knowing, but it's not weak. Email is a pretty good 2FA in terms of security, it's just not great in terms of usability, so it makes for a good fallback. Attacker with MP + email access is pretty severe. I wish more services used email as a 2FA instead of SMS.
- _jal 5y agoNope. Keeping my secrets store on someone else's computer is simply not compatible with my threat model. Yes, they say it is encrypted, and I believe them and believe they're competent. But competent people write vulnerable code all the time, disastrously bad hires happen (see Unifi), and companies go bad. You can't un-disclose information stored with them, only laboriously invalidate it.
- politelemon 5y agoAgree. Moving from one proprietary online solution to another proprietary online solution isn't the answer.
- FearlessNebula 5y agoHow do you sync your passwords across all of your machines? Do you self host your passwords on your own server? Do you manually sync?
- miked85 5y agoNot OP, but I use the standalone version of 1Password + Resilio Sync.
- dylan604 5y ago1Pass has the ability to sync via WiFi, Dropbox, iCloud, etc. I only use the WiFi as the other options are still cloud platforms I don't trust.
- cshepher 5y agoThese have all been removed in 1password 8. It is cloud-only, subscription-only.
- karmakaze 5y agoWhat's your personal threat model? I'm always trying to balance the risk of a party focused on security vs the minimal effort I'm likely to put into it. I don't want to be a story about the guy that lost their password to a wallet or anything else important. I used to be able to reliably remember complex passwords reliably but finding that's no longer the case, now only shorter intermittently used ones based on how often I have to use "reset password".
- mattrighetti 5y agoThis kind of feature is also available on BitWarden Premium
- YeBanKo 5y agoEver since 1password removed local vaults I am looking / waiting for a decent alternative. I also wonder what the impact of that move was on enterprise users, as they don‘t have hosted version.
- MeinBlutIstBlau 5y ago