5 ms·
You can never trust cloud-hosted password managers..
by only4here 5y ago
You can never trust cloud-hosted password managers..
- mateuszf 5y ago> You can never trust cloud-hosted password managers.. If you examine the source code of a client (for example bitwarden) and make sure that it's not leaking your master password and then compile the soft yourself and not update - you'll be pretty safe. This will make it similarly secure as e.g. keepass, because even for keepass you should be sure the source is legit
- nisegami 5y agoTechnical trust is one thing, but I think the trust GP is referring to is more of a trust in the company's commitment to the business model. Password Managers aren't sexy. There isn't a ton of disruption possible in the field, so these companies may tend to look to expand beyond password management or get acquired. This in turn can mean the password manager product will be left to rot.
- chefandy 5y agoMaybe you can't. Everybody has their own risk tolerance, but at some point, everybody's going to have to draw a line. Maybe you're only storing passwords for local services, but almost all of the credentials in my password manager are for services run on some cloud. Even then, did you evaluate all of the code for each of those services? How about the compiler code or the chips? Dell shipped out machines with a hardware trojan in 2010. I have separate instances for work and personal accounts, so one breach wouldn't affect the other. Since my passwords are distinct, the number of accounts that would actually be useful to them is minimal, and fraud response is a pretty important metric in deciding what companies I do important business with. Identity theft is a problem, but all of this is probably more likely to be leaked in some other database, like the Equifax hack, than through an account compromised in a password manager cloud storage breach. My password manager being compromised would indeed be a huge time suck, but I don't think the long-term consequences would be any more severe than a few key individual accounts that are probably even more vulnerable. I think things like coordinated attacks where they social engineer their way through 2FA— which have been seen in the wild— to present a greater real-world concern.
- ifyoubuildit 5y ago> Maybe you can't. Everybody has their own risk tolerance, but at some point, everybody's going to have to draw a line. I'm in agreement with parent, I think putting your passwords in the cloud is a wild single point of failure. Even if you can tell a compelling story about how they carefully encrypt everything right now, you're always a silent update away from it all being dumped on the internet. I think people (in aggregate) just don't care about the risk and will take the path of least resistance. They don't have to draw the line there, but they will. > My password manager being compromised would indeed be a huge time suck, but I don't think the long-term consequences would be any more severe than a few key individual accounts that are probably even more vulnerable. Having your main email account compromised seems like an absolute nightmare where you potentially lose control of every single service that you subscribe to (banking, utilities, cell phone (so maybe 2fa is even broken), medical portals, social media, etc). Having your entire set of passwords compromised is like that on steroids. Rather than your attacker having to use your email to get to each of those services one at a time, they just have them immediately. And who says you'll even know that your stuff was compromised? I'm a bit of a crank though. I don't do any of the smart home stuff. I see my phone as a necessary evil. If some company shoehorned an app or a WiFi connection into their product, I don't buy it. After being in tech long enough, I just want things that work for me, not for the company I bought them from.
- avianlyric 5y ago> you're always a silent update away from it all being dumped on the internet. This is true of all password managers that have any ability to connect to the internet. You’re one silent update away from your manager suddenly uploading all your passwords to a random endpoint in Russia.
- ifyoubuildit 5y agoTheoretically, if you audit the source then you only really need to care about updates to the actual code. If it doesn't do silent updates then it can't change underneath you, even if it does some kind of network operations. Its not fool proof, but it feels better than a black box that could be a different black box tomorrow or after the next acquisition or round of investment.
- velcrovan 5y agoYou can never fully trust any password manager unless you audit all of its source code and compile it with a compiler whose source code you have also fully audited. Good luck!
- deleted 5y ago[deleted]