3 ms·
Can you use your browser's native password manager? Chrome supports syncing of passwords. Just dump a bunch of gibberish into the password field when you regist
by staticassertion 5y ago
Can you use your browser's native password manager? Chrome supports syncing of passwords. Just dump a bunch of gibberish into the password field when you register and let the browser do the rest.
- gtf21 5y agoIDK if this is still the case, but I remember a few years ago it was shown that Chrome was just storing your passwords in plain text on your machine.
- joveian 5y agoFirefox has a way to set a primary password, however IIRC there are some major issues with it. However, it is worth considering what you are trying to protect against and for most single user systems I'm not convinced it is worth using something other than the built in browser password manager (unless you have a number of other applications that require passwords and don't have an easy way to store them). Encrypting paritions with sensitive data is a better way to protect data when the system is off. Unless you clear cookies all the time there is quite a bit that can be done just with cookies, although protecting passwords should at least prevent loosing access to accounts. In some cases a password manager can help with the possibilty of a computer being stolen while on. Uploading unencrypted files right away is easier if someone gains remote access but, while depending some on the specific OS and password manager, it is usually not too difficult to start reading passwords as they are used and intercepting the primary password of the password manager the next time it is used might not be all that hard either.
- staticassertion 5y agoThere's nothing wrong with storing passwords in plaintext on the machine.
- drdec 5y agoOne vulnerability in your browser allowing file system access and now all your passwords are known to the hacker. You run the wrong executable and there go all your passwords again, being uploaded to who knows where. But you 100% trust the authors of all the software you run and you know they would never be vulnerable to a sole chain attack a la SolarWind. Don't keep passwords you can't afford to be public in plain text in a predictable location on the file system.
- staticassertion 5y agoIn every single case you've described the attacker can: a) Already ready your passwords from memory/ webpages/ any other of the million ways b) Access your cookies and session tokens If the attacker is in a position to read the plaintext file off of the disk it really won't matter if it's encrypted. You're welcome to do so, I'm sure there are extremely niche scenarios where it may help, but it's not really worth mentioning imo.
- drdec 5y agoNot all of your passwords will be in memory. I don't know how you read a password from "webpages". Session tokens do not exist for websites you are not currently accessing. The password file will contain all the saved passwords, whether you are logged in or not.
- xboxnolifes 5y ago> I don't know how you read a password from "webpages" When you enter your password to login.
- staticassertion 5y ago> Not all of your passwords will be in memory. They almost certainly will be, but the key will be if they aren't. > I don't know how you read a password from "webpages". Like a billion ways. Inject JS, log keys, install malicious extension, blah blah blah > Session tokens do not exist for websites you are not currently accessing. I'm just enumerating the billion ways that encryption is made pointless. > he password file will contain all the saved passwords, whether you are logged in or not. And the attacker can just access it lol Maybe in a world where full disk encryption wasn't ubiquitous you could talk about an offline attack, and you could tell me you share your computer with someone who's not tech savvy but is an asshole. But it's all gonna be pretty niche.