3 ms·
> about the insecurity Passwords don't have to be insecure, that's precisely the point of a pwd manager (apart from having a different pwd for every service).
by usrbinbash 5y ago
> about the insecurity
Passwords don't have to be insecure, that's precisely the point of a pwd manager (apart from having a different pwd for every service).
- mr_mitm 5y agoThey're insecure in the sense that you must tell someone your secret. Using a secret key means that the secret never leaves the system, it appears accidentally on the screen much more rarely, it can't be quickly remembered, can't be seen by keyloggers or clipboard monitoring software, ... In an ideal world, we'd be using private keys on something like a smart card secured by a pin for everything.
- usrbinbash 5y agoIf we assume a system compromised to the point where the attacker can install key/clipboard loggers, then private keys (which are usually also secured by a symmetric password that has to be entered on the system) won't help us either. If a level of security is required where even a compromised end user system is not enough for an attacker to authenticate successfully, then MFA is the only answer, and that is not an argument against passwords, because it doesn't matter what the other factors are.
- mr_mitm 5y agoI agree that nothing can save you once your system is compromised. But that is not equivalent to having a keylogger, because physical keyloggers exist (or keylogging via camera, if that suits your definition of keylogger). Clipboard monitoring can also happen accidentally via remote desktop clients or virtual machines. No matter how you slice it, there are many more scenarios where passwords can get leaked compared to private keys being leaked. If everyone used private keys instead of passwords, the total number of compromised accounts per year would be substantially lower.
- usrbinbash 5y ago> If everyone used private keys instead of passwords The only difference between that and using a pwd manager: using a key-pair requires more infrastructure (namely public key repositories). I'd still have a master key to everything (the symmetric key used to encrypt my priv. key).