4 ms·
Except they can't really do that. The key there is the person's password manager as most of the things mentioned there are online. The user account should just
by _abox 4y ago
Except they can't really do that. The key there is the person's password manager as most of the things mentioned there are online. The user account should just unlock the desktop.
My password manager requires my yubikey to be present, it's pincode to be entered and it to be touched for every use (to avoid remote hijacking). And I don't keep important things logged in.
But xkcd in this case also forgets that the reason for the admin accounts being separate is that most of the usual activity running in the user context means that malware runs in that context too. So it has a much harder time to obtain true persistence and undetectability like this exploit does.
- lvass 4y ago>The key there is the person's password manager as most of the things mentioned there are online Are you sure your passwords/session data can't be exfiltrated by other means, e.g. your .mozilla/.chromium? >My password manager requires my yubikey to be present, it's pincode to be entered and it to be touched for every use (to avoid remote hijacking) Going by KeepassXC docs, the database is encrypted with an HMAC challenge response, changing only on DB save. But if you have the ability to copy the database file and the HMAC response in the same point of time as this malware does, the yubikey part is useless. What password manager are you using?
- pxc 4y agoHow would a GPG-based password manager fare here, assuming it's using a Yubikey the same way?
- lvass 4y agoAFAICT, the strength of both TOTP and public key protocols over fixed-response mechanisms depends on actually having two distinct parties, otherwise you're just adding keys that can likely be all exfiltrated by the same threat. I can see the yubikey being more meaningful if you're storing the passwords in a server whose security you trust more than your desktop, but having an infected desktop is still very bad.
- GekkePrutser 4y ago> Going by KeepassXC docs, the database is encrypted with an HMAC challenge response, changing only on DB save. But if you have the ability to copy the database file and the HMAC response in the same point of time as this malware does, the yubikey part is useless. What password manager are you using? I use a GPG-based password manager (pass) so this is not the case. Each password is encrypted individually using the GPG key in the yubikey. I hate keepass (I have to use it at work because they're stupid). I recently wrote a whole essay on why KeePass is so behind the times to our leadership, I hope they will finally go for something that actually has centralised management and auditing. We've seen teams that have used the keepass filename as master password for example and we have no way to prevent this kind of thing. I also use Fido2 where possible which is even better of course. And yes stuff can be exfiltrated but websites such as facebook, dropbox etc are pretty well defended against session cookie theft these days. I'm just saying there is still a very good reason for the admin account to be boxed off, despite the XKCD makes it seem useless.
- lvass 4y agoInteresting, your passwords are safe even if the machine is infected for as long as you don't use them, that's good. Root access makes absolutely no difference in that aspect though. The point is you can do very real harm without it.
- GekkePrutser 4y agoNo, but malware is much more capable of hiding from antimalware software if it obtains admin rights.
- GekkePrutser 4y agoAnd yes, it also means that only the passwords I actually use are exposed if a machine is compromised. Because each password is encrypted individually.