5 ms·
A lot of the criticism of this article seems to be: “If they already have access to your local file system, you already have bigger problems” What about defenc
by quickco 4y ago
A lot of the criticism of this article seems to be: “If they already have access to your local file system, you already have bigger problems”
What about defence in depth?
This article is suggesting an alternative, which are password managers such as 1Password. These Password managers do not suffer from the same weak key storage as the browser’s build-in password managers.
So this article is bringing attention to a weakness in the browser’s built-in password managers, and suggesting a very viable and easy-to-adopt solution.
Why the strong criticism of this article?
- Double_a_92 4y agoBecause it might imply to users that using nothing is better. Which leads to people reusing simple passwords... or post-it notes.
- MarkSweep 4y agoThe article states that there is a big problem, but the solution it gives only incrementally improves the situation. If passwords stored in plaintext is a problem, don’t just use slightly harder to access storage. Use SSO so there are not credentials to steal. If the article gave a complete picture of what to do to mitigate the damage of endpoint compromise or was less alarmist in its assessment of risk, I would have liked it better.
- MattPalmer1086 4y agoThat's a fair assessment of the article I think. It's a genuine threat, and one we have had to deal with in a small way before. Most of the criticism I've read here seems to be dismissing the threat entirely, using the weak "if that happened you've got bigger problems" argument.
- CamperBob2 4y agoWhy the strong criticism of this article? These articles always assume everyone has the same threat model: you are head of the NSA's IT department, and hostile nation-states are spending billions to attack your security with everything from 1024-qubit computers to $5 pipe wrenches. Forcing users to employ the same security tools and practices that would be appropriate for dealing with far more serious threats is just annoying, and likely to result in passive-aggressive resistance.
- inshadows 4y ago> What about defence in depth? It is a manager-speak buzzword. What about it?
- nl 4y agoMany think integrated password managers create more vulnerabilities than they solve. https://lock.cmpxchg8b.com/passmgrs.html https://lock.cmpxchg8b.com/passmgrs.html is a reasonable overview of this. > So this article is bringing attention to a weakness in the browser’s built-in password managers, and suggesting a very viable and easy-to-adopt solution. Because many actual experts disagree it is a weakness > Why the strong criticism of this article? The advice tries to make it out like browser suppliers are doing this to lower security for some unknown reason, whereas actually their model is safer than what is recommended. It is possible to argue against browser suppliers here, but you need to look at their arguments for doing it that way. This article doesn't do that.
- pdpi 4y agoThe problem is that the article takes on this hyperbole-laden all-or-nothing tone that does nobody any favours. If you go along with the all-or-nothing mentality, then local file system access is pretty much game over anyway. If you want to take the security-in-depth approach, you have to first apply it to these password managers and take an honest look at the problems they solve. And it turns out they’re amazing from a cost:benefit benefit perspective. Put differently: go read the spectre/meltdown papers. Imagine if _those_ were written in the same tone this is. That’s the problem.