5 ms·
Is there an intellectually honest response to the notion that products like this, at one level, centralize rather than decentralize vitally sensitive informatio
by scotuswroteus 4y ago
Is there an intellectually honest response to the notion that products like this, at one level, centralize rather than decentralize vitally sensitive information and therefore (1) increase the vulnerability of the customer and (2) paint a big red X on the target, thus incentivizing a higher investment of resources and time for hackers to compromise the product? I want to read that, and I want not to read some snarky idiom-of-non-argument response to that point.
- yucky 4y agoThis has always been my take as well. I understand the appeal of not having to remember multiple passwords, but damn it feels like you're creating a far bigger problem.
- giraffe_lady 4y agoThe basic background is that it's impossible to genuinely create and remember unique passwords for every authentication you need, you will need to have patterns or reuses, or keep them "written down" somewhere. AND THEN, it is inevitable that some of those services will have breaches and poor practices, some of your passwords will be exposed. So the threat model of a "normal user" is that one of their reused passwords will be breached and released, and these services prevent that. If you are in the situation of being specifically targeted because of a system you have access to, you have an entirely different threat model and should consider the tradeoffs in light of that. The centralization can't really be avoided and is also somewhat a separate issue. You can weigh the benefits and risks of doing it yourself, keeping it in a physical book or stack of postits, paying one of these companies etc but it has to happen if you're truly using unique passphrases and none of these is free from risk, either of discovery or unrecoverable loss.
- paulryanrogers 4y agoSome mitigations include: - Rotating important passwords, so old copies are less useful - Bucketing into multiple vaults, easier with file based tools like KeePass, though you could have separate accounts on various SAAS vaults - Requesting to be forgotten from old services, especially those which have shared PII and passwords - Hardware 2FA
- pcai 4y agoOne could argue it is _theoretically possible_ that in expectation, occasional massive breaches of hugely centralized services will actually be less damaging than much more frequent but smaller scale breaches of decentralized secrets on account of the returns to better, compounding, mutually reinforcing security practices benefiting all stakeholders simultaneously It is intellectually similar to the argument that "the cloud providers might have downtime, but they're probably going to have less than your private DC due to the economies of scale and returns on investment in reliability"