5 ms·
This is a really great user experience. One thing I wonder about is if people start logging in without their password all the time, will they slowly forget what
by presto8 4y ago
This is a really great user experience. One thing I wonder about is if people start logging in without their password all the time, will they slowly forget what their password is over time?
Partly to force memory reinforcement, I set the password cache time of gpg-agent on my machine to 24 hours maximum. Thus I have to enter my password once a day, which helps me to remember it; but it isn't overly burdensome.
Although maybe if one always has
- joombaga 4y agoThat's is exactly what happened when I configured the LastPass browser extension to remember my password. I needed it to switch USB security keys and had no idea what it was. The saved password in my other browser's extension saved me.
- haspok 4y agoMy master password is "public" (I put it in a mail draft, also a note on my phone and printed it out on a piece of paper, just to be sure), and I have 2FA enabled via Yubikey. I never really understood why I had to always provide my master password anyway when logging in even on a trusted device, as the whole point of a password vault is to no longer have to remember any passwords... but we are getting there, eventually.
- sebk 4y agoI'm not sure what service you're using, so this might or might not apply to you: Consider that some password managers use MFA to allow you to connect to their online service that will download a synced, encrypted copy of your password vault, but the vault itself is only wrapped with a key derived from your master password. If someone was to obtain a copy of your vault, decrypting it would be trivial with a weak or compromised master password in that case. CTAP supports an extension called hmac-secret that would allow you encrypt your vault, which would mitigate this issue (While introducing others potentially -- for instance, hmac-secret does not require user verification so anyone with your yubikey could decrypt it). Of course there are other mechanisms to encrypt a vault other than a key derived from a password that you can use with a Yubikey, like PGP, but I don't know of any commercial password manager that does it that way.
- presto8 4y agoYou bring up good points: ideally, there would be no need to remember a passphrase at all! Especially since the passphrase has to be long and unwieldy in order to be resistant to offline dictionary attack. The thing I worry about is that the security of the passphrase is only as secure as the mechanism guarding it. If it's written on a piece of paper, then how is the paper secured? It could be put in a vault, but then the vault itself is a conspicuous target for thieves. Hiding the paper somewhere is probably pretty reasonable, but if it's too well hidden, it could get forgotten or accidentally thrown out over time. I use a YubiKey as well as an ultimate backup, and it has a PIN code mechanism that will lock after a few incorrect attempts, so that is a reasonable tradeoff for security and usability I feel. I wonder if the best solution is to have a distributed copy of a recovery passphrase to friends and family. Then separately have a distributed copy of the vault itself (in my case, it's GPG-protected Password Store). This must have been an area of study already, I need to do some research!