4 ms·
Using "password manager for everything" comes with a critical disadvantages of making the pass mgr a single point of failure, increasing attack surface area. Ta
by devdiary 4y ago
Using "password manager for everything" comes with a critical disadvantages of making the pass mgr a single point of failure, increasing attack surface area. Take an example of recent Lastpass breach, I am pretty sure it will lead to hacking almost all services for some Lastpass users. Although Lastpass is saying - don't worry, your passwords are encrypted with your master password and it will take million yrs to crack them. No, it won't take even a month/day to crack master password of many of those users. You're overestimating people's ability to create strong master password and the efforts needed in cracking a password.
I'd rather be very specific in suggesting password managers, use them only for non-critical services.
- xcdzvyn 4y agoHard disagree. The problem with Lastpass being pwned was Lastpass being Lastpass. Put your passwords in a password manager, don't put your passwords on the internet in The Cloud™. > You're overestimating people's ability to create strong master password and the efforts needed in cracking a password. Okay - so we're establishing that many people use insecure passwords. Password managers mitigate this risk completely by generating incredibly secure passwords - however, people may use an insecure master password. > I'd rather be very specific in suggesting password managers, use them only for non-critical services. And your proposed solution is for people to use NO secure passwords, but to use their poor password creation abilities on every site they use. This only leads to people using insecure passwords _everywhere_, rather than in one, local file, which is far less likely to be attacked.
- darkwater 4y ago> Put your passwords in a password manager, don't put your passwords on the internet in The Cloud™. Which doesn't work well in a multi-devices landscape as the one we live in for many people (even if not the majority, because the majority probably just owns and uses a smartphone).
- albuic 4y agoIt works well for me, you just need to synchronize your password manager's file once in a while. Are you really creating that many accounts ? And you can use anything even cloud providers to easily synchronize the single file. I don't use cloud password managers, history has shown it is too risky.
- xcdzvyn 4y agoSyncthing has never failed me for this.
- devdiary 4y agoThat's what I meant to say - don't put your critical services passwords in one cloud password manager
- debarshri 4y agoHaving reduced threat vector is sometime better that having multiple threat vectors spread all across. You can make the same argument for VPN server. Apart of lastpass hack, I cannot think of any other password manager hacks that have lead to password being compromised. I absolutely agree that in an enterprise setting there has to be another layer of security on password managers. But with password managers, credential usage and sharing becomes seamless that can lead to less leakage.