6 ms·
I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the mo
by pigsty 4y ago
I feel like there should be a law of the internet for this. The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable.
It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak.
- djbusby 4y agoPigSty's Razor
- _0w8t 4y agoIt all depends on how the data are encrypted. With a sensible design capturing the encrypted storage will only reveal the number of encrypted records, rough estimates on their size, and time stamps.
- accrual 4y agoIdeally it would be an opaque blob with no information about the number of records or their size, just the total size and maybe a last modified or accessed time.
- _0w8t 4y agoPassword managers typically offer to store images like document scans. Without per record encryption one needs to send the whole encrypted blob on each modification.
- WesolyKubeczek 4y agoNot necessarily. You can have a write-ahead log which also consists of opaque blobs and which other devices can pull and reconcile on their own. At some point, a whole reconciled version is uploaded.
- jraph 4y ago> The more a company asserts that their data is secure and encrypted and you should trust them, the more likely it is to leak and be proven to be massively vulnerable. That's a consequence of the Murphy's law [1]. Very well written. You phrased it perfectly for it to have its place at [2] which is full of this kind of stuff. It's almost like this sentence claims itself the right to appear there. If you read French you might enjoy this website. If not, you might still enjoy the different phrasings of Murphy's law in different languages here [3]. [1] https://en.wikipedia.org/wiki/Murphy's_law https://en.wikipedia.org/wiki/Murphy's_law [2] https://courtois.cc/murphy/murphy.html https://courtois.cc/murphy/murphy.html [3] https://courtois.cc/murphy/murphy_original.html https://courtois.cc/murphy/murphy_original.html
- technion 4y agoI definitely feel the opposing law works. When I see a project with a massive disclaimer about "this crypto is not audited, I'm a noob never deploy this anywhere" I'm likely to see better crypto than most of the commercial products I work with, including ones with sales people that talk about unbreakable crypto.
- wepple 4y agoAnd likewise “military grade encryption” usually means “win2k Visual Basic backend”
- wlesieutre 4y agoYour data is automatically translated into Navajo
- FooHentai 4y agoThat’s a great reference, thank you for the laugh.
- kodah 4y agoThat's a silly term for that. Commercial businesses have the same access to NIST that the military does. Their guidance is even free! Military grade when we're talking about a screw is a little different. It means that the screw is made and QC'd to a very specific spec/standard. My next question might be, "Where can I find you on the FedRamp approved list?". To which, I'm sure they'd respond that anything outside the algorithm is not military grade, which is what most attackers will exploit in the end.
- whatshisface 4y agoIn electronics military grade means it works over a wide temperature range. That's about it.
- deleted 4y ago[deleted]
- waboremo 4y agoThat assertion should be accepted even if you store your password offline.
- noduerme 4y agoHow hard is it to store encrypted data that needs a locally held master key to decrypt? Pick any industry... You'd have to be willfully ignorant or outright corrupt to fail your core business promise, wouldn't you?
- quanticle 4y agoThe average user that LastPass caters to thinks that a "backup" is the reason they were late for work in the morning. LastPass doesn't want to be in a position where they're telling their users, "Sorry you're SOL," if their device breaks and they don't have a second copy of their locally-stored encryption key.
- noduerme 4y ago[edit] I guess that's true. I'm not sure who their users are, but obviously not people overly concerned about security. [/edit] Just because I think it's funny - every time I visit my dad (who's in his 80s) he regales me with his startup ideas. "Why don't you build something that I can put on my glasses so when I lose them I can find them? Whoever invents that would be a billionaire." I say, "Yeah dad, they have that." "Why don't they make it so I don't have to remember passwords for all these different websites? I could just have one password and it would remember it for everything." I think I've explained at least a dozen times why I think third party trust is a bad idea; I've had to really refine it down to the level of explaining this to a six year old. But the salient point here is that even my dad never signed up for LastPass. So who the fuck is signing up for LastPass?
- riffraff 4y agoCompanies. It is to convenient to use a shared password manager to share passwords within a group of people or some such. Also techies have been telling non-techies "use a password manager!" for years, and people fail to evaluate one solution or the other. My brother in law (a non technical person) was telling my wife last year how good LastPass was for him!
- smegger001 4y ago>It’s fine to store your passwords online for convenience, but as a user, it’s important to accept that it’s no longer your private password and will, at some point, leak. ehh. I store my passwords online but its on a file I encrypted offline with strong password (over 20+ characters) and key. I use keepass which is a locally encrypted and stored password manger, and I store the DB on Dropbox and download it to any of my computers/devices were it is decrypted locally when needed. I don't trust password wallet services ass they all seem to want to do the enryption server side with a reset-able password which really means they have the master password not you, but my set up seems secure enough to me.
- 12907835202 4y agoHow does this work with mobile chrome/Firefox etc. Does it sync?
- smegger001 4y agothere is a keepass compatable app on fdroid i use, and it can sync just by syncing the db over dropbox
- xnickb 4y agoI have a similar setup, except I use Syncthing. Works fine with Keepass2Android/KeepassXC on both Windows and Linux machines. Occasionally I might need to do some manual steps (a week ago windows stopped running Syncthing and that caused some conflicts down the road), but most of the time it just works. If you have specific questions, feel free to ask.
- konha 4y ago> I don't trust password wallet services ass they all seem to want to do the enryption server side with a reset-able password which really means they have the master password not you None of the popular password managers work this way.
- milkshakes 4y ago
- deleted 4y ago[deleted]
- Shorel 4y agoNo. Security is the area where fast and fuzzy heuristics get you into problems. Examine each option critically and reach independent conclusions.