5 ms·
Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me
by chank 4y ago
Having all your keys/passwords on a 3rd party server is something that I've never been willing to accept from a security standpoint. That's what always kept me from using a `hosted` solution. I do get the allure from a multi-user management aspect though.
- smt88 4y agoI used to use KeePass and synced the database (but not the keys or password) with Dropbox. Very secure and mostly convenient.
- bigiain 4y agoI loved a similar setup when 1Password used to make that easy. I am very grumpy about them bait and switching me to a cloud/subscription model. (But not quite grumpy enough to have done anything about it yet.)
- chank 4y agoVersion 7 is still available on their website to download (if you have a key for it). Oddly enough they still do update it. It's what I use and likely will use until it no-longer works or there is some issue with it.
- lolinder 4y agoIs the added security just that Dropbox is a lower value target (possible) and that attackers won't think to look for password databases in Dropbox accounts if they do compromise Dropbox (less likely)? Or is there something more to it? EDIT: Given the replies below, I should be clear that I'm not interested in comparing to LastPass, I'm comparing to Bitwarden. LastPass had an obviously bad security model that failed to encrypt everything, but Bitwarden does not have that flaw.
- aborsy 4y agoNo. When you login to LastPass, your password can be taken if LastPass is compromised. You have to trust that LastPass will not do it. If you login to Dropbox, the master password to your keepass database cannot be stolen. You don’t need to trust Dropbox. But what you said is also an additional benefit.
- lolinder 4y agoIn theory, the master password is never supposed to leave your device even with the cloud-based password managers. So, yes, you're trusting that their clients do what they say they do, and I suppose an attacker could hijack the client and offload your password. That said, the same risk applies to any client you use. Someone could have compromised the latest update of KeePassX as readily as they can compromise LastPass's client. If you don't have automatic updates then that's helpful, but I'm not sure it's producing enough security to be worth the extra hassle.
- Dylan16807 4y agoHaving to compromise KeePassX rather than Dropbox, and specifically while you are updating, is not an insignificant difference.
- lolinder 4y agoHaving to do it while updating narrows the window of opportunity for sure, but I don't think KeePassX is a more secure target than Dropbox or Bitwarden. They don't have to get bad code into an MR (though that's one option), they could compromise the website and have it distribute a different binary. If you build it from source you're safe against that, but are you really building it from source? Also, remember that the same logic applies to Bitwarden: they need the master password and therefore must compromise the client during the window where you update it.
- roperj 4y ago> Or is there something more to it? The part where they said they do not store either the key or password on Dropbox.
- lolinder 4y agoYou do not store the password on a password manager either. LastPass swears up and down that they never see your master password, all encryption happens client side. I can see good reasons not to trust LastPass at their word, but Bitwarden?
- dspillett 4y agoDrop box is just the sync mechanism, with keepass' encryption (and their own care to keep the keys safe and not carried on the same medium) being all the protection. Dropbox is not added security in this setup, it is a natural factor if what is being transferred [the keepass file(s)] is sufficiently secure in itself.
- lolinder 4y agoI know Dropbox isn't added security, my question is why Dropbox losing the vault wouldn't be just as bad and as likely as Bitwarden losing the vault? Another reply indicates that the main thing is that you don't have to trust the cloud service to do the encryption and zero-knowledge stuff right.
- disillusioned 4y agoNo possibility for a MITM attack (except, I suppose, with a keylogger, but then you've got bigger problems), and absolutely NOTHING outside of encryption, whereas whoever has this leak now knows what users have accounts on what websites, which is a veritable treasure trove. That plus security through obscurity: no one is presuming you're going to come out of a Dropbox hack with millions of password vaults. Even finding them would be... nightmarish. (Though I suppose you could somehow hack a Dropbox file index database?) The value of a target like LastPass is absolutely insanely high: it's a concentrated honeypot of encrypted vaults. Plus, the Android app makes using a Dropbox synced folder location fairly trivial, so that works pretty well. And you can set your own number of password rotations, which, while annoying when it takes my phone 5-10 seconds to unlock, realllllllly helps ensure no one else is going to crack this vault if they ever got it.
- lolinder 4y ago> No possibility for a MITM attack ... and absolutely NOTHING outside of encryption LastPass is a disaster, but in theory these benefits are true of Bitwarden as well. They say they encrypt the entire vault, no exceptions, and do the encryption entirely on device. I can see the honeypot argument, but Dropbox is also a big honeypot for different reasons (tons and tons of plain text information that could be very valuable in the right hands). And I don't think finding the vaults would be as hard as you think it would, because searching for encrypted files should be relatively easy, and any encrypted file is probably worth attempting to crack. I'm not trying to argue for cloud password managers, I'm totally open to being persuaded and would immediately switch if I were, but I'm really failing to see where the added security is versus Bitwarden. Bitwarden is open source just like KeePassX, so if it did not implement the security model that claims to I think someone would have blown a whistle by now.
- mgsouth 4y agoThe database is encrypted when at rest; i.e., no plaintext is stored on Dropbox. Assuming your master password is decent, you could plaster the database on a billboard and it would be safe. LastPass, on the other hand, encrypts some information (the actual passwords). The URLs and other sensitive information is stored in plaintext in the cloud. [Final edit. I swear.] As you note, as long as the entire blob is encrypted it doesn't really matter how it's replicated; BitWarden's one-stop-shopping can certainly be more convienent.
- lolinder 4y agoBut that is the same claim that Bitwarden and 1Password make. Both insist that they don't ever see your master password, which means that your vault security depends entirely on it being good enough. And both encrypt everything. Assuming that I trust Bitwarden not to lie about their security model, what do I gain by piecing together multiple tools to accomplish the same thing?
- mgsouth 4y ago(Sorry, I turned around and made an edit, but not before you replied.) KeePass encrypts the entire database, all fields, as one giant blob. LastPass stores URLs and other fields as plaintext; these too can contain critically sensitive information. [Edit: (See I flagged it)] As far as know it wasn't LastPass's client that was compromised--it was their servers/data store.
- deleted 4y ago[deleted]
- lolinder 4y agoHaha, the edits got very confusing but I think we're now on the same page.
- dzikimarian 4y agoTheir software does see your master password. It may process it locally, it may not. If it's run in web client inside browser, that may change at any second. This may happen due to attack, their mistake, their dependency vulnerability or plain lie on their part. Fundamentally you need to trust them. In case of keepass and independent sync(doesn't have to be Dropbox), software that sees master password doesn't need access to the internet. Can be even airgapped if you are extra paranoid. So to sum it up: keepass + sync is better, because there's no single party that is even able to screw up you to the point of leaking your passwords. "Impossible to fail" is better than "they are doing their best, pinkie promise". Also - why pay recurring fee for yet another cloud storage, when I just need plain encryption software.
- eternityforest 4y agoDoesn't KeePass use a single database file with no conflict resolution? I looked at using them but ultimately decided against them, a conflict overwriting a password scares me more than even just using chrome sync and calling it a day.
- smt88 4y agoI use 1Password now, but KeePass has conflict resolution and also a full history of all secrets.
- eternityforest 4y agoSeems like KeePass apps on Android often have decent but not quite perfect UI around conflict merging: https://www.ctrl.blog/entry/keepass-file-conflicts-android.html https://www.ctrl.blog/entry/keepass-file-conflicts-android.h... It does seem to be solvable though. I could see myself using SyncThing+ KeePass if I ever became unsatisfied with BitWarden and I found an app without too many sync issues.
- robbintt 4y agoWrite yourself a graph of your core account recoveries, don't put those on. Just put your leaf accounts on (those that recover from the core accounts).
- jeeeb 4y agoFWIW. After using it at my previous workplace, I got a 1Password family account. It’s got my (not particularly technical) wife using unique strong passwords for all her online accounts and made family password sharing easy. I think the convenience of the cloud is key to this. I get that there’s a security risk that 1Password gets compromised and the app is infected with malware or there ends up being a vulnerability on their encryption scheme but it still feels like a net improvement to my overall online security. Also MFA can help mitigate the risks of the passwords being compromised.
- cbo100 4y ago> but it still feels like a net improvement to my overall online security. This is what I’m at on it too. Without cloud syncing convenience wins and we end up using simple passwords over and over again. With cloud syncing I believe we are much more secure than we would otherwise be.
- nine_k 4y agoBut you do not have the keys and passwords on that server. Only their encrypted forms. And the master password never leaves your machine(s), the sensitive bits are only decrypted locally. This is reasonably safe, as long as you're careful with your master password, no different form GPG.
- chank 4y agoI'd still rather not let anyone have the encrypted versions of my keys/passwords. If the software is compromised then it's reasonable to consider the encrypted data can be brute forced with some time. I'm not here to argue the merits of encryption. I understand it very well. I'm only considering my own levels of comfort and need to trust a 3rd party as well as pay a recurring fee to store my keys/passwords.
- nine_k 4y agoEncryption that can't be brute-forced within centuries, even with a quantum computer, exists for some time, and is not really expensive to apply, especially on such small scales as a password database.
- zmmmmm 4y agoI kind of agree with you, but on the other hand, they are storing everything you give them using strong cryptography. If you fundamentally don't trust cryptography then none of those passwords you are worried about are worth protecting in the first place. So I'm not sure it's logically consistent to say that such a service should / should never exist on that basis. Where I do think it resonates is fundamentally it's just a bad idea to centralize things like this. It may be a necessary to construct a commercial business around this, but centralising massive amounts of trust across unrelated entities into ANY party is just a fundamental compromise that shouldn't have to be made. We would all be better off with genuine decentralised infrastructure to make all this work. What does irritate me is that all these companies are full of "zero trust" marketing spiel but their products always actually end up coming back to placing 100% trust in them in the end.
- chank 4y agoIt's not the cryptography that I don't trust. It's the e2e implementation. I mean we wouldn't be having this conversation if it was just about the cryptography. Also, subscription fees are a turn off.