5 ms·
The secret key bothers me. A lot. Where do you store this mission critical piece of data? This is a value you cannot memorize (unless you are Rain Man) and it c
by FatActor 4y ago
The secret key bothers me. A lot. Where do you store this mission critical piece of data? This is a value you cannot memorize (unless you are Rain Man) and it can be used to gain access to your account. The whole point of a password manager was to avoid this kind of vulnerability. Gives me the willies. It's basically a return to post-it notes.
- FatActor 4y agoCan't edit so I'll reply to myself. Thanks, folks, I should have jsut RTFA'd I misunderstood secret key as a failsafe, it is not: https://support.1password.com/secret-key-security/ https://support.1password.com/secret-key-security/ I installed both LastPass and 1Password and they make my homegrown key storage system feel so awkward by comparison.
- FatActor 4y ago1pw really doesn't play nice with yubikeys. LP has no issues (i think it doesn't use WebAuth, which 1P does). 1P UI is nicer. LP is a bit clunky. Not being able to add notes/docs to 1P in the extension kinda stinks ... why can't they just open the vault like LP does. They seem to be very similar: they both crap all over login forms! I like the secret key thing now: it basically forces people to have big passwords. But I find it annoying because my passphrase is enormous to begin with, I don't want to have to fuss with managing another key. I think they are neck-and-neck from my security posture view.
- CharlesW 4y ago> Where do you store this mission critical piece of data? Some suggestions: https://blog.1password.com/where-to-store-your-emergency-kit/ https://blog.1password.com/where-to-store-your-emergency-kit...
- majikandy 4y agoLastpass
- devrand 4y agoBut you need both the master password _and_ the secret key. Even if you write it down on a post-it note, you now need a physical attack to access it on top of whatever attack you needed for the master password.
- deleted 4y ago[deleted]
- lynndotpy 4y agoYou need the secret key and password to gain access. The key is 38 characters long, which is certainly within the range of human memory, if you're inclined to memorize it.
- jiveturkey 4y agoit’s stored in icloud storage
- lxgr 4y agoIt used to bother me too, but I‘ve since come around: It‘s a strictly additional barrier to the passphrase. Bitwarden and LastPass don‘t use one, so if you are fine with that security level, you could publish it on your blog, GitHub profile, or Wikipedia talk page and would literally not be less secure than those two. It really only is defense in depth, but in a breach like this is where it could shine. A parallel brute force attack becomes infeasible if attackers need to also compromise cloud or local storage, or even trivially correlate semi-publicly but unstructuredly posted secret keys to accounts/vaults.