4 ms·
> [Password managers are] major centralized honeypots given the data they handle, and leaks are probably worth millions on the black market. My knowledge in th
by pyth0 4y ago
> [Password managers are] major centralized honeypots given the data they handle, and leaks are probably worth millions on the black market.
My knowledge in this area is admittedly limited but shouldn't password managers be fully encrypting your data with a key only you have (like 1Password). The way I understood it was that these leaks shouldn't be a problem because the data is worthless without the master key. Although I guess LastPass wasn't doing it that way.
- imiric 4y agoI was specifically talking about _online_ password managers in that quote. Even in the best case scenario that they do follow all best modern security practices for storing the data at rest, there are countless exploit opportunities while the data is in transit, especially considering the clients are web browsers, with their own security issues. Not to mention the vulnerability from rogue employees, social engineering, etc. Entrusting _any_ company with the secrets to your digital life is a bad idea in general. I know that 1Password is the darling in this space, but breaches are a matter of time. They only need to mess up once. Their entire business reputation relies on being 100% secure, which is impossible. I'm not surprised LastPass is reluctant to share more information; they want this to go away as soon as possible so that business can continue as usual. It also wouldn't suprise me if there were other breaches that were never made public, at LastPass, 1Password, or any of these companies.
- anyfoo 4y ago> I was specifically talking about _online_ password managers [...] considering the clients are web browsers Is that an actual thing?! I'm only familiar with password managers that use the Internet to synchronize, i.e. it's still 100% possible to apply the cryptography such that the service vendor or anyone else cannot read your passwords stored or in transit. I can maaaybe imagine password managers with a web interface that however still decrypts locally, client-side.
- imiric 4y agoTLS does a good job at this, and I'm not assuming it's compromised. But it's complex to setup correctly, and I'd rather avoid the need to transmit sensitive data everytime I access my credentials, and entrust my most critical information with a 3rd party, all to support a service that shouldn't exist to begin with. Password managers are currently a necessary evil, so if you must use them, use an offline one, and sync across devices via any other secure mechanism.
- anyfoo 4y ago> TLS does a good job at this, and I'm not assuming it's compromised. But it's complex to setup correctly TLS has nothing to do with it. TLS is transport security, which is relatively useless for preventing the service provider to access your data. I'm sorry to say this, but this is just word salad, including the "I'm not assuming it's compromised" bit. > and entrust my most critical information with a 3rd party The point is you don't need to do that, and can still sync over the Internet.