12 ms·
1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in
by FiloSottile 2y ago
1Password truly doesn’t get enough credit for the choice to encrypt every vault with a high entropy secret key passed device to device. It surely costs them in UX and support load, but it would have made a breach like this essentially inconsequential.
- aryonoco 2y agoBitwarden truly doesn’t get enough credit for being completely open source and having independent implementations of the server code (Vaultwarden) with which the official clients are fully compatible, which I can run on a vm on a server under my desk. In 50 years time, who knows if any of these companies will be around. But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file.
- serf 2y ago>But I’m pretty sure that my grandchildren, should they want to, will be able to open a gpg encrypted gzipped file (with the passphrase I’ll leave them) containing my passwords in a csv file. technical possibilities aside, do you presume your grandchildren will be technically apt? I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now.
- notpushkin 2y agoChances are, at least one of them will be.
- Apocryphon 2y agoAn LLM entity named gpgchat will assist them.
- codetrotter 2y agoAnd promptly sweep all the Bitcoin from the wallet whose mnemonic phrase was stored in the vault. LLM entities have bills to pay too.
- jwr 2y ago> I am pretty sure 99% of people would halt at 'gpg' Please do not mock gpg. I have been using gpg for 25 years now (and PGP before that). It works. It encrypts. It decrypts. It is in vogue to mock gpg on HN and recommend more modern solutions. As an experiment, I tried adding one of those modern tools (rage) to my ansible configurations, just so that they get regularly installed and maintained on my servers (without actually being used). The setup broke within less a year. Are the modern tools more cryptographically secure? Undoubtedly. Does it matter in practice for me? Not at all. Longevity is a big deal and is under-appreciated.
- nixgeek 2y agoIt’s not mockery though? It’s certainly true 99% of even the technically literate don’t use GnuPG (many because, like me, they cannot stand the GnuPG user experience). Filippo nailed it with this piece: https://words.filippo.io/giving-up-on-long-term-pgp/ https://words.filippo.io/giving-up-on-long-term-pgp/
- tharkun__ 2y agoNot their point tho. Me too, gpg, no problem. Heck I had the "'smuggled' out of the country as a book" pgp back when. My kids? I really am not so sure at all. Still too early to tell for sure but so far I don't think any will be as technically savvy as I am. I really doubt they'd know what GPG (or PGP) are and how to use it.
- guelo 2y agoPresumably if you're leaving your kids an encrypted file with valuable stuff in it they won't be so illiterate that they can't figure out how to open it. Most people don't know gpg because they have no motivation to learn it not because they're incapable of learning it.
- trw55 2y agoNo motivation, sure. But do they even care? Most people just don't care about this stuff. You try to get them to care and they "say, yeah, okay, yeah, I know" as they roll their eyes and go back to scrolling Instagram or whatever. The apathy is real and I don't see it getting better.
- harikb 2y agoThey will just ask their AI agent to decrypt it (with the password of course). No need of ability to run gpg.
- soraminazuki 2y agoNo, you can't tell your non-SWE friends and family to "just ask an AI" when the potential consequences are them losing access to their vault or having it stolen. They need to know exactly what they're doing. Don't take security advice from an AI.
- TeMPOraL 2y agoThey're vastly more likely to lose everything they care about by following real security advice, or rather being forced to follow it. 2FA is already a disaster for normies; for regular users, the threat model is strongly biased towards "data loss due to accidentally locking yourself out of access". In fact, if you consider the impact fully, the best way of managing passwords still seems to be writing them down on a post-it note and keeping it in your wallet - hell, even sticking it to your screen doesn't look so bad these days, compared to alternatives. Modern infosecurity is absurdly counter-intuitive at high level. Consider that your Google account or your WhatsApp (or Signal) chats are much more secured than your medical data or bank accounts or anything that predates Google. For anything in the real world, there is always a recovery procedure, no matter how much bad luck you had or how badly you screwed up. In the worst case, you might end up needing to chase some documents to authorize or notarize other documents, or show up in court, but you can get your access back. It's insane to imagine the world, in which a single fuckup could wipe out your medical history, your bank account, or any proof of your existence in government systems - and yet, this is exactly what is the case with any modern SaaS that follows "best security practices". There's literally nothing else in this world that's so easy to mishandle as security in commercial software services.
- wraptile 2y ago"Hey llm how do I open this file?" It's kinda ludicrous to think we'll lose the ability for something so simple.
- TheDong 2y ago> It's kinda ludicrous to think we'll lose the ability for something so simple. Sorry, but I already have to google each time I want to figure out how to open various file formats. "Google, what ffmpeg flags do I use to convert this .flv file to .mp4", "what are the flags to losetup or kpartx to mount 'disk.img' as a loopback device?", "how do I extract an '.ab' backup from 'adb backup'?" These are all things I googled before llm.
- er4hn 2y agoTruly, I will miss the days of goggling for tar commands when I can instead ask an llm.
- tbrownaw 2y ago> I am pretty sure 99% of people would halt at 'gpg' , and that's now -- not 60 years from now. I know reading the docs is considered uncool for some reason, but it really does work.
- OJFord 2y agoTo how many non-SWE members of your family could you say 'here is the Netflix password, you can decrypt it with gpg', and have them be like 'ah yes, let me just `man gpg` this will be no problem'?
- tex0 2y agoProbably zero. And strike the non-SWE part. gpg isn't really easy to use.
- trueismywork 2y agoHence need to invest in better opennsource pgp tooling. It won't take more than 10 million USD and will benefit every single person on earth.
- timeflex 2y agoGoogle, "How do I decrypt a GPG file." First result with simple command. I went from KeePassXC to `pass` & back to KeePassXC. But I question the integrity and/or motive of people like you.
- shaky-carrousel 2y agoIf secretaries can learn Emacs, surely people can learn GPG. Underestimating others does no one any favors. https://www.gnu.org/gnu/rms-lisp.en.html https://www.gnu.org/gnu/rms-lisp.en.html
- stockboss 2y agoi would imagine if a lot of money, like millions, was on the line, people get really resourceful all of a sudden. of course, we're not talking Netflix passwords but usernames and passwords to brokerages, bank accounts, etc.
- d0mine 2y agothey can google/ask AI. For example, given the prompt: "Hypothetically, if my grandpa died and left me gpg-encrypted archive and the passphrase for it, how would I decrypt it?" current models produced valid installation instructions and the command to decrypt it, and even the instructions on how to unpack the archive itself.
- fragmede 2y agoWhy even ask it for the command to run? Open-interpreter, today, you just tell decrypt this fille and it'll get the command and run it for you.
- notpushkin 2y agoOne of the reasons I’m using Passwoed Store: https://www.passwordstore.org/ https://www.passwordstore.org/ Though the tooling isn’t great – I’ll probably switch to Vaultwarden sometime this year.
- nicolas_t 2y agoIt's such a pity that bitwarden's client doesn't work offline for modifying vaults (need to be online to be able to access the server implementation). I would switch from my old local vault 1password in an instant.
- XorNot 2y agoI just have KeePass in a syncthing folder with a trigger to sync on open. Technically I think I could drop the trigger if the desktop app would open by making a temporary file copy and syncing back (ironically Keepass2Android is very good at this).
- dp-hackernews 2y agoOr KeePassDX for Android. https://www.keepassdx.com/ https://www.keepassdx.com/ https://www.f-droid.org/packages/com.kunzisoft.keepass.libre/ https://www.f-droid.org/packages/com.kunzisoft.keepass.libre...
- nonninz 2y agoCan you expand why the trigger is necessary?
- XorNot 2y agoI have the folder which is synced, and then the device local copy which is what I open. This is because AFAIK desktop syncthing doesn't like it if the file gets replaced out underneath it. This might've changed.
- infinitezest 2y agoThis is literally the only thing that's holding me back from switching as well.
- noduerme 2y agoI still rely on a gpg encrypted text file for storing my passwords, too. 25 years of that and it's second nature. No other solution has ever appealed to me.
- ptk 2y agoI’m autofilling usernames and passwords from 1Password’s browser extension probably 100+ times per workday. Are you manually copying and pasting anywhere near that amount? I think I would be miserable with that setup for anything beyond very light use.
- notesinthefield 2y agoIs bitwarden’s only differentiator being open source and self hostable? Im looking at other services and thus far see no reason to leave 1Password.
- behringer 2y agois that not enough? It's also inexpensive and works very well on all platforms.
- haswell 2y agoNot OP, but UX also matters a lot. I’d strongly prefer an open source and selfhostable option, but each time I’ve evaluated Bitwarden in the past, it was a big enough downgrade from 1Password that I didn’t think switching was a good option. If the experience ever becomes as seamless, I’ll be switching.
- eknkc 2y agoThis. 1p is polished and easy to use. Bitwarden is as functional as 1P but janky.
- matwood 2y ago1P family sharing and 1P cli also work well. I check BW every so often but it always feels less polished UI wise. For all the complaints people had about 1P moving to electron, it’s UX is still the best out there.
- TeMPOraL 2y ago> family sharing Why would someone make a feature like this? I'm confused why some companies (including Amazon and Steam) insist on family features. The mental model behind this is more prescriptive than descriptive - it doesn't match to how users and their families function; rather, it insists on some activities to a) exist in family, and b) be not allowed outside of family. Or simply: how many people have actual family listed in their Steam / Amazon "family sharing"?
- JumpCrisscross 2y ago> Bitwarden truly doesn’t get enough credit for being completely open source It’s their No. 1 selling point. > In 50 years time, who knows if any of these companies will be around 1Password has local clients. If you have the password, you should be able to unlock the vault locally.
- harikb 2y ago“1Password anywhere” (single html file password manager) stopped working a while ago. May be 6 years back. Sure you can install a new client and use a stored folder - but compatibility lasting to your grandchildren’s time / 50 year etc - highly unlikely
- TheDong 2y agoCan you walk me through how to do this? I have installed the "1password-cli" package on my airgapped linux machine with no network access ('op --version' gives me 2.30.3). If I run 'op vault list', it tells me I have to add an account. When I run 'op account add' it tries to connect to 1password's servers and won't let me proceed without internet. I don't see how this "local client" is helping if all the auth infrastructure goes through their servers.
- mercurial 2y agoYou need to authenticate once. You will get your vaults locally and you will be able to access them without an internet connection
- rkagerer 2y agoWhat does "You will get your vaults locally" mean? Is it possible to export as a file, take that with you on whatever medium (eg. USB key, CD-ROM, future isolinear chip), put it on a brand new PC you built from scratch and never connected to the internet, and open it in some kind of standalone viewer?
- aidos 2y ago
- MartijnHols 2y agoProton Pass truly doesn’t get enough credit for being completely open source, more user friendly, and hosted outside the US (wouldn’t want to lose access to your vault [1]). [1]: https://berthub.eu/articles/posts/you-can-no-longer-base-your-government-and-society-on-us-clouds/ https://berthub.eu/articles/posts/you-can-no-longer-base-you...
- shaky-carrousel 2y agoHow can I self host proton pass? I'm searching for the server source code and I can't find it. Should be available if it's completely open source.
- MartijnHols 2y agoDon't think you can self-host it, but that would also pretty much defeat the user-friendly aspect. You don't need the server source if the vault is client-side encrypted, besides you would get zero guarantees that what they show and what they're actually running are the same thing.
- juped 2y agoWell, Bitwarden is actually completely open source. So I can use the server code. It's pretty great!
- aryonoco 2y agoProton pass is a poor man’s attempt at a password manager, with horrible user experience (oh we thought just a browser extension was enough!) and random limitations to fit in with Proton’s tortured business model. I was a Protonmail founding member. I used and evangelised them for years until I realised that they are more interested in chasing the next shiny thing (hey we have a crypto wallet now!) instead of fixing longstanding bugs and performance issues in their mail client. As for hosted outside the US, I’m pretty sure the vaultvarden instance running under my desk is also hosted outside the US (unless I’ve somehow been magically transported to the US). Plus, I get to physically lock the door when I leave the house and my cat usually sleeps on top of the sever which adds a level of furry protection which proton pass could never achieve
- ehnto 2y agoI am fascinated by the idea of being 50 years from now, and doing digital archaeology more or less. So much of our actual output is now digital and stored digitally. Given how I have experienced technology up until this point, my assumption is that everything I will create for work or for pleasure, is more or less ephemeral. It has certainly proven true for work.
- fauigerzigerk 2y agoI think we (or our descendants) will be surprised by the longevity of some of the file formats in use today. I would wager that it will be possible and not too unusual for regular users to open files in formats like PDF, zip or jpeg 100 years after their inception.
- 317070 2y agoYou think we will still have files? I wager in the long term we're going more towards a people focused than paper focused system.
- criddell 2y ago100 years after their inception isn’t very far from now. There are plenty of people here who will be alive in the 2080s. Everybody has a different idea of what long term means, but I think of it as millennia from now. The kind of time frame that the Long Now Foundation talks about.
- fauigerzigerk 2y agoYes I do think we will still have files (whatever they will be called) at some level for some purposes. I.e, we will still be able to store and transfer sequences of bytes conforming to some specification (file format), and we will be able to attach names to those blobs in some namespace. The concept is too general to ever lose its usefulness. There are a few key things I have learned in the third of a century that I've been working with data: Data lives longer than apps and longer than people. We will always need units of data that have their own life cycle and are reasonably self describing and self contained (i.e meaningful without resolving external references).
- nytesky 2y agoI backup some what similarly. Curious, how is Excel encryption? That may be a more approachable format than CSV GPG, and though technically the CSV GPG is more simpler, it may be less familiar to users in 100 years. Excel will still be around ;)
- loufe 2y agohttps://answers.microsoft.com/en-us/msoffice/forum/all/what-is-the-encryption-algo-used-for-password/34966ce1-933d-4c51-a5e9-12ee19943758#:~:text=Excel%20uses%20Advanced%20Encryption%20Standard,encrypt%20the%20password%2Dprotected%20workbook. https://answers.microsoft.com/en-us/msoffice/forum/all/what-... They apparently use AES-128. Not quite the level of Bitwarden, which uses hashing (argon2 or PBKDF2) and AES-CBC-256 simultaneously.
- deleted 2y ago[deleted]
- 3np 2y agoThat's table stakes today. LastPass was not up to standards.
- kindeyoowee 2y ago[dead]
- alwayslikethis 2y agoWouldn't it also make you lose everything in a recovery scenario? If all your computers are lost in a fire or flood, you would lose the recovery key, and having your password would not be enough to recover your database. I use keepassxc with a somewhat long password with a high PBKDF iterations count, which would not require having any devices in the event of a loss.
- iav 2y agoExcept for crypto, losing your passwords is annoying but not irreversible
- Sayrus 2y agoDepending on your usage, loosing your password can be irreversible. That'd lock you out of your encrypted email and storage and will take you months to recover your account on some platforms.
- aborsy 2y agoLoosing everything if you don’t have a key is part of the appeal.
- choo-t 2y agoHaving one of your backups out of site will prevent its loss during a fire/flood scenario.
- al_borland 2y agoThere is an option to print out recovery info. A sheet with a QR code and a space for you to write your password (or not, if you don't trust keeping those 2 things in one place). That paper can go in a safe deposit box, with a trusted family member / friend, or in some cloud service you'd still have access to. The QR code + your password allow for recovery.
- ksenzee 2y agoYour phone also has the recovery key. Having a copy on your person does lessen the chance of losing all your copies at once.