3 ms·
Centralizing everyone’s credentials after all these years still seems like the most risky idea ever. The only thing possibly more attractive to a hacker would b
by sciens3_ 2y ago
Centralizing everyone’s credentials after all these years still seems like the most risky idea ever. The only thing possibly more attractive to a hacker would be free sex and drugs, but only for a little while, and then they’d go back to trying to steal everyone’s credentials.
Some other targets: everyone’s PII, info on friends, family, pets, answers to security questions, mobile IDs, PIN numbers, account numbers, signatures, photos, fingerprints, voice patterns, facial and retinal scans, gaits, DNA, mitochondrial RNA.
- n8m8 2y agoI have similar gripes, but I still feel like on balance, randomizing passwords across accounts is more important. Selfhost vaultwarden ftw (or not — don’t f*ck it up)
- sciens3_ 2y ago> Selfhost vaultwarden ftw (or not — don’t f*ck it up) Right. Randomizing passwords doesn’t require centralization.
- namaria 2y agoTruly the chain of decisions that got us here is baffling. "Use random high entropy passwords for each account" good "Store them encrypted" great "In a computer publicly available on the internet" wat "Under an account that also handles your 2fa tokens" c'mon now!
- commandersaki 2y agoIf you do e2ee correctly this is a non-issue. See 1Password for one way to do to it right.
- namaria 2y agohttps://www.bleepingcomputer.com/news/security/1password-discloses-security-incident-linked-to-okta-breach/ https://www.bleepingcomputer.com/news/security/1password-dis... https://www.forbes.com/sites/daveywinder/2023/12/11/android-warning-1password-dashlane-lastpass-and-others-can-leak-passwords/ https://www.forbes.com/sites/daveywinder/2023/12/11/android-... https://www.zdnet.com/article/hackers-stole-this-engineers-1password-database-could-it-happen-to-you/ https://www.zdnet.com/article/hackers-stole-this-engineers-1...
- commandersaki 2y agoHow is any of this a threat to 1Password E2EE? The point is if they even have access to my encrypted data, they wouldn't be able to access the plaintext without the key (and yes the passphrase is not sufficient). This is just lazy scaremongering.
- namaria 2y agoThe point you're trying to make is a trivial one: in the absence of errors, there are no problems. LastPass e2ee was never the problem in the original story either.
- commandersaki 2y agoYou are wrong, the article posted said the heists happened because of both a breach and cracking master passwords. LastPass E2EE relied on keys from the master password using a password hash that had a low iteration count. Therefore low entropy passphrases could easily be cracked. Furthermore not all data was encrypted. This is all a weakness of their E2EE. 1Password uses both PAKE for remote authentication and a high entropy key (128-bit) and therefore doesn't solely rely on a master password. There is an actual difference. Of those links you posted, two of them could've equally affected a password manager that was local. All password managers can be subverted by external threats whether using cloud storage or not. My point is, properly implemented E2EE (hopefully vetted by cryptographers) is marginally different to a password manager using local storage. Sure having it cloud hosted can affect more than one user, but attacking the ciphertext data would be infeasible.