8 ms·
Passwords, Backups and a false sense of security
- Tichy 14y agoWhat about the password manager of Firefox? It seems to be better at remembering passwords from signup, so the only missing ingredient seems to be generating a random password upon signup.
- bluespice 14y agoAn Apple fanboy looses a couple of photos and the whole Internet cries. There are people out there who don't hand over the keys to their lives to a single corporation, and know how to manage their passwords and onsite/offsite backups. Please people, this isn't a crisis. Last months Apple hipsters found out what viruses are and know they are starting to pay attention to passwords. Catching up slowly eh?
- apawloski 14y agoAlright, so ignoring your (poorly executed) trolling, this actually is an important issue. Whether or not you approve, a lot of people use products that leave them vulnerable to situations like the one described in the other post. What's your objection to posts describing safer operating procedures?
- larrys 14y agoInstead of the program suggested in the OP, on the command line you can also do this to generate random passwords: perl -le'print map { (a..z,a..z,0..9,"\$","!","-")[rand 65] } 0..pop' 7 Note this particular one only generates 7 digits with no UC. You can alter it to your taste or needs. You can also wrap it in a shell script to generate a bunch in a row (in this case 10), like this: for i in {1..10} do perl -le'print map { (a..z,a..z,0..9,"\$","!","-")[rand 65] } 0..pop' 20 done As an aside I don't like any web based site that generates passwords (nor do you need that as just shown) since there is no way to know if the passwords generated are being logged along with some identifying information.
- DavidSJ 14y agorand() is not cryptographically secure. You should not rely on it in security-sensitive situations. http://perldoc.perl.org/functions/rand.html http://perldoc.perl.org/functions/rand.html
- larrys 14y agoAgree but as I said it also "only generates 7 digits with no UC" which is even worse. My point is simply that you can do this by the command line. And depending on what the purpose of the password is (and how difficult you want it to be) in many cases it fits the purpose. If I was generating initial passwords for someone's email account for example I probably would also leave out digits and letters that are easily confused, like 0 and O and l and 1 and some other things which isn't a best practice either but might be appropriate for other reasons.
- rane 14y agoCan you give a practical example how this can become a problem if I use rand() to generate a password to be used on a website?
- barrkel 14y agoMany PRNGs only have 32 bits of state. If someone knows your settings (alphabet chosen and length) the max number of passwords to check is 4 billion.
- larrys 14y agoYou might also want to try "Super Duper" which allows you to clone an entire Mac disk very easily. You can then test the backup by booting from the disk. It's also helpful when installing a new OS. Clone your existing disk, install the new OS on the clone (or on the original knowing you have an exact clone if anything goes wrong).
- sxcurry 14y agoA second on Super Duper - I do this at least once a month to have a completely cloned system on an external USB Drive. Equally important - take the USB drive off site! I plan to buy a 1TB drive every six months so that I can take a complete clone to my cabin, just in case of a disastrous fire at my house. That's in addition to Time Machine, Dropbox, etc.
- peterwwillis 14y agoGenerating hard passwords is actually kind of pointless. Yes, a hard password means it's difficult to brute force the authentication or crack a password hash you've stolen. But if you just use unique passwords for each service you use, it multiplies the work required to crack all the accounts. The biggest risk to your accounts and your data is simply having everything in one basket. The other biggest risk is saving passwords, but nobody wants to memorize a bunch of difficult passwords. So it's actually easier to have a whole bunch of kinda similar easy-to-remember passwords, so you don't have to save them. See, if you use Windows, chances are you've had some malware before. And if you've had malware, everything you type, everything you've seen or stored, including live browsing sessions, are controlled by somebody else. So doesn't really matter what your password is or how many you have if somebody's on your PC extracting your password database. But nobody wants to think about that. So they craft themselves a false sense of security, using password generators and copying files to the ends of the earth. Truth is, if someone wanted to, they could probably ruin your day. The only safe backup is an offline backup, and the only safe password is one that's never saved anywhere.
- maxerickson 14y agoThe whole point of a password manager is that it is convenient. Sure, the database may be exposed to malware, but that applies to any password that gets used, so the additional risk is pretty small.
- peterwwillis 14y agoNo, the additional risk is enormous. If they get your password database they get all of your passwords. If you don't use a password database, they only get the passwords you use, which (unless you sign into everything every day) should not be all of your passwords.
- maxerickson 14y agoI would expect the malware to sit there quietly until it collected at least a few interesting passwords. So it sort of depends on what the attacker is trying to do and how many interesting accounts the attacked has.
- sdizdar 14y agoI don't think generating more complex passwords will completely solve the problem. The problem is using only one cloud service for your data. Basically, don't put all your eggs in one basket. I always recommend to replicate all your data and files to other cloud service which has different security characteristics. For example, if you use Google Docs and Evernote - replicate everything to a separate Dropbox or Google Drive account (using cloudHQ or some other system). Doing offline backup manually is also a solution but it is easier just to replicate everything to a separate Dropbox account and Dropbox will put everything to your PC - you can map that Dropbox account to an external drive.
- mapgrep 14y agoI'm a little disappointed how this article and many of the comments here ignore the specifics of what actually happened. Yes "use different passwords" and "use a password manager" are good general advice. But this blog post expressly uses a specific case - the Honan hack - as a case study, without highlighting the one major lesson from that case. The actual problem most strongly highlighted by the Honan case is that your Gmail account is only as strong as the "backup email address" it is tied to. Honan's problem has nothing to do with using the same password -- he /had/ different passwords which you know if you read his post carefully. Problem is, his iCloud email was his Gmail backup email, and Gmail apparently allows arbitrary persons to instantly take over an account as long as they control the backup email. No waiting period, no warning email to the Gmail account, no SMS notification. Yes this can be fixed with two-factor auth (apparently) but by default that is off and by default Google badgers you about setting up a backup email address until you do so. By default Google does not badger you about two-factor auth. The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number. If you think about it, it's a little insane that you can protect your Gmail with two-factor auth but you can't protect your laptop the same way. Maybe a password manager would have encouraged Honan to use a stronger iCloud password, and maybe a stronger iCloud password would have prevented this attack, but that's not established because we don't know how the attack was pulled off. It was a seven char alphanumeric password and the attacker specifically told Honan it was not a brute force attack.
- spqr 14y agoYou are right. This is a critical issue with Gmail. I removed the backup email address in my account a few months ago when I realized this. I also turned on 2fa which works unbelievably well.
- bigiain 14y ago"The other big issue highlighted by the Honan case is that it is way too easy for bad guys to wipe your Apple devices. In retrospect, it really seems like there should be more between having your laptop, phone, and tablet wiped than a single password. At the very least, a security question, but ideally something like a credit card number (compared against a stored hash), confirmation SMS to a pre-registered backup phone (spouse's phone, friend's phone, relative's phone, etc) or a confirmation robo-call to a work phone number." That depends a lot on what kind of threats you're trying to protect yourself against. I suspect there's a lot of people for whom the correct response to a misplaced phone/laptop is "remote wipe immediately - if it turns up in the back seat of my car I'll just restore from backup - if was left in a plane/taxi/competitors-office/deacon I want everything o. It wiped _right now_!" I bet if pg lost a laptop with emails/documents about current and prospective YC deals or exits, he'd rather not have to wait till a office hours robo-call gave him a remote-wipe-PIN. It didn't work out for @mat, but I think "good backups and easy remote wipe" is a better default than "making remote wipe harder just in case your backups don't exist."