8 ms·
Right; but in the scenario of this Tweek, you've invited someone untrustworthy into the vault and are then freaking out because they can see the post-it note of
by Someone1234 5mo ago
Right; but in the scenario of this Tweek, you've invited someone untrustworthy into the vault and are then freaking out because they can see the post-it note of passwords. It is inherently irrational.
This issue is inherently unfixable by ANY password manager, because the process model of the underlying OS isn't itself secure. No obfuscation will work, because the password manager itself needs to de-obfuscation it before use (and that memory too is dump-able).
All adding in-memory obfuscation does it make ignorant people feel better, while not moving the security needle even an inch.
- ignoramous 5mo ago> This issue is inherently unfixable by ANY password manager, because the process model of the underlying OS isn't itself secure Usually the confidential bits are hardware isolated away from the supervisor (host kernel/OS) in Enclaves/TEEs, Realms, Secure Elements, Security chips, etc.
- jazzyjackson 5mo agoOne more reason to use hardware-bound passkeys and not passwords.
- Someone1234 5mo agoTrue. But then your hardware dies, and you're locked out of every account you own. It is objectively good security, but has a ton of usability headaches yet to be really solved. I've seen orgs move to passkeys only, then offer reset-questions (e.g. city of first job, etc); because the Customer Service volume/workflow wasn't figured out.
- jazzyjackson 5mo agooh lawd, yes it does come down to 'who has the power to reset your account', and very few people want to take the path of 'no one has the power' in the case of lost credentials.
- alterom 5mo ago>your hardware dies Or your backpack gets stolen. Oops. I swear, people who idolize passkey security must never travel anywhere. PS: "just have more devices with passkeys", they invariably say. Yeah right because people are made of money, everyone has the forethought, and a 2nd laptop in the US is a great asset when you're in Poland and can't login anywhere.
- StilesCrisis 5mo agoI've been avoiding passkeys but more and more websites are trying to push them, and one website I use now requires them. I've already got a password manager! I don't need to change everything again!
- stouset 5mo agoYour password manager almost certainly already has baked-in passkey support.
- StilesCrisis 5mo agoIt does, but what's your point? Why should I redo everything?
- stouset 5mo agoNobody is asking you to?
- crazygringo 5mo agoThe subject here is literally websites trying to push passkeys on users. That is who is asking us to. About every week now Amazon tries to trick me into creating a passkey. It doesn't even ask, it just goes ahead and triggers my browser passkey creation mechanism without my consent. PayPal recently tried to force me to create one too and I had to kill and restart the app because that was the only way to skip it. I'll stick to my password with 2FA, thanks.
- Barbing 5mo ago>It is objectively good security, but has a ton of usability headaches yet to be really solved. Thank you, then this is still true today? Disappointing the rollout was botched (recall cross platform and password manager difficulties). Haven’t done research since but even with some new UIs and flows promoting passkeys in the past couple months, haven’t regained my trust either.
- themaninthedark 5mo agoAt my work we required a complex password <15 characters lower + cap, number and symbols. Updated to Windows Hello and passkey. Now I can use a 4 digit pin to login.
- mjmas 5mo agoYes, but the pin uses the TPM which allows other things like only ever allowing a low number of guesses before requiring a reset of the pin (using a password or other mechanism)
- themaninthedark 5mo agoThanks, didn't know that!
- kenniskrag 5mo ago> But then your hardware dies A lot of services have password reset email features. If the email account has passkey you're screwed. But restore by snail mail can be possible but slow (for paid services). More secure? Don't know but same category of problems already known due to sim swapping attacks in mobile sector. But for sure the Mail account is a high value target. Storing passkeys in a database may be possible but complex to do it right e.g. backup verification, avoiding to leak while backup etc.
- kenniskrag 5mo agoEdit: Banking has no selfservice password reset. A lot of work for customer support due to identification. Nobody wants to do that for free and if the accounts are freenyou may get DOSed by bots which trigger passwort resets.
- oasisaimlessly 5mo agoNo, that is actually very rare, not typical. Do you have any examples of password managers that do that?
- stouset 5mo agoI think we’re largely in agreement. I do think there’s some benefit in reducing the amount of time that a password is in cleartext in memory. But it’s pretty far down the list.