6 ms·
You have secrets; we don’t. Why our data format is public
- dexen 14y agoAlso worth noting is the (linked) tongue-in-cheek http://blog.agilebits.com/2012/04/01/cipher-of-advanced-encryption-rotation-and-substitution/ http://blog.agilebits.com/2012/04/01/cipher-of-advanced-encr...
- hsshah 14y agoIn other words, Security through Obscurity does NOT work.
- kirubakaran 14y agoWhat password manager would you recommend for Linux? I use KeePassX but I wish I didn't have to copy-paste passwords onto website login forms.
- edanm 14y agoI'm wondering this also, only on OSX. I love Keepass on Windows, but the lack of auto-type on OSX is killing me. Bonus points for something which makes having a central repo of shared passwords possible, Keepass is terrible for this.
- alexjeffrey 14y agoI'm working on something like this at the moment, which will be released within the next few months. I can email you when it's ready if you're interested?
- edanm 14y agoSure, but to be completely honest, this is one of those things where I'm very unlikely to take a big chance on a new, untried software. At least, not for my business. For my personal use, sure. I'd like to see a helluva lot of proof that you're a legit company before trusting you with this kind of information. I say this not to discourage you, but just to explain how a business owner will think about your premise. Or at least me, don't know if this is representative of your actual audience or not. In any case let me know when it's up, I'd love to take a look!
- alexjeffrey 14y agoOf course, and these are problems I will be working to solve very early on. The kind of users I'm aiming for should be rightly concerned about the security of their passwords and I will be providing as many mechanisms as possible, both socially and technologically, to prove said security in a transparent way.
- InAnEmergency 14y agoLastPass?
- kirubakaran 14y agoI find it hard to trust a closed source app with all my passwords. Also: https://grepular.com/LastPass_Vulnerability_Exposes_Account_Details https://grepular.com/LastPass_Vulnerability_Exposes_Account_...
- martinced 14y agoNone. Zero. Zilch. Nada. Will people never learn? Do you realize what happens when your password manager itself gets compromised? Using a password manager is trading security for conveniency. This is simply not acceptable. I fully expect all the people using insecure security practice and all the people selling snake oil to downvote this. The problem, however, is that you can't argue with facts. And the fact is that trading security for conveniency is a very stupid thing to do.
- smilliken 14y agoWhat would you recommend instead? If you insist people remember all of their passwords in their head, you'll end up with them using the same password for everything.
- purephase 14y agoI think the most common is you have a single password, but you hash it with the name of the service you're logging into. For example, if you're password is "puppy" and you're signing-up for HN, your password would be: pHuApCpKy And, if you wanted to make it stronger, salt it with some special characters. p~Hu!Ap@Cp#Ky$ ... which is just the shift-characters on a number row in order. This way, you only have to remember one password, and it is service specific, and pretty strong. No password manager needed. Of course, I don't do this. I use a 1Password and KeepassX.
- GhotiFish 14y agoI like the idea of hashing off a root word + site. I'd rather have the browser do it for me though, and I don't think there's anything on the page itself that I could depend on to hash with. Maybe the domain? To be honest, firefox has an encrypted database of site-passwords. What's wrong with that?
- icebraining 14y agoI have a system like that, that takes a master and the domain. The advantages over the Firefox password manager is availability and not having to worry about backups. Since I know the algorithm, I can recreate any password using widely available tools.
- narcissus 14y agoI think Keepass2 requires Mono but if you're OK with installing that, then xdotools can be installed to autotype for you.
- gregdetre 14y agoI've been using 1Password for a few years now. I'm not qualified to comment on the security aspects of it - I'm trusting them and Apple to take care of that. But I can comment on the superb quality of the user-facing aspects - it's a pleasure to use, has great iPhone and Dropbox support, and I really like the way they communicate as a company.
- tlrobinson 14y ago“I won’t comment on the safety of this nuclear reactor, but it’s truly a beautiful nuclear reactor”
- sneak 14y agoI love and use 1Password, but bear in mind that passwords are all it encrypts: the rest of the account details, such as URL, are stored in plaintext for an attacker to harvest. :(
- kingnight 14y agoDo you have a reference for this? I ask because when you drag an attachment to a entry, it states: "The file has been added as a secure attachment." Leading me to believe it's encrypted (along with everything else in the entry...).
- nwh 14y ago~/Library/Application Support/1Password/1Password.agilekeychain/data/default/ Only the password itself is encrypted. Everything else is just sitting there in JSON. ~/Library/Application Support/1Password/1Password.agilekeychain/a/default/files The attached files do appear to be encrypted, but I don't know how well. The names of the files aren't however, and they may be enough to expose or incriminate you.
- kingnight 14y agoThanks for the paths. I've made some entries and checked what gets encrypted and seems some items in addition to the password are encrypted. I'm seeing the 'Username' and 'Note' fields for example, for Login items as encrypted. I found a summary[1] of why/what gets encrypted under "Individual Entry Contents". [1]: http://help.agilebits.com/1Password3/agile_keychain_design.html http://help.agilebits.com/1Password3/agile_keychain_design.h...
- guygurari 14y agoSee this discussion [1] for example where they say this explicitly. Passwords and logins and other sensitive details are encrypted, but item titles (including note titles) and URLs are not. They have a new keychain design [2] in which most metadata (including item titles) is encrypted. This is currently used for iCloud syncing, and they plan to roll it out for other sync methods and perhaps local storage as well [1]. I am guessing this will happen in the new OS X version. [1] http://discussions.agilebits.com/discussion/12237/metadata-is-not-encrypted http://discussions.agilebits.com/discussion/12237/metadata-i... [2] http://learn.agilebits.com/1Password4/Security/keychain-design.html http://learn.agilebits.com/1Password4/Security/keychain-desi...
- azio 14y agoSaid the company who didn't update their software for many months.
- deleted 14y ago[deleted]
- ntumlin 14y agoDo you keep the true crypt volume on your SD card too?
- derefr 14y agoI did answer that in the wall-of-text above: > Note that I don't have to worry about losing the cred files themselves, because I don't store them on me [on the SD card]; I only keep the keyfile [on the SD card]. You could keep a copy of the TrueCrypt volume there, but besides making the SD card more worthwhile as a theft target [they would only need it + your master password, not it + your master password + knowledge of and access to your Dropbox], it introduces versioning/sync difficulties when you add or change keys. You're almost unilaterally using these keys to speak to remote hosts anyway, so you're going to be online enough to get to your Dropbox whenever you need them.
- brini 14y agoDid you delete your comment? It may have diverged a bit from the topic, but I found your method more compelling than using a password managing service.
- jonknee 14y agoWith the format being open I really wish a Linux client would happen already.
- tlrobinson 14y agoWhat's the difference between: 1) entering your 1Password master password in untrusted software and 2) running untrusted software which could potentially keylog your 1Password master password? Agilebits likes to talk about how 1Password protects against keylogging (http://help.agilebits.com/1Password3/security.html http://help.agilebits.com/1Password3/security.html and note the author here http://mackeyloggerprotection.com/ http://mackeyloggerprotection.com/ ) but what's stopping attackers/malware from keylogging your master password and exfiltrating your 1Password database and master password?
- jpgoldberg 14y agoI'd really like to direct people to our discussion forums where questions like this our discussed. It's kind of hard to provide user support spread out over a range of sites. There are some counter measures in 1Password to try to thwart keyloggers. The details vary from OS. As far as we know, our defenses work against existing keyloggers, but we also know that this is an arms race that we can only lose. If your machine is compromised, then you can no longer trust anything on it. So while we believe that our current counter measures work against current threats, we can't state with much confidence that they will continue to do so. We've been fortunate in that keyloggers tend to be simple and go for the low hanging fruit. Cheers, -j
- makkes 14y agoClosed-source security software isn't worth very much in my eyes since you can never be sure that it does what the vendor says it does.