Based on the information we have, you must also change all the passwords that may reside in your OSX KeyChain or any browser password stores."
That sounds like a very large exercise...
Based on the information we have, you must also change all the passwords that may reside in your OSX KeyChain or any browser password stores."
That sounds like a very large exercise...
That is not to say that there are many good reason to do so, but the password manager do become a very coveted target.
edit: Maybe I phrased that badly. It is a risk associated with password managers that everyone that are using one should be aware of.
You'd need a way to change your certificate though (and keep it to the same account).
Some system through DNS? I think I'm just slowly reinventing OpenID
Then they can't silently gain access to your account persistently. They can gain access until you logout but then they have to wait for you to login again. Or they can change the key but then you'd notice that you can't login.
For this to really work, you need a way to detect compromise of the password. This way the 2nd factor holds you over until you've managed to rotate all important enough passwords.
Alternatively, separate trusted hardware with an interactive (i.e. challenge-response) protocol. Something like a TPM or yubikey.
Yes, we shouldn't have passwords for authentication at all, ever, period, and shouldn't have had them for at least a decade now. All the tech has long existed to switch to hardware backed public key cryptographic auth, and even to do so in a way that is far more user friendly then endless passwords and more secure at the same time, a sort of win-win that is quite unusual. We should all have HSMs (be it in the form of tokens, cards, compliant hardware in phones, or whatever) holding our private keys, and websites should only have our public certs. Entire classes of issues (like everything associated with password databases) would be perfectly and completely eliminated forever. There would be no dependence on any 3rd party services. Users would only need to remember at most a couple of PINs and that's it.
Back here on Earth though I can count every single site I've used in my life that had certificate based authentication and still have plenty of fingers left. Maybe U2F will make a bit more of a dent, but for a long time to come passwords will be the core of a lot of people's most critical personal security (like most of their money) and online identities. To have any value passwords need to be unique, and need to be fully random, and also have to deal with layers of extra crap that have been piled on top like password policies, arbitrary allowed characters (universal UTF? hahahaha), arbitrary minimum/maximum lengths, "security" questions (which should of course just be random strings lest they undermine the point of having a password but probably have their own special character restrictions), etc. Humans cannot remember all this garbage for more then a handful of sites. Password Managers are a practical solution to this mess of the "worst one except for all the other ones" variety. They effectively replicate (badly, but that's not their fault) some of what an actual decent key system would offer by default. They make attack scaling harder.
In short they're the best match to the most typical threat models most people face. Any good efforts to replace passwords period with keys is to be applauded, and if successful would eventually (years down the line) make password managers obsolete by making passwords themselves obsolete. But in the mean time password managers matter and people talking down at them due to issues that don't actually match general threat models are doing a terrible disservice to the public.
1. Use a password pattern. Something like 8 random digits that you memorize and then part of the domain name or business name. Such as "goo" for google. Put them in whatever order you like. Now you've memorized one pattern but use a unique password everywhere.
2. Use a predictable algorithm instead of a password. Their are web based services for this. You enter the domain name and then "encode" it to a password. That is typically not reversible.
These fall down some when you have to change a password or when a system has requirements that don't match your password (like requiring a number or symbol). Other users will mention other limitations as well.
Should be hard to crack and easy to remember.
Can anyone who actually knows this thing chime in?
There are 'stateless' password managers that work that way. It does not really protect against malware. If your user account is compromised by malware, what holds them from reading out your password and applying the same procedure to obtain password for interesting sites? You'll still be updating your password everywhere.
What you want is a second factor that uses a challenge-response mechanism with user interaction (e.g. U2F Yubikeys that require a finger press to start the challenge-response).
Even if they have plaintext password (which is often not case), this is just shasum. Feel free to guess which password (and which exactly scheme) I used to generate my password for news.ycombinator.com, if (of course it's now not like that :) it is:
bb05f766a74e6bf722136eaca97d9beb1fcc8f59d47c2d9e6eb1667d57c4cb82
You have now (after hacking whole hackernews db) access to my password ONLY for the hackersnews. Which was the original goal of the method: to use different passwords at different sites, which if compromised (password), do not reveal scheme used to generate it for different sites.
That's not the point. The malware would have access to your complete machine, possibly with root privileges, what holds them from reading your master password with a keylogger when you type it in?
It does not provide more security against trojans than a password manager.
I was replying solely and only to the acusation that after revealing plain text password on one site (which was generated using said scheme) you disclose every one.
This is simply not true.
In addition (but I didnt address that), there is no single keychain/password store to steal by the trojan. I can use it anywhere, using only my head as a 'storage' machine.
Or for desktop security. Pretty sure Wayland's current security model prevents this as long as the password manager has a well-designed API.
With OS X keychain(and browser) unfortunately, if your system is compromised, you can decrypt the password store.
Your browser's native store is probably unencrypted [1], and the OS X keychain password can be snatched with a clone of the native password prompt. Neither is true for any respected password manager. They keep you safe.
How would a respected password manager guard against an infected machine?
Take keepass as an example, they state: The actual problem here is running specialized spyware (as the same user and with the same rights, like KeeFarce assumes). If you are doing this, everything is over. An application cannot protect itself in such a case; all modern PC operating systems (Windows, Linux, ...) http://keepass.info/help/kb/sec_issues.html#keefarce
Also, at the bottom of the page: Neither KeePass nor any other password manager can magically run securely in a spyware-infected, insecure environment. Users still are responsible for the security of their PC.