Maximizing password manager attack surface
palant.de
palant.de
Of course, serializing to HTML and parsing it out of the browser seems like a very bad idea. I suppose it was made this way because their neuronal network was written for HTML.
I wonder what made Kaspersky use a neuronal network to recognize password fields. It seems over-kill to me, but I may underestimate the complexity of properly handling password fields.
1. JavaScript is not a great language to build high speed low resource inference engines.
2. Sending user's HTML to your cloud to do so is a privacy, security and latency nightmare.
3. Regex matching doesn't get you anywhere near 95% field accuracy (not even talking about form accuracy, identifying all fields on a page correctly) on the web. You'd be amazed (or maybe not if you're a web dev) at the lack of consistency in field names - from machine generated field names to missing names to duplicate names... It's magical. Even to a human observer looking at a rendered page, it can be confusing which field is which. Just look at chrome try and fill a complicated address form out for you using a saved persona.
4. Even if achieved in JavaScript, the model would be simple to pull out and reuse elsewhere, possibly to learn how to game it.
5. Good models will be built by good data scientists, whose favorite tools likely don't produce models that can be serialized for use in a JavaScript inference engine.
This comes down to the approach taken here - put the inference in the code where it runs (and that was likely the same that trained the model) and interface with the page via extension to ship it there and back. It's local so it never leaves the machine.
It's very high stakes to take user controlled HTML into unsafe memory. Large surface area doesn't automatically mean an insecure implementation.
> JavaScript is not a great language to build high speed low resource inference engines.
This is a browser plugin analyzing html downloaded at human browsing speed. I doubt performance is a primary requirement.
> Even if achieved in JavaScript, the model would be simple to pull out and reuse elsewhere, possibly to learn how to game it.
The binary model is obfuscated but still distributed. I expect that the added difficulty of working with the binary model is small compared to the overall challenge of gaming it.
> Good models will be built by good data scientists, whose favorite tools likely don't produce models that can be serialized for use in a JavaScript inference engine.
Models built in research-optimized environments can be translated after the fact to match production needs. (It is getting easier with e.g. standard interchange formats for neural models.). Kapersky is a resource-rich org working on security software -- exactly the folks whom, if diligent and well intentioned, should invest in such hardening.
I'd be really glad if there was a viable method to do this without murdering the end user device.
I mean, we all make mistakes, but the kind of bugs that have been found in various AV products are so obviously stupid one can easily get a concussion from face-palming. If I were to roll my own crypto, there are all kinds of subtle mistakes that I could, nay: would, make that I might not even understand if someone explained them to me very patiently. Like, redirecting system calls from a "sandboxed" process, but then executing them as SYSTEM? How can I trust a company that allows such dumb mistakes in their code to build software that is supposed to make a system more secure? It is like finding out that the surgeon who is supposed to operate on you lacks basic knowledge of human anatomy.
I don't. AV software is virtually impossible to vet for a customer; it is the literal stone to keep tigers away (do you see any? It must therefore work). So 100 % of selling AV software is marketing, not functionality.
"Independent tests", e.g. how much slower the computer is made by AV software disfavour solid design: All else being equal an AV software where the signature engine runs directly in the kernel code intercepting FS calls will always be faster than the properly designed software were the signature engine runs at lower privileges (requiring task switching), and the FS filter driver has to delegate.
Tests where well-known malware is fed into engines and the red flag comes up are also pretty meaningless; signature scanning works, that's not the problem of the product.
The problem of the product is that the only things a customer can measure disfavour good execution of it and that signature detection is fundamentally inept in countering relevant attacks and therefore no real protection. Heuristics (or ML or whatever) doesn't really work well, either.
Oh, do we know whether it's really just a simple passwordmanager, and not also some autofill-manager, session-restorer, or other security/comfort-snakeoil?
I use the Chrome password store. Copying passwords over clipboard seems quite unsafe to me. And I have to trust my browser with my passwords anyway, even if I use no password manager at all.
Of course, if you (really) control all software running on your machine, the clipboard is no issue. But I'm lazy and don't have the time to read all source code and compile everything myself.
The downside is that I've considered changing to Firefox as my primary browser a couple of times, but the passwords make switching harder.
I think that's an area between "we store your passwords on our server" and "this file I store has all my passwords". No?
How it should have been done: stay in the JavaScript sandbox for all the logic, rely on the browser's existing functionality, use an absolutely minimal communication interface to the application.
But a masterpassword for offline storage is a completely different story, because even if the world knew your masterpassword, they still couldn't do anything with it, because they need to get to your dropbox file first.
If you use similar passwords everywhere, any site can read your password and use it to login somewhere else... You are supposed to use long random passwords for websites because you have to assume that every single password gets compromised and the website you are on tries to hack all other accounts.
* Assuming your dropbox doesn't have every-login 2FA, you're missing on that. Relying on the master passphrase (notice I didn't say password) alone for anything is a bad idea imo. But I'll give you the option here of saying "yes, my dropbox has 2FA". In your case you have a dropbox password AND a master pass to remember. That's 2:1 right there.
* Next we have that your encrypted excel is zip encrypted last I looked - I could be wrong - but I at least thought that Office encryption was just them using zip. So that's vulnerable to an offline attack if someone has your file. Symmetric 256bit AES encryption (again, iirc) so it really doesn't matter how good your password is if 256bit AES isn't good enough for you. Compare this to an offline blob from something like LastPass that uses much stronger 1024 or 2048bit asymmetric encryption.
* Next, we have that your excel file when opened on some foreign computer is maybe going to sit in the %temp% folder until it's cleared. The entire thing will be clear-text in ram at once no doubt. Compared to you accessing LastPass or similar from a browser that's designed to clear itself after logging off and only one password is in RAM at at time (supposed to be anyhow).
* Small things like immediate access, organization, accessing on your phone... All areas that password managers will win no doubt.
* Almost done, but using a password manager will let you do things like "detect password change" on a site you're accessing and update that password automatically. It'll let you sign in to sights for the first time and auto-create a new entry. This goes a LONG way into keeping an updated and current list.
* Finally, in terms of just general security... I can open my pass manager and access a password without copy and paste, and without anyone standing over my shoulder seeing it, I can share to a non-secure friend or co-worker in a way that at least encourages good behavior and when I update it they get the new pass without me informing them. With an excel file you can reliably do none of those things.
That's not to say someone couldn't do it better than a pass manager. Just that I lead with my point. My Mom has a more secure setup than many tech people because she wasn't allowed to make any errors.
On the LP FF or LP Chrome it's only listening to that program. On desktop it's trying to listen to all browsers at the same time and watching for other apps it recognizes.
It would make sense if LP Desktop had a broader attack surface.
OnePassword on the other hand, highly encourages people to download the binary because their standard extension connects to it.
Also, this thread seems to imply that having a binary component is always bad. It can also increase security. If the extension is rate-limited in retrieving passwords from a vault, then a compromised browser can only extract a limited number of passwords, whereas with a browser-native extension the attacker could extract all passwords.
Not that I'm a big fan of LastPass in general, published a number of article on their issues already: https://palant.de/category/lastpass/