What do crypto & network pros think of lastpass, keepass, 1password, et al?
quora.com
quora.com
Would there be any additional security hazard from using last pass and it's plugins verses using a password manager that's not integrated into the browser?
The attack surface is larger than a standalone app; your browser is a popular (and historically ripe) target; your browser sees lots of untrusted input from third parties; you manipulate sensitive data with your browser.
I use one (actually three) but it's not a good solution for everybody (what is?). Mostly the pros/cons are obvious but two less obvious risks: * Beware the clipboard * Don't forget the vault passphrase...
I'm not sure that's what you mean by "beware the clipboard", but 1Password actually clears the clipboard some time after you copy a password to it. In my case, it doesn't really help since I'm also using a clipboard history through Quicksilver…
As for the passphrase, this can be a problem. I was planning on regularly sending my list of password to my close family but never got to it yet.
It's not that long ago that certain browsers would give up your clipboard to any site that asked for it.
IE: http://www.securiteam.com/windowsntfocus/5CP0C1F61O.html
Similar (attacks paste), for FF: http://www.digitaltrends.com/computing/firefox-clipboard-hac...
The best way to avoid losing the vault passphrase is to make it a strong, rememberable password and move the passwords within the vault to randomly generated character strings (where sites permit it, there are a frustratingly large number of sites where certain characters or lengths of passwords simply do not work). That way, you remember only one password.
The biggest issue I've encountered with over a year of daily use of a password manager is making sure you can access the password database file consistently. Having the file on Dropbox is no use if your Dropbox password can only be fetched from the password database! So, always always always keep a local copy somewhere just in case.
* I generate random passwords 12 characters long unique to every site and write them down on business card stock which I keep in a reasonably secure place. They fit in my wallet with my money for example.
* Usually I don't even need to carry them around. Since the plaintext password and login session cookie must be handled in the clear by the web browser anyway, I just use the browser's built-in password manager. Mobile devices remember credentials too. If your browser is pwned, your login session is pwned, Zeus has proven this.
* I use a separate web browser in a separate OS image for online banking and purchasing things online (anything involving money).
This system works adequately for me. Therefore, giving passwords to a third party appears to me to add an unnecessary risk.
I fully admit that my system is unusual (I work for a multi-factor authentication company) and many people may be better off with a password management service.
http://www.theregister.co.uk/2002/02/25/steve_gibson_invents...
Really? Why?
KeepassDroid is updated to read the 2.15 format.
https://market.android.com/details?id=com.android.keepass
What's in this version: Support for KeePass 2.15 database format changes.
UPDATED: April 11, 2011 CURRENT VERSION: 1.9.2