Experts fear crooks are cracking keys stolen in LastPass breach
krebsonsecurity.com
krebsonsecurity.com
By default, third-party password managers are stupid. Before - two people had the secret, now three of them do, one of whom is a juicy central target that has the secrets.
I'm aware that this is an extreme oversimplification of e.g. hashes and whatnot, but it seems true enough for laypeople such that it's better advice than most, especially for individual and personal accounts.
It's not a case of 1st party or 3rd party for most users. Especially laypeople.
It's a case of 3rd party or none.
Most users are not going to piss around manually syncing KeePassXC or whatever.
3rd party makes it easy to use secure passwords. The alternative for laypeople is going back to what they do otherwise. Password re-use.
Yup, and ALSO makes it easy to SCREW UP. That's the point. This paternalistic garbage helps no one.
Right now, the smarter thing is to be like: "Look, passwords are hard. Security is hard, but individuals have to take responsibility" because entirely too many companies are bad at this.
There's also another simple solution, but no company is yet good enough to do this. Provide indemnity.
Being ignorant of convenience required and capability available of the target audience isn't going to help anyone.
Don't let perfect be the enemy of good.
A 3rd party password wallet from one of the majors is vastly more secure than someone's nan using the same password for everything. Which is the alternative in practice.
You seem to think that normal people are going to learn IT security to a reasonable degree, and be personally responsible.
Many people literally aren't capable of being what you want them to be.
Yours is a beautiful dream that clashes strongly with observable reality.
If people don't learn -- and maybe they won't, then, the only real solution is actual liability. These companies promise safety and don't deliver; time to sue or regulate or both.
But we need to stop pretending that "third-party," in all its present crappiness, is an acceptable option, even if sometimes it's better than what people do on their own.
No password manager sounds like an awful idea, who can memorize all their passwords?
How can I keep passwords on 2 computers, an iPhone and iPad all in sync?
If someone breaks into my home, they’ve got it. But that’s not a threat model that scales, so it’s not a major concern to me.
But people are often away from home and want to log into websites and apps from their smartphone. A physical password book sitting at home is useless for that very common scenario. That "login from anywhere" is the typical motivation of gp's comment: "How can I keep passwords on 2 computers, an iPhone and iPad all in sync?"
And again, to take it a level further -- I would absolutely use a company's software under one, and only one condition -- indemnity/warranty.
Any company that is willing to go "If you get breached, we will pay for the harm" can absolutely take my money.
Firstly, companies change logos, change names, force password resets or your password will leak in a breach. How does this system accommodate those scenarios?
Also, once a few of your passwords are in data breaches, anyone who wants to target you can derive your admittedly less complex formula.
It is not out of the question that there already is or will be technology to compare multiple passwords from the same person from different leaks and derive the formula.
It's true that's a hypothetical attack vector.
In practice, so few people use this approach that you're not going to see a general-purpose deployable attack suite based on this principle. It'd be useful for a targeted attack, but if you're under a persistent, targeted threat there are better tools (spear-phishing, social engineering, physical compromise, etc.).
I guess the only way that would work is if it was somehow connected to a large concensus network and could only be unlocked if connected requiring some sort of proof that can't be forged which in itself may be an issue.
Oh god I think I may have just given someone another idea for a crypto startup...
E.g. coinbase don't let you deposit from mixers (at least in large amounts), but they do let you deposit from okx, which in turn accepts deposits from sketchy chinese exchanges which accept deposits from mixers.
Alternatively, you can go via monero but that only replaces the first few steps in the ladder.
Thankfully I don't think any proposed regulation does much to stop this, short of entirely banning crypto, which I don't see happening any time soon.
The identity behind a wallet or account might be worthless. Years ago a common scam in Eastern Europe (maybe everywhere) was to pay old or homeless people a tiny fee to open bank accounts all over the city and then hand over the credentials to the criminals. Then they could operate a network of thousands of such accounts for various purposes, sometimes for reasons as simple as getting a small loan that doesn’t require any collateral and disappearing with the money.
This can work as long as they can move around the crypto in an obscure enough way so that it takes just hours or days longer for the authorities to trace than it takes for the criminals to cash out.
Or use something like changelly or a number of decentralized exchanges.
If you’re concerned Steve Gibson did a good rundown on the security now podcast
One of the most unfortunate things with the LastPass breach last year was that lots of accounts had the number of PBKDF2 iterations set to a low value (typically 1000). A low number of iterations makes brute forcing the master password easier.
This value would have been set when the user's account was created, and for older accounts it wouldn't have been increased unless users changed the setting manually.
LastPass is now setting it a lot higher by default, but that doesn't help the vaults leaked in the breach.
https://support.lastpass.com/s/document-item?language=en_US&...
The experience of one victim mentioned suggests it's economical to crack at least 50 bit entropy passwords for at most a $3.5 mil payout.
50 bits isn't great, but it's not terrible either.
(Edit: looked more in to how to calc password entropy. Luckily I'm good. Thanks a lot for this info tho.)
I use an alogrithm for swizzling a handful of passwords that fit in my brain. It's the best compromise I've found between using too few passwords and letting them ride around in a third party that could get compromised.