Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
Now, given the general ignorance on infosec I'm suprised that people actually refused to pay to upload their passwords. The world has some hope after all.
by that logic, every time you send a password over a TLS connection, you're publishing it outright too
But even if they do all that, they still have to break my password. Nobody is going through all that for a one user password manager.
I'm not sure where your sentiment comes from here.
A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me. I much prefer 1Password's approach where they have a usually-hidden second secret (the "Secret Key") that both (A) isn't shown unless you're setting up another device, and (B) acts as extra data needed to form the decryption key for your vault.
The main threat model I'm thinking of protecting against is a 1password vault data breach of some kind (or possibly cooperation with government agencies) + password exposure in some way (be it from CCTV-extracted password entries, over-the-shoulder watching, etc), as even with both of those factors, they would somehow need to get your secret key to decrypt vaults.
Like, all of those lastpass vaults obtained during the Lastpass hack would be de-facto useless even with a correct password if their design included some sort of hidden secret secret.
AFAIK, 2fa is just another step before a server - executing code as it was intended - will return vault data to you. It doesn't protect against vault disclosure aka ransomware / data breach, similar to the Lastpass breach.
As for yubikey to authenticate into a vault, I'm not sure if it's something that actually strengthens the knowledge required to get into a vault (assuming you have the vault data yourself). Like, is it actually another secret required to decrypt the vault data? Or is it just another step the server verifies before it grants you access to download the vault data (and then decrypt client-side)?
> A PW manager relying on only a single password as the encryption key - and one that you type in frequently, mind you - has always been a little of a design issue to me.
Yes, I meant 2FA via FIDO2. It strengthens up the entrance to your vault. No key? No entry.