Probably worth being careful with password choice if you're going to sign-up to this. Don't use one of your existing ones!
Other than that, I'm so glad to see Myst back!
Probably worth being careful with password choice if you're going to sign-up to this. Don't use one of your existing ones!
Other than that, I'm so glad to see Myst back!
Well you never should.
All of my accounts hooked to finance, or email, etc, are all unique strong passwords.
However, I have a throwaway password for throwaway sites, or sites I'm unsure of the security for.
Can anyone explain why using the same junk password for forums, crappy webgames, temporary reddit accounts, etc is a problem?
Why should I take up the brain-space to memorize a unique password for a site like this?
Steve Gibson uses it, I won't pretend to be as capable of speaking to it's benefits so I encourage you to listen to Security Now.
Edit: Last pass can be loaded once in the browser, and if you link it to a yubikey it is much more secure. http://blog.lastpass.com/2010/07/lastpass-gets-green-light-f....
The last person you should take security advice is from Steve Gibson. He's done an amazing job of making himself out to be a "security expert" but his understanding of security is ... exceedingly limited.
Read this post to see one example how he just, like, doesn't understand anything at all: https://www.grc.com/ssl/ev.htm
I don't like keeping lastpass with a master password because typing a strong, long master password every single time I want any password is not a use case I enjoy, and I certainly don't want to lock up my passwords with something that is easily defeatable.
And without a strong master password locking every attempt to use lastpass, it becomes far, far less secure than memorizing passwords.
You can also get 2 factor authentication (free with google authenticator on your smartphone, or slightly less free with yubikey and others). Thus, even if someone did somehow get/break your master password (unlikely), they still wouldn't be able to use it for anything.
Lastpass really is quite great.
Allowing your lastpass to "trust" your machine means ANYONE with physical access to your machine has access to 100% of every password you store there.
How is that not the same as writing down passwords on a sticky note and sticking them under my keyboard?
Small distinction, but there it is.
Also, with LastPass you are just trading risks. You increase the risk of your accounts being compromised by access to your computer, but you decrease your risk of accounts being compromised because HN password database was cracked. I use LastPass because I think that trade results in less overall risk, especially because it replaced saving my passwords in Chrome's less-secure password manager.
Memorizing a few unique passwords for mission critical services while using generic throwaways for low-priority sites is more secure than LastPass can ever be.
I started this thread asking if there was a better solution that memorizing 5-10 passwords and using some variable of a throwaway for the majority of everything else, and I'm still not convinced that my method isn't the best outside of just hard memorizing a unique password for every site.
Fact is: my memorized passwords can only be compromised where they are stored on servers (or through a keylogger).
LastPass can be compromised every single way that my memorized passwords can, in addition to being compromisable on any computer you use it on, and the LastPass services stores all of your passwords offsite, all of them, adding in another huge vector for attack against your entire catalog--- in a way that my memory can never be attacked (without say, interrogation/force).
I don't know, I don't like the idea of a digital store of all of my most critical information put behind a password that doesn't even pop-up on your computer. Mine as well just store all your passwords in Chrome. Same amount of security. Actually Chrome probably does better since it won't automatically push your passwords to the cloud unless you sync...
I started this thread asking if there was a better solution that memorizing
5-10 passwords and using some variable of a throwaway for the majority of
everything else, and I'm still not convinced that my method isn't the best
outside of just hard memorizing a unique password for every site.
When I was younger, I had only 5-10 important accounts and I memorized unique passwords that I thought were strong. Now I have many more important accounts, including four brokerage accounts, several bank accounts, half a dozen credit card accounts, two domain registrar accounts associated with tens of thousands of dollars worth of domains, etc. I have a separate computer that I only use to access these important accounts, and my passwords for these accounts are stored in KeePass, which allows me to have unique passwords with 200+ bits of entropy.I prefer my current setup more than my old setup.
Highly likely to be compromised, you mean? Viruses are a thing, and you can bet malware will target LastPass in order to get to finances.
Also consider linking to a yubikey. https://helpdesk.lastpass.com/security-options/multifactor-a...
EDIT: DO NOT FOR ANY REASON DO THIS >for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
I cannot respond directly to Munin but anyone who suggest that is going to lead you to this http://www.telegraph.co.uk/news/uknews/crime/10276460/David-...
Someone could get a hold of your wallet and take a pic of your passwords then put them back and you'd never know you'd been compromised. And Lastpass uses the trust no one mentality so you don't have to trust them. They never see your password it's encrypted using your password and yubikey if you have one.
https://www.schneier.com/blog/archives/2005/06/write_down_yo...
But, of course, don't write the password to an encrypted drive on a piece of paper that you keep with the drive.
Sure write them down if they don't matter, but don't write your bank account password down, or your google account. Especially if you have your ID in your wallet it'd be pretty easy to find you and get all your passwords if you lost your wallet. If you DO write them down, leave some portion of your password off.
I.E. your password is "password*&^&" only write down "password" and append the rest from memory.
http://www.theregister.co.uk/2001/06/25/steve_gibson_really_...
Then they could go to my computer and photograph my LastPass which, as this thread explains, is perfectly 'secure' to leave without a master password on 'trusted' machines.
Literally identical threat, IMO, being personally targeted for password theft.
If they can get my wallet, they can get to my desktop, I imagine.
assuming that every place you use a password is both competent and honest (which is a stretch), the only way for someone to get your passwords is to compromise your computer. if they do that, and you use lastpass, then they have all of your passwords.
for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
LastPass has made certain compromises in security to give you more functionality. For example, you can log into their website and enter your master password, to retrieve any other password. This is bad since the browser can be compromised.
However, I trust the browser and LastPass more than I trust my ability to keep the passwords secure. There is no way that I am going to remember the 300 or so passwords I have stored in LastPass and I will certainly not be able to change them as fast as I sometimes have to.
I am not saying that LastPass is the end-all-be-all of security, but compared to what 99.999% of people are doing, it is a huge win. IMHO, your statements are spreading FUD.
> assuming that every place you use a password is both competent and honest (which is a stretch), the only way for someone to get your passwords is to compromise your computer. if they do that, and you use lastpass, then they have all of your passwords.
That assumption has been proven time and again to be completely false. As someone who had their BTC stolen while using what would be considered a secure password, I can say that password cracking against a stolen database dump is not a theoretical threat.
> for this reason I recommend writing your passwords down on a piece of paper you keep in your wallet or purse.
This goes directly against your initial point that you don't know when your passwords have been compromised. You have no idea when someone takes a picture of your password sheet :)
Putting HTTPS insecurity aside, we really shouldn't be implementing crypto in JavaScript.
http://www.matasano.com/articles/javascript-cryptography/
KeePass is both native and open-source, so it avoids many of the problems that LastPass presents, IMHO. Simply install the client program and sync via SparkleShare, git, Dropbox, UbuntuOne, Google Drive, etc.
Plus that article attacks JS doing crypto that the server will decrypt (which, yes is useless, use TLS). It doesn't address using browser add-ons to do AES encryption, have your data stored on the server in encrypted form, and only decrypted when you download it again.
Is this method flawed? Only if you do a web-app instead of a browser add-on. Once you package the client code, it can be just as hard to break as something like KeePass (assuming the add-on itself has a decent security policy, ie don't eval()code from random places).
Plus, modern browsers now have "window.crypto" which provides a PRNG. So there goes that argument.
The article is just completely wrong in many ways. The only valid point I see it make is about garbage collection and potential for reading decrypted memory directly (MANY languages have this problem, not just JS).
One of the points you brought up is extremely valid though: LastPass is closed-source, so it's nearly impossible to truly validate the crypto. Keepass (I also use it) is a much better option, and great when paired with some sort of sync utility.
For this reason, if you lose your master password, LastPass can't unlock your passwords for you. You'll have to go to the NSA for that.
I was just thinking if my account is not publicly listed then I can just have a really complicated username and use a really simple password. (Complicated as in a SHA 2 or MD5 hash of your real name ). (Just thinking loud)
On the subject of red flags during signup, a password length restriction is always a red flag to me. If you're hashing my password, you don't care how long it is, right? If you limit length, I assume it's stored in plain text.