I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
I agree with you about the wider industry problem, but for your own personal use just start using a password manager. Just do it.
I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass.
I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.
If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that company and all the people that work for it would go down. I'd personally see this as more of a reason to trust 1Password over KeePass.
The primary argument is that the code is open and you can audit it, but in reality that doesn't really happen unless there is a real drive to do it (like we saw recently with TrueCrypt).
I trust/distrust both about the same amount. But 1Password has more resources behind it so they are doing more to try and secure the data within the encrypted store.
Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to get it expensed.
> this seems to be an area where it's really worth investing money in getting the more reliable solution.
You're stating that "Free as in Beer" == "Less Reliable" and the fact that something costs money implies with 100% accuracy that it is reliable. Neither of these are true. Arguing that I'm bringing up a strawman because I said "Free vs. Millions of Dollars" instead of "Free vs. $50" is beside the point.
And I never even came close to saying that "something costs money implies with 100% accuracy that it is reliable". You are once again making up words to put in my mouth.
The fact is, a lot of people still believe the "open source == more eyeballs" myth, even though that is a myth. Open source does not equate to reliability. And when it comes to software that requires this much trust, a company built around a product is more inherently trustworthy than open source, as the entire company is on the line with their product (and the livelihood of all their employees), whereas with the open source product only the reputation of the author(s) is at stake.
Please note that, once again, I am not saying this is a "100% accurate" indicator of reliability. There are many factors at play. One important factor would be whether the software in question has ever undergone a security audit. Another would be whether there's proper documentation on the encryption (i.e. 1Password's file format is completely documented, both so third party software can use it if need be, and so the security of the file format can be vetted). A third would be the involvement of anyone who is already previously known to be an expert in the field. Etc.
Edit: Come on guys, please stop drive-by downvoting. If you disagree, comment!
Edit: And hates being told they hate it. How meta. If you disagree, please leave a comment. Drive-by downvoting does not help anyone.
On the other hand, AgileBits (makers of 1Password) is a company, with actual money on the line (in addition to reputation) serving as an assurance that the product will not only continue to be developed, but will remain secure.
If KeePass screws up, some reputation is lost, people may switch to another product, and the developer(s) can just move on to working on other software if KeePass can't be salvaged. If AgileBits screws up, not only is reputation lost, but so are paying customers, depending on the severity the entire company might go belly-up (e.g. if 1Password is compromised heavily enough that it can't be trusted anymore), a lot of people are suddenly out of a job, etc. Basically, there's a lot more at stake for AgileBits, which makes it much easier to trust that not only are they going to do their job right, but they're also going to have processes in place to ensure a build never gets released externally that doesn't pass QA, etc.
And don't forget that as a paying customer of AgileBits, I can get support from them for any problem I might be having. Open source projects don't typically employ support personnel, and generally rely on the community to try and provide whatever support they can.
---
Ultimately, this comes down to the fact that this is a specialized class of software, where one breach can mean irreparable damage as the attacker now has access to your passwords for everything. For that kind of software, I really want the backing of a company, with a significant amount to lose, rather than just some unknown collection of open source developers.
Which is to say, for nearly any other class of software, I'm much more inclined to judge it based on its merits, and open source has a lot of advantages. But this isn't any other class of software.
I might be a strange case, but I just have this feeling "real" companies spend their $$$ on meetings in Bahamas and Ferraris, while FOSS/OSS would be more open to security audits/etc.
A company with money on the line can (also) easily be shut down or aquired. I imagine a FOSS/OSS team would be demanding more guarantees for the future of the project, while "in it for the money" companies would take the check and not give a damn if it was shut down the same day.
"Real" companies often seem to push releases/features (prematurely?) to attract new customers. That the new features pass review/QA doesn't necessarily mean they are implemented right (goto fail?). In addition FOSS/OSS have public bug trackers, I'd rather know there are x number of bugs labeled "security" in my os, than not beeing told at all.
Support can (should?) be where open source make money, there are lots of FOSS/OSS projects out there offering paid support/installations/sass.
And the unknown collection of open source developers _may_ be a much better collection of security specialists/coders than in the "real" company. As most of FOSS/OSS is done voluntarily you don't have to pay huge paychecks for top of the line expertise.
Bottom line, I trust Debian (& co) and Mozilla. I don't trust Microsoft, Apple and Google.
This is 100% biased as to what I think. I understand that this is a two sided issue, and fully understand people who think like you sketched out. I'm just not one of those people :P
They even have an export function to dump the passwords (unencrypted) into a plain text or CSV file, so you can easily migrate the data to a new manager if needed.
To add to this all syncing on 1Password is done using 3rd party vendors.
You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.
I can spend $40-80 and buy a bunch of 1Password license packages, or I can use KeePass and place the database in my Dropbox folder. Yes, 1Password has a more aesthetic interface, but otherwise it basically does the exact same thing.
Point being the sync is platform agnostic. The etcetera covers BT Sync.
Just keep a copy on a local computer with Dropbox if need be.
The sync folder is encrypted—is there some risk I'm not seeing?
For you, I would just keep a copy elsewhere (friends computer etc.) or just get an additional device (mobile or otherwise).
A brief visit to their website later and I remembered: 1Password doesn't have Linux support. It's a shame; it looks really nice and I don't mind paying for good software.
I checked the 1Password site and it seems like a bit of a bait and switch. Download links without any mention of a price or trial anywhere on the product pages until you create a vault and see a License link in the menus. Then $50+ and another $10 for the mobile app.
I'm sure it's worth it, but I'd much rather they spell out their pricing up front.
The only thing holding me back has been not having great mobile access (as far as I can tell) on Safari on iOS. Looks like iOS 8 will change that.
IMO it's not far off the equivalent of how tourist trap restaurants in Europe put out bread on the table (something provided for free in many restaurants) and then charge you if you touch any. FWIW, that's considered pretty slimy behaviour.
There's browser add-ons you can use to auto-populate your login details that work well for most login forms with mostly no or minimal configuration required. It can get a little annoying when the login form has a CAPTCHA or some other non-standard requirement, but generally all that means is a few extra clicks. When creating new account details, configurable (e.g. length, allowed characters, etc.) password generation is built in.
You can keep your encrypted data store file on a cloud service for syncing between devices, should you wish. Which brings me to the 1Password mobile apps, which allow you to take your details mobile.
Probably the greatest friction point I've encountered has been when I'm on a foreign computer that doesn't have any of my 1Password support tools installed on it. In this case I usually just pull out my phone, navigate to the login details I need and enter them manually. But I take this as a small price to pay for markedly greater peace of mind.
I really can't recommend using a password manager enough. If 1Password is not it for you, then use some other password manager. But just use one.
It's not my favorite manager by any dimension, except for portability... but portability is just killer for it.
Password managers only protect against certain kinds of attack. Many cloud services do not or can not properly encrypt their users' data, so having a strong password won't help in the event that your cloud provider's datacenter gets rooted.
And you can use stronger passwords (if the service permits), thus if they only lost the passwords datbased (assuming it's hashed) you are still safe.
Most providers don't erase disks properly. Takes too much time.
Logic. Win.
Of course there are limits to any measure of security, but 1password does a great job in helping people manage themselves.
Personally, it's helped me a lot in just keeping my various usernames/user accounts organized (I sign up for just about anything).
What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.
[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.
[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.
[0]: http://www.reddit.com/r/Bitcoin/comments/23sjle/chrome_exten....
[1]: http://www.reddit.com/r/Bitcoin/comments/1vrium/a_google_chr...
For Bitcoin hardware wallets like Trezor, IIRC they either do or will support BIP-70 "Payment Protocol" payment requests that are signed with an X.509 cert, allowing you to verify the request on the dongle's screen.
I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.
It'll basically push specialized requirements to the hardware dongle (ie deciding whether it's enough to confirm user registration/authorization with the touch of a buttom, or whether it needs to be with a 4 digit pin, or even with biometrics like voice or fingerprint or iris scan). The test device in the following presentation video only uses a button press to confirm user intent, but it could have arbitrary requirements, making the protocol usable for both trivial website logins to online banking to eventually perhaps even a replacement for defense department CACs.
Here's a good fairly in-depth video presentation of what the FIDO Alliance is working on (there are functional test devices, and a functional test branch of Chrome that works with them):
By day two of using 1Password I had 70 entries, and was blown away at how much peace of mind I had. There were seventy things I never needed to _worry_ about forgetting. It was like my brain was holding onto each of those and now I felt more able to just focus on working, it's insane how since I didn't know any better I waited years to finally try it.
Second thing I did, buy a copy for my cousin for his birthday! Hope he has a great year with more brainspace for ideas and less spent trying not to forget things :)
You didn't get screwed by a password manager, you got screwed by a bad backup policy..
Sorry to be pedantic - and I feel your pain for losing your data - but there you go..
It also _probably_ means having these online somewhere. You're relying on strong crypto (and a really good base password) to protect you here.
If there was key-logging software on your machine, you're pooched any way you slice it (since such malware can just snarf decrypted keystores out of memory anyhow). However, with LastPass you can use Google Authenticator or a Yubikey or similar to enforce second-factor logins, so that even if you have malware on your machine, there is a drastically-smaller window in which to attack you.
On the upside, you get phishing protection (LP won't fill passwords for sites that don't actually match the site that you've saved passwords against), password duplication detection and strength auditing, notifications of when your passwords may have been compromised by major breaches, secure transport of passwords to other people, and transparent synchronization across devices. It's quite good.
Personal infosec hasn't evolved quick enough to match the technology it depends on. Sure we're comfortable with 12 character, 3 month rotation passwords, but the average 'civilian'? Probably doesn't even have a passcode on their phone despite the massive personal security risk they're carrying around with them.
We need to educate and/or provide easier authentication.
(Most of mine are markedly longer.)
Though I'll admit to being a tad less aggressive on the rotation than I ought to be.
Other sites silently break if you use characters outside A-Za-z0-9. e.g. you set a password with } or @ in it, then can't log back in again.
Ebay wouldn't let me paste a password into the password field recently, I had to type it out, and the keepassx "autotype" feature was thwarted by their focus-altering javascript code on the form. I also think they silently dropped special characters - I know it took me 4 or 5 password reset emails to get the new stored pw to stick.
Paypal requires that you enter a credit card number to change the password, so rotating it is tricky if you don't have the card on hand. I'm undecided if this is good or bad, since this sort of 2 factor makes it harder for someone to hijack your account.
There are a lot of ways that sites try and make life hard if you are doing things the right way and using a pw manager. It feels like there's this big conspiracy driving us to use the same "Monkey123" password everywhere.
I use a password generator. My defaults are _long_. But the nice thing is that I can pass it most constraint rules reasonably readily to create a valid password if I need to fit another use-case.
I don't use Ebay, but that sounds particularly annoying. Conversation on G+ suggests that the copy/paste defeat is to combat copy/paste exploits elsewhere, though by that point you might as well declare game over anyhow.
I'm definitely _not_ using "Monkey123" everywhere. But a lot of sites get a perfectly cromulent password ... and a mailinator.com email address (also randomly generated). I never use the same tokens twice (mostly registration-required but no real utility / long-term state storage).
I had been slowly working on a system which would store pseudo-randomly generated salts and store one for each individual domain. It would detect which site I was entering my password into, take the relevant salt and digest it against the password I had entered - sending a stupidly long, digested passwords to the sites which would allow for it. The password itself would never leave my computer. Progress was slow, though, and other projects took priority.
With Mitro, I've done a similar thing by pseudo-randomly generating 64-character base64 strings to store as the passwords for my accounts.
If you're still interested in this type of system, PasswordMaker has been around for quite a while and does essentially the same thing:
Then whenever I change that file I backup the truecypt container to Spideroak so I'm not hosed if I my stick gets lost/broken/stolen.
As someone who consistently needs my passwords on the go, a password manager is really the best way to go.
The tricks I'm thinking of involve fooling the user into thinking a site is something it's not or guessing some sort of personal information. But with a separate application the former seems unlikely and the latter is stopped if you use a scheme such as diceware (https://en.wikipedia.org/wiki/Diceware). I understand that naive, theoretical musings on security are no match for experience, so how would you break that set up?
Not that I'm into this sort of thing, but I've had a few people attempt to co-opt me into criminal activity in the past so I wouldn't be at all surprised to read about such attacks.
Your comment is a really lame excuse for not using a password manager and is quite a bit of FUD; there is no technical solution to a social engineering attack, so it's a clever way out as an excuse to avoid doing something difficult. You are not the first person to try it on me. You also sound like you're making the case for social engineering control of their machine, at which point what does the password manager matter? You have physical. Game over.
I have this conversation regarding self-signed certificates and MD5 hashing as well. "But they don't authenticate," or "but MD5 is insecure!" Yep, I know. Do you understand the threat vector for my usage of either? You sure?
Just use one. Seriously.
https://help.agilebits.com/1Password3/forgot_password.html
I have my master password written on a piece of paper that is stored in a safe location, mostly so my wife can access my information if anything ever happened to me, but it also works as a backup if I ever forget my master password for some reason.