this post was submitted on 14 Aug 2024
583 points (96.5% liked)

Privacy

32482 readers
289 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

It is truly upsetting to see how few people use password managers. I have witnessed people who always use the same password (and even tell me what it is), people who try to login to accounts but constantly can't remember which credentials they used, people who store all of their passwords on a text file on their desktop, people who use a password manager but store the master password on Discord, entire tech sectors in companies locked to LastPass, and so much more. One person even told me they were upset that websites wouldn't tell you password requirements after you create your account, and so they screenshot the requirements every time so they could remember which characters to add to their reused password.

Use a password manager. Whatever solution you think you can come up with is most likely not secure. Computers store a lot of temporary files in places you might not even know how to check, so don't just stick it in a text file. Use a properly made password manager, such as Bitwarden or KeePassXC. They're not going to steal your passwords. Store your master password in a safe place or use a passphrase that you can remember. Even using your browser's password storage is better than nothing. Don't reuse passwords, use long randomly generated ones.

It's free, it's convenient, it takes a few minutes to set up, and its a massive boost in security. No needing to remember passwords. No needing to come up with new passwords. No manually typing passwords. I know I'm preaching to the choir, but if even one of you decides to use a password manager after this then it's an easy win.

Please, don't wait. If you aren't using a password manager right now, take a few minutes. You'll thank yourself later.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 5 points 4 months ago* (last edited 4 months ago) (2 children)

So many folks talking about which software they use, and how they sync it between devices etc.

You all know there are hardware password keepers right? They present to your devices as a usb and/or bluetooth keyboard and just type out the user/password that you select. They have browser plugins to ease the experience. Now your password is not even stored on the device you're using to perform your login and it will work on any modern device even without internet access.

Oh and no subscription fee to cover the costs of cloud infrastructure.

[–] [email protected] 2 points 4 months ago (2 children)

What happens if it gets lost stolen or broken?

[–] [email protected] 3 points 4 months ago

I save copies of the password database in several locations. I have to keep them synchronized manually but that's preferable to using commercial ones that take turns in getting their data breached.

[–] [email protected] 2 points 4 months ago* (last edited 4 months ago) (1 children)

That will vary from vendor to vendor. In the case of the one I like there are a few relevant things.

The password db is stored encrypted on the device. Accessing the passwords requires all of:

  • the device
  • a smartcard with a particular secret on it
  • the 4 digit hex pin to unlock the secret on said smartcard, which is what is used to decrypt the db

Three PIN failures and the smart card is invalidated.

That sort of covers "stolen" and "lost + recovered by a baddie". Your bad actor would need to have their hands on both physical pieces and guessed the 4 digit hex code in 3 tries.

As far as a user recovering from a lost or failed device or smart card goes, you can export the encrypted version of the db for backups, which I do to a thumb drive I keep in my document safe. I do the same with a backup smart card. So that and a backup device or purchasing a new one if yours fails or is lost/stolen.

In the super "just in case" move, I also keep a keepassdb on said thumb drive. In case my device fails and it's just not possible to get a new one. Kind of like keeping two cloud providers in case LastPass goes bankrupt or something.

[–] [email protected] 1 points 4 months ago (1 children)

Hyptothetically, couldnt an attacker clone the smart card and retry on the copies?
I would believe a salted and hashed 0-knowledge password vault is more secure than a US-company which could be forced to surrender private keys used for the encryption

[–] [email protected] 1 points 4 months ago* (last edited 4 months ago) (1 children)

How would any company, regardless of geography have the secret I generated? This is a stand alone hardware device. They seller is not involved at all once I've received my package.

Could a sophisticated/well resourced actor clone the smart card they stole or you lost? Sure, brute force attacks are brute force attacks. At least you'd know your device and card are stolen. Now you're in a race to reset your passwords before they finish making 500 clones of the smart card they stole.

Hypothetically I could blackmail someone at LastPass and have a backdoor is installed for me.

Someone could bust down my door while I have it connected and unlocked and just login to all my things. ¯\_(ツ)_/¯

[–] [email protected] 1 points 4 months ago (1 children)

You lost an arm. Remember to use the \ to escape the markdown ;)

I don't know much of smart cards and the whole hardware based authentication beyond knowing they exist at all so please take my questions for what they are.

I was thinking the encryption on those cards are done with a private key and a writer/reader by the manufacturer (like HID). So if the NSA busts down the door and demands the key you could technically decrypt it.
So if you generate your own private key that vector is obviously mitigated, assuming they are providing the tool with a non-reversible hashing process or a guide on how to generate the key so it wouldn't aid in the brure forces decryption.

Thank you for the info :)

[–] [email protected] 2 points 4 months ago* (last edited 4 months ago)

I saw the lack of arm and facepalmed but I was half asleep poo posting so got over it :p (fixed now!)

I've been using this device for ~5 years now, so my memory is a little hazy on it, but I'm pretty sure for the particular device I prefer (which is to say, I have nfc what the setup is for other vendors, which could be greatly superior) the AES-256 key used for encryption isn't generated until you setup your first card.

[–] [email protected] 2 points 4 months ago (1 children)

Curiously enough, I never heard of those. Do you happen to know good ones so I can further check?

[–] [email protected] 2 points 4 months ago (1 children)

I'm a pretty big fan of the mooltipass. They're sold out and between iterations right now, but a new one is expected soon. One of my coworkers is pretty into their OnlyKey.

[–] [email protected] 2 points 4 months ago

Mooltipass looks sick actually. I have my reservations regarding the ble part, but I would have to look into it more to understand it. Might get one to check around how well it works (once availability is there)