Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #194150 > unrolled thread
| Started by | rhkramer@gmail.com |
|---|---|
| First post | 2018-03-25 18:00 +0200 |
| Last post | 2018-03-26 04:00 +0200 |
| Articles | 20 on this page of 52 — 19 participants |
Back to article view | Back to linux.debian.user
Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-25 18:00 +0200
Re: Password Manager opinions and recommendations likcoras <likcoras@riseup.net> - 2018-03-25 18:40 +0200
Re: Password Manager opinions and recommendations Ben Finney <bignose@debian.org> - 2018-03-26 00:10 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 19:50 +0200
Re: Password Manager opinions and recommendations Roberto C. Sánchez <roberto@debian.org> - 2018-03-25 20:10 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 20:50 +0200
Re: Password Manager opinions and recommendations Ángel <debian-user@debian.16bits.net> - 2018-03-25 23:20 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 21:40 +0200
Re: Password Manager opinions and recommendations Mark Fletcher <mark27q1@gmail.com> - 2018-03-27 04:50 +0200
Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-26 02:40 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 04:00 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 22:00 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 23:40 +0200
Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:10 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 15:00 +0200
Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 03:10 +0200
Re: Update: Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-27 03:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Kushal Kumaran <kushal@locationd.net> - 2018-03-27 07:00 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:00 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-27 13:20 +0200
Re: Update: Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-28 04:30 +0200
Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-28 12:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Tomaž Šolc <tomaz.solc@tablix.org> - 2018-03-30 14:00 +0200
Re: Update: Re: Password Manager opinions and recommendations Curt <curty@free.fr> - 2018-03-30 14:50 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:10 +0200
Re: Update: Re: Password Manager opinions and recommendations Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-31 01:00 +0200
Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:00 +0200
Re: Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-30 16:20 +0200
Re: Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 20:20 +0200
Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 10:50 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 15:20 +0200
Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 21:00 +0200
Re: Password Manager opinions and recommendations Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2018-03-31 03:50 +0200
Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 15:10 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) <tomas@tuxteam.de> - 2018-04-02 15:20 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 20:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Roberto C. Sánchez <roberto@debian.org> - 2018-04-02 15:30 +0200
Re: Chaniging focus: security ouitside a password manager likcoras <likcoras@riseup.net> - 2018-04-02 16:00 +0200
Re: Chaniging focus: security ouitside a password manager Ben Finney <bignose@debian.org> - 2018-04-03 01:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) "der.hans" <deb-user@LuftHans.com> - 2018-04-03 02:10 +0200
Re: Chaniging focus: security ouitside a password manager Richard Hector <richard@walnut.gen.nz> - 2018-04-03 08:00 +0200
Re: Chaniging focus: security ouitside a password manager rhkramer@gmail.com - 2018-04-03 13:50 +0200
Re: Chaniging focus: security ouitside a password manager Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-04-03 18:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 11:40 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 21:10 +0200
Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 03:40 +0200
Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 04:20 +0200
Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 05:10 +0200
Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 04:00 +0200
Page 1 of 3 [1] 2 3 Next page →
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-25 18:00 +0200 |
| Subject | Password Manager opinions and recommendations |
| Message-ID | <vxgdP-5Um-11@gated-at.bofh.it> |
I started reading up on password managers in order to consider using one.
Up until now, I've made up passwords myself, and stored them in an encrypted
file. Some of the drawbacks include:
* I keep the passwords on the short side
* I don't change the passwords as often as I should
* I sometimes use the same password on more than one site
All of the above because it is not convenient enough for me to do better.
My head is just not "into" reading about password managers--it just seems to
be too boring to really get into, so, I thought I'd try posting here to get
opinions and recommendations from the list. (I am continuing my effort to
read--maybe I'll get a renewed burst of enthusiasm after I send this ;-)
Here are some of what I think are my criteria for a password manager:
* encrypted storage on my own machines (no storage "in the cloud")
* ability to transfer to other devices, including Android tablets and
phones--either all the passwords or just one for some special logon on a
machine I don't normally use. Currently I do almost everything (that requires
a password) on one of my desktop computers. I have a laptop that I use very
occasionally. Occasionally I've had to go to a library (or similar) to use a
Windows machine. I do have an Android tablet and phone, and, in general, I
don't use that for confidential type stuff (no banking, for example), but that
could change if either I feel very secure or in some sort of extreme
emergency.
* (a repeat of part of the previous bullet) a means to easily take an
individual password to another machine for occasional use of another machine
* a means to recover all the passwords if the password manager becomes
defunct (and this also implies backup and restore capabilities)
* a means to automatically generate secure passwords
* a means to automatically update passwords on the target websites (to
facilitate regular / frequent password changes)--this is probably a stretch--I
mean something that would work its way through the various screens and prompts
to change a password with a minimum of manual intervention by me
As an alternative to a password manager, I may create my own memorizable
password generator "algorithm" that I can mostly use "in my head". For
instance, it could be something like this:
* think up a multiword phrase, possibly with a mnemonic connection to the
target website (or, have a means to extract them from a book, e.g., the 3rd
sentence of the 5th chapter of War and Peace--or maybe the first sentence in
the book that contains the word bank would become the passphrase for my bank).
* have a consistent substitution algorithm, which might do things like
this:
* capitalize the nth letter of each word (or the nth letter of the first
word, the (n+1)th letter of the 2nd word, ...
* substitute (or insert) a punctuation mark for (like above) the mth
letter of each word (or the mth letter of the first word, the (m+1)th letter of
the 2nd word, ... --the puntuation might be selected in, for example, keyboard
order (or reverse keyboard order) across the numeric keys (e.g., !@#$%^&*()
(although maybe some of those might be invalid in (some?) passwords)
* some other similar generation rules
Obviously, having "published" these ideas, my actual implementation will be
somewhat different ;-)
[toc] | [next] | [standalone]
| From | likcoras <likcoras@riseup.net> |
|---|---|
| Date | 2018-03-25 18:40 +0200 |
| Message-ID | <vxgQy-6mo-11@gated-at.bofh.it> |
| In reply to | #194150 |
On 03/26/2018 12:52 AM, rhkramer@gmail.com wrote: > I started reading up on password managers in order to consider using one. Good! Welcome aboard. > Here are some of what I think are my criteria for a password manager: > > * encrypted storage on my own machines (no storage "in the cloud") > * ability to transfer to other devices, including Android tablets and > phones--either all the passwords or just one for some special logon on a > machine I don't normally use. Currently I do almost everything (that requires > a password) on one of my desktop computers. I have a laptop that I use very > occasionally. Occasionally I've had to go to a library (or similar) to use a > Windows machine. I do have an Android tablet and phone, and, in general, I > don't use that for confidential type stuff (no banking, for example), but that > could change if either I feel very secure or in some sort of extreme > emergency. > * (a repeat of part of the previous bullet) a means to easily take an > individual password to another machine for occasional use of another machine > * a means to recover all the passwords if the password manager becomes > defunct (and this also implies backup and restore capabilities) > * a means to automatically generate secure passwords > * a means to automatically update passwords on the target websites (to > facilitate regular / frequent password changes)--this is probably a stretch--I > mean something that would work its way through the various screens and prompts > to change a password with a minimum of manual intervention by me > I think pass (https://www.passwordstore.org/) meets most of your requirements. It's a glorified shell script that calls gpg under the hood to create passwords that are stored locally (under ~/.password-store). - It does not have a network component. - You can transfer individual password files, decrypt them yourself with gpg, etc. - Very straightforward to decrypt with a simple shell script. - Uses pwgen to generate passwords, if requested. You can customize generation a bit (no special characters, etc.) - It does not handle automatic password updates. It would also be trivial to modify the script to use some other password generator, and of course you can input your own passwords. The pass package in Debian also includes the passmenu utility, which uses dmenu to automatically type in your password for you. I highly recommend you use this or some other frontend, as copy-pasting passwords becomes a chore. Let the password manager type it out for you! That is one disadvantage of pass, though. It does not have a built-in frontend, so it requires you to install some other piece if you want to use it more efficiently. Also note, if you decide to use passmenu, I think there was some bug where it did not properly escape text when typing it in for you. Not sure if it was patched or if the bug is still open. If it gives you trouble, just grab the latest version from the pass git repository. > As an alternative to a password manager, I may create my own memorizable > password generator "algorithm" that I can mostly use "in my head". For > instance, it could be something like this: > * think up a multiword phrase, possibly with a mnemonic connection to the > target website (or, have a means to extract them from a book, e.g., the 3rd > sentence of the 5th chapter of War and Peace--or maybe the first sentence in > the book that contains the word bank would become the passphrase for my bank). > * have a consistent substitution algorithm, which might do things like > this: > * capitalize the nth letter of each word (or the nth letter of the first > word, the (n+1)th letter of the 2nd word, ... > * substitute (or insert) a punctuation mark for (like above) the mth > letter of each word (or the mth letter of the first word, the (m+1)th letter of > the 2nd word, ... --the puntuation might be selected in, for example, keyboard > order (or reverse keyboard order) across the numeric keys (e.g., !@#$%^&*() > (although maybe some of those might be invalid in (some?) passwords) > * some other similar generation rules > > Obviously, having "published" these ideas, my actual implementation will be > somewhat different ;-) About that, I would suggest you just use diceware (http://world.std.com/%7Ereinhold/diceware.html). The page includes instructions on adding special characters/etc to increase entropy/satisfy dumb requirements. The reason for this is that you are guaranteed a certain amount of entropy even if your method of generating passwords is revealed, even if they know which wordlist that you use. Something like what you describe might possibly be safer, but you can't really quantify how much security you would be giving up by omitting some step, or how worried you should be about having some of the steps revealed by accident or by other, more nefarious means. Don't take chances when generating passwords. Also, diceware passwords are surprisingly easy to remember, even if they don't have some kind of mnemonic relation to the site it's for. Remembering multiple 6~8-word passwords is not that hard if you use them relatively often.
[toc] | [prev] | [next] | [standalone]
| From | Ben Finney <bignose@debian.org> |
|---|---|
| Date | 2018-03-26 00:10 +0200 |
| Message-ID | <vxlZU-1CZ-9@gated-at.bofh.it> |
| In reply to | #194151 |
likcoras <likcoras@riseup.net> writes: > I think pass (https://www.passwordstore.org/) meets most of your > requirements. It's a glorified shell script that calls gpg under the > hood to create passwords that are stored locally (under > ~/.password-store). I concur with the recommendation for Password Store, in this case. (that link again, <URL:https://www.passwordstore.org/>). Someone who has been manually handling their password database should be right at home with the Password Store system. > - It does not have a network component. Password Store uses Git to store the entries, and Git natively allows distribution of the repository via SSH or HTTPS (and others, of course). > - You can transfer individual password files, decrypt them yourself > with gpg, etc. This is very important! Our password data is too crucial to be locked into a custom data format needing a specific tool. Password Store avoids this by using only standard, general-purpose tools. > - Very straightforward to decrypt with a simple shell script. > - Uses pwgen to generate passwords, if requested. You can customize > generation a bit (no special characters, etc.) For more useful passphrases I can recommend Diceware or ‘xkcdpass’ <URL:https://pypi.python.org/pypi/xkcdpass>. That's a separate tool though, Password Store does not yet integrate with it. > - It does not handle automatic password updates. True. This could be implemented in a custom client though. Which raises another advantage of Password Store: it is a description of a password manager *without* specifying the client. There are many clients that work with this system, as can be seen at the website. <URL:https://www.passwordstore.org/#other> So I use the ‘pass’ command-line client on some machines, QtPass desktop client on others, and the Android app (available from the F-Droid app store <URL:https://f-droid.org/repository/browse/?fdid=com.zeapo.pwdstore>) to carry them with me. -- \ “Isn't it enough to see that a garden is beautiful without | `\ having to believe that there are fairies at the bottom of it | _o__) too?” —Douglas Adams | Ben Finney
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2018-03-25 19:50 +0200 |
| Message-ID | <vxhWh-71Y-3@gated-at.bofh.it> |
| In reply to | #194150 |
On Sun 25 Mar 2018 at 11:52:13 -0400, rhkramer@gmail.com wrote:
> I started reading up on password managers in order to consider using one.
>
> Up until now, I've made up passwords myself, and stored them in an encrypted
> file. Some of the drawbacks include:
>
> * I keep the passwords on the short side
The PIN for my credit card has only four digits.
> * I don't change the passwords as often as I should
There isn't and never has been a need to do this. Passwords don't
deteriorate with age.
> * I sometimes use the same password on more than one site
Tut, tut.
> All of the above because it is not convenient enough for me to do better.
>
> My head is just not "into" reading about password managers--it just seems to
> be too boring to really get into, so, I thought I'd try posting here to get
> opinions and recommendations from the list. (I am continuing my effort to
> read--maybe I'll get a renewed burst of enthusiasm after I send this ;-)
>
> Here are some of what I think are my criteria for a password manager:
>
> * encrypted storage on my own machines (no storage "in the cloud")
Definitely done by
http://masterpasswordapp.com/
It is designed that way.
> * ability to transfer to other devices, including Android tablets and
> phones--either all the passwords or just one for some special logon on a
> machine I don't normally use. Currently I do almost everything (that requires
> a password) on one of my desktop computers. I have a laptop that I use very
> occasionally. Occasionally I've had to go to a library (or similar) to use a
> Windows machine. I do have an Android tablet and phone, and, in general, I
> don't use that for confidential type stuff (no banking, for example), but that
> could change if either I feel very secure or in some sort of extreme
> emergency.
I don't use such such exotic devices but see how
http://masterpasswordapp.com/
suits.
> * (a repeat of part of the previous bullet) a means to easily take an
> individual password to another machine for occasional use of another machine
http://masterpasswordapp.com/
has only one password; you can take it anywhere you want.
> * a means to recover all the passwords if the password manager becomes
> defunct (and this also implies backup and restore capabilities)
Not too sure about this but, provided you have the app, you have the
ability to (re)generate all your passwords.
> * a means to automatically generate secure passwords
That's
http://masterpasswordapp.com/
> * a means to automatically update passwords on the target websites (to
> facilitate regular / frequent password changes)--this is probably a stretch--I
> mean something that would work its way through the various screens and prompts
> to change a password with a minimum of manual intervention by me
See above. A waste time.
> As an alternative to a password manager, I may create my own memorizable
> password generator "algorithm" that I can mostly use "in my head". For
> instance, it could be something like this:
Don't bother.
http://masterpasswordapp.com/
got there before you. And does it better than you and I could ever do.
> * think up a multiword phrase, possibly with a mnemonic connection to the
> target website (or, have a means to extract them from a book, e.g., the 3rd
> sentence of the 5th chapter of War and Peace--or maybe the first sentence in
> the book that contains the word bank would become the passphrase for my bank).
> * have a consistent substitution algorithm, which might do things like
> this:
> * capitalize the nth letter of each word (or the nth letter of the first
> word, the (n+1)th letter of the 2nd word, ...
> * substitute (or insert) a punctuation mark for (like above) the mth
> letter of each word (or the mth letter of the first word, the (m+1)th letter of
> the 2nd word, ... --the puntuation might be selected in, for example, keyboard
> order (or reverse keyboard order) across the numeric keys (e.g., !@#$%^&*()
> (although maybe some of those might be invalid in (some?) passwords)
> * some other similar generation rules
>
> Obviously, having "published" these ideas, my actual implementation will be
> somewhat different ;-)
masterpasswordapp is a deterministic password generator. Such things
sometimes get a bad press. In this case, much of the criticism is
unjustified. Documentation and support for it is excellent.
--
Brian. (Who doesn't have any commercial connection with
masterpasswordapp.com/)
[toc] | [prev] | [next] | [standalone]
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Date | 2018-03-25 20:10 +0200 |
| Message-ID | <vxifE-7nL-15@gated-at.bofh.it> |
| In reply to | #194154 |
On Sun, Mar 25, 2018 at 06:48:15PM +0100, Brian wrote: > On Sun 25 Mar 2018 at 11:52:13 -0400, rhkramer@gmail.com wrote: > > The PIN for my credit card has only four digits. > > > * I don't change the passwords as often as I should > > There isn't and never has been a need to do this. Passwords don't > deteriorate with age. > I disagree. Forced password changes are annoying and counterproductive, but there is an argument to be made for users periodically changing their passwords. The Yahoo! data breach, for example, did not become publically known until long after the breach. Even then, the scope continued to expand as additional related breaches were discovered that had taken place even earlier. There are some sites which force me to change my password periodically and find them annoying because the passwords do not protect anything important enough to warrant that. On the other hand, there are some sites where I regularly change my password to guard against a hacker gaining continuing access to my account/data following a breach. While you are right that passwords do not deteriorate, they do get compromised. The last few years have shown that it happens with rather shocking regularity. Regards, -Roberto -- Roberto C. Sánchez
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2018-03-25 20:50 +0200 |
| Message-ID | <vxiSm-7CO-5@gated-at.bofh.it> |
| In reply to | #194155 |
On Sun 25 Mar 2018 at 14:06:53 -0400, Roberto C. Sánchez wrote: > On Sun, Mar 25, 2018 at 06:48:15PM +0100, Brian wrote: > > On Sun 25 Mar 2018 at 11:52:13 -0400, rhkramer@gmail.com wrote: > > > > The PIN for my credit card has only four digits. > > > > > * I don't change the passwords as often as I should > > > > There isn't and never has been a need to do this. Passwords don't > > deteriorate with age. > > > I disagree. Forced password changes are annoying and counterproductive, Those two attributes may be a consequence of forced password changes but are not sufficient to advocate or not advocate such a strategey. > but there is an argument to be made for users periodically changing > their passwords. The Yahoo! data breach, for example, did not become > publically known until long after the breach. Even then, the scope > continued to expand as additional related breaches were discovered that > had taken place even earlier. 1 day after the breach your data had been compromised. Changing your password 10 days later on in your 1 month cycle doesn't seem to me to be reactive security. Better than nothing, I suppose, but closing the door after etc. In any case, your 20 character, high entropy password was your ultimate defence. (Not unless Yahoo! didn't hash). > There are some sites which force me to change my password periodically > and find them annoying because the passwords do not protect anything > important enough to warrant that. On the other hand, there are some > sites where I regularly change my password to guard against a hacker > gaining continuing access to my account/data following a breach. If I had so little confidence in the password hashing procedures at the site I might do the same. My problem would then come down to predicting when a likely breach would occur. -- Brian. > > While you are right that passwords do not deteriorate, they do get > compromised. The last few years have shown that it happens with rather > shocking regularity. > > Regards, > > -Roberto > > -- > Roberto C. Sánchez >
[toc] | [prev] | [next] | [standalone]
| From | Ángel <debian-user@debian.16bits.net> |
|---|---|
| Date | 2018-03-25 23:20 +0200 |
| Message-ID | <vxldw-PW-17@gated-at.bofh.it> |
| In reply to | #194156 |
On 2018-03-25 at 19:47 +0100, Brian wrote: > 1 day after the breach your data had been compromised. Changing your > password 10 days later on in your 1 month cycle doesn't seem to me to > be reactive security. Better than nothing, I suppose, but closing the > door after etc. > > In any case, your 20 character, high entropy password was your ultimate > defence. (Not unless Yahoo! didn't hash). Sure. If someone stole your password, be that by compromising and injecting a password-stealing javascript server side, due to a sslstrip you didn't notice on that free wifi, perhaps just someone looking at the keys you pressed when entering your password, etc. the data you had up to that point in that service should be considered compromised. However, if the password was changed N days/months later, as part of a periodic password change, that would mean that data processed after that date would no longer be in risk, whereas otherwise the account would continue being accessible by the bad actors for years (assuming that you are not using a pattern that removes the benefit or rotating the password!). Regards
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2018-03-26 21:40 +0200 |
| Message-ID | <vxG8h-zI-9@gated-at.bofh.it> |
| In reply to | #194160 |
On Sun 25 Mar 2018 at 22:43:26 +0200, Ángel wrote: > On 2018-03-25 at 19:47 +0100, Brian wrote: > > 1 day after the breach your data had been compromised. Changing your > > password 10 days later on in your 1 month cycle doesn't seem to me to > > be reactive security. Better than nothing, I suppose, but closing the > > door after etc. > > > > In any case, your 20 character, high entropy password was your ultimate > > defence. (Not unless Yahoo! didn't hash). > > > Sure. If someone stole your password, be that by compromising and > injecting a password-stealing javascript server side, due to a sslstrip > you didn't notice on that free wifi, perhaps just someone looking at the > keys you pressed when entering your password, etc. the data you had up > to that point in that service should be considered compromised. > > However, if the password was changed N days/months later, as part of a > periodic password change, that would mean that data processed after that > date would no longer be in risk, whereas otherwise the account would > continue being accessible by the bad actors for years (assuming that you > are not using a pattern that removes the benefit or rotating the > password!). I would be more accepting of this argument if it fitted with real world examples in other fields. Nobody offers the advice to change the locks on your front door or your car at regular intervals. But the computer security business has conjured up the "what if" argument to counteract commensense. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | Mark Fletcher <mark27q1@gmail.com> |
|---|---|
| Date | 2018-03-27 04:50 +0200 |
| Message-ID | <vxMQq-5EJ-7@gated-at.bofh.it> |
| In reply to | #194185 |
On Mon, Mar 26, 2018 at 08:34:28PM +0100, Brian wrote: > On Sun 25 Mar 2018 at 22:43:26 +0200, Ángel wrote: > > > On 2018-03-25 at 19:47 +0100, Brian wrote: > > > 1 day after the breach your data had been compromised. Changing your > > > password 10 days later on in your 1 month cycle doesn't seem to me to > > > be reactive security. Better than nothing, I suppose, but closing the > > > door after etc. > > > > > > In any case, your 20 character, high entropy password was your ultimate > > > defence. (Not unless Yahoo! didn't hash). > > > > > > Sure. If someone stole your password, be that by compromising and > > injecting a password-stealing javascript server side, due to a sslstrip > > you didn't notice on that free wifi, perhaps just someone looking at the > > keys you pressed when entering your password, etc. the data you had up > > to that point in that service should be considered compromised. > > > > However, if the password was changed N days/months later, as part of a > > periodic password change, that would mean that data processed after that > > date would no longer be in risk, whereas otherwise the account would > > continue being accessible by the bad actors for years (assuming that you > > are not using a pattern that removes the benefit or rotating the > > password!). > > I would be more accepting of this argument if it fitted with real world > examples in other fields. Nobody offers the advice to change the locks > on your front door or your car at regular intervals. But the computer > security business has conjured up the "what if" argument to counteract > commensense. > It's pretty difficult to steal someone's keys without them realising it has happened. In contrast, password compromise happens without the victim's knowledge all the time. Mark
[toc] | [prev] | [next] | [standalone]
| From | Richard Hector <richard@walnut.gen.nz> |
|---|---|
| Date | 2018-03-26 02:40 +0200 |
| Message-ID | <vxol3-3lp-1@gated-at.bofh.it> |
| In reply to | #194150 |
[Multipart message — attachments visible in raw view] — view raw
On 26/03/18 04:52, rhkramer@gmail.com wrote: > I started reading up on password managers in order to consider using one. I use the keepass family - KeePassX on Debian, KeePassDroid on Android. I believe Windows and Mac versions are available as well. > * encrypted storage on my own machines (no storage "in the cloud") Yes > * ability to transfer to other devices, including Android tablets and > phones--either all the passwords or just one for some special logon on a > machine I don't normally use. Currently I do almost everything (that requires > a password) on one of my desktop computers. I have a laptop that I use very > occasionally. Occasionally I've had to go to a library (or similar) to use a > Windows machine. I do have an Android tablet and phone, and, in general, I > don't use that for confidential type stuff (no banking, for example), but that > could change if either I feel very secure or in some sort of extreme > emergency. I sync my database to my own NextCloud instance - in my case it's on a VPS, which I guess is 'in the cloud', but I manage it myself. There are NextCloud clients for all the above platforms as well. > * (a repeat of part of the previous bullet) a means to easily take an > individual password to another machine for occasional use of another machine Not that I know of. But it's on my phone, which goes where I go. That does mean I sometimes have to view the password and type it in, which is a pain for a 16-character password full of symbols ... > * a means to recover all the passwords if the password manager becomes > defunct (and this also implies backup and restore capabilities) It's free software, so you can keep copies of it. It can export to XML (IIRC) too. > * a means to automatically generate secure passwords Yes. Well, I assume they're secure; I'm no cryptographer. > * a means to automatically update passwords on the target websites (to > facilitate regular / frequent password changes)--this is probably a stretch--I > mean something that would work its way through the various screens and prompts > to change a password with a minimum of manual intervention by me Difficult. That would have to be scripted for each website etc, wouldn't it? Richard
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-26 04:00 +0200 |
| Message-ID | <vxpAt-4gv-1@gated-at.bofh.it> |
| In reply to | #194163 |
<extensive snipping to reply to just one point--I may respond to others at some time in the future> On Sunday, March 25, 2018 08:38:25 PM Richard Hector wrote: > On 26/03/18 04:52, rhkramer@gmail.com wrote: > > * a means to automatically update passwords on the target websites (to > > > > facilitate regular / frequent password changes)--this is probably a > > stretch--I mean something that would work its way through the various > > screens and prompts to change a password with a minimum of manual > > intervention by me > > Difficult. That would have to be scripted for each website etc, wouldn't > it? Yes, at least I think so, unless there is some standard for how to handle passwords (including changing them) on websites. I suspect that there isn't. There may be some commonality in websites generated by a common website "generator" (one of those packages that help you create a website--I think they exist, but I've never used one--maybe Drupal is an example?
[toc] | [prev] | [next] | [standalone]
| From | Brian <ad44@cityscape.co.uk> |
|---|---|
| Date | 2018-03-26 22:00 +0200 |
| Message-ID | <vxGrE-If-9@gated-at.bofh.it> |
| In reply to | #194166 |
On Sun 25 Mar 2018 at 21:54:22 -0400, rhkramer@gmail.com wrote: > <extensive snipping to reply to just one point--I may respond to others at > some time in the future> > > On Sunday, March 25, 2018 08:38:25 PM Richard Hector wrote: > > On 26/03/18 04:52, rhkramer@gmail.com wrote: > > > * a means to automatically update passwords on the target websites (to > > > > > > facilitate regular / frequent password changes)--this is probably a > > > stretch--I mean something that would work its way through the various > > > screens and prompts to change a password with a minimum of manual > > > intervention by me > > > > Difficult. That would have to be scripted for each website etc, wouldn't > > it? > > Yes, at least I think so, unless there is some standard for how to handle > passwords (including changing them) on websites. I suspect that there isn't. > There may be some commonality in websites generated by a common website > "generator" (one of those packages that help you create a website--I think > they exist, but I've never used one--maybe Drupal is an example? The standard exists. You change your password via the website. Then you inform your password manager of the change. -- Brian.
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-26 23:40 +0200 |
| Message-ID | <vxI0q-20p-15@gated-at.bofh.it> |
| In reply to | #194186 |
On Monday, March 26, 2018 03:49:38 PM Brian wrote: > On Sun 25 Mar 2018 at 21:54:22 -0400, rhkramer@gmail.com wrote: > > <extensive snipping to reply to just one point--I may respond to others > > at some time in the future> > > > > On Sunday, March 25, 2018 08:38:25 PM Richard Hector wrote: > > > On 26/03/18 04:52, rhkramer@gmail.com wrote: > > > > * a means to automatically update passwords on the target websites > > > > (to > > > > > > > > facilitate regular / frequent password changes)--this is probably a > > > > stretch--I mean something that would work its way through the various > > > > screens and prompts to change a password with a minimum of manual > > > > intervention by me > > > > > > Difficult. That would have to be scripted for each website etc, > > > wouldn't it? > > > > Yes, at least I think so, unless there is some standard for how to handle > > passwords (including changing them) on websites. I suspect that there > > isn't. There may be some commonality in websites generated by a common > > website "generator" (one of those packages that help you create a > > website--I think they exist, but I've never used one--maybe Drupal is an > > example? > > The standard exists. You change your password via the website. Then you > inform your password manager of the change. Ok, but that's not the kind of standard I was hoping for--I was hoping for a (standard) programmatic way of changing the password on a website, which, being programmatic, could be initiated by the password manager.
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2018-03-27 10:10 +0200 |
| Message-ID | <vxRQ6-19a-7@gated-at.bofh.it> |
| In reply to | #194189 |
On Mon, 26 Mar 2018 17:38:33 -0400 rhkramer@gmail.com wrote: > > > > > > > Yes, at least I think so, unless there is some standard for how > > > to handle passwords (including changing them) on websites. I > > > suspect that there isn't. There may be some commonality in > > > websites generated by a common website "generator" (one of those > > > packages that help you create a website--I think they exist, but > > > I've never used one--maybe Drupal is an example? > > > > The standard exists. You change your password via the website. Then > > you inform your password manager of the change. > > Ok, but that's not the kind of standard I was hoping for--I was > hoping for a (standard) programmatic way of changing the password on > a website, which, being programmatic, could be initiated by the > password manager. > Unless such a thing is a library function in JavaScript, then no commercial website will contain it... More seriously, I doubt that such a thing exists, it would be like the backdoor in OpenSSL, an absolutely disastrous idea. Websites tend to store password data (sometimes in plain text!) insecurely enough as it is. Also, many websites where security is a big issue do try to ensure that logins can't be made by computer. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-27 14:50 +0200 |
| Message-ID | <vxWd3-3ZI-11@gated-at.bofh.it> |
| In reply to | #194203 |
On Tuesday, March 27, 2018 04:08:07 AM Joe wrote: > On Mon, 26 Mar 2018 17:38:33 -0400 > > rhkramer@gmail.com wrote: > > > > Yes, at least I think so, unless there is some standard for how > > > > to handle passwords (including changing them) on websites. I > > > > suspect that there isn't. There may be some commonality in > > > > websites generated by a common website "generator" (one of those > > > > packages that help you create a website--I think they exist, but > > > > I've never used one--maybe Drupal is an example? > > > > > > The standard exists. You change your password via the website. Then > > > you inform your password manager of the change. > > > > Ok, but that's not the kind of standard I was hoping for--I was > > hoping for a (standard) programmatic way of changing the password on > > a website, which, being programmatic, could be initiated by the > > password manager. > > Unless such a thing is a library function in JavaScript, then no > commercial website will contain it... > > More seriously, I doubt that such a thing exists, it would be like the > backdoor in OpenSSL, an absolutely disastrous idea. Websites tend to > store password data (sometimes in plain text!) insecurely enough as it > is. > Good point, although I'd expect such a function to require authentication, presumably by entering the old password. > Also, many websites where security is a big issue do try to ensure that > logins can't be made by computer. Oh, yeah, Captchas (and such)--how could I forget about those...
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-27 15:00 +0200 |
| Message-ID | <vxWmK-43e-11@gated-at.bofh.it> |
| In reply to | #194211 |
On Tuesday, March 27, 2018 08:47:10 AM rhkramer@gmail.com wrote: > On Tuesday, March 27, 2018 04:08:07 AM Joe wrote: > > On Mon, 26 Mar 2018 17:38:33 -0400 > > > > rhkramer@gmail.com wrote: > > > > > Yes, at least I think so, unless there is some standard for how > > > > > to handle passwords (including changing them) on websites. I > > > > > suspect that there isn't. There may be some commonality in > > > > > websites generated by a common website "generator" (one of those > > > > > packages that help you create a website--I think they exist, but > > > > > I've never used one--maybe Drupal is an example? > > > > > > > > The standard exists. You change your password via the website. Then > > > > you inform your password manager of the change. > > > > > > Ok, but that's not the kind of standard I was hoping for--I was > > > hoping for a (standard) programmatic way of changing the password on > > > a website, which, being programmatic, could be initiated by the > > > password manager. > > > > Unless such a thing is a library function in JavaScript, then no > > commercial website will contain it... > > > > More seriously, I doubt that such a thing exists, it would be like the > > backdoor in OpenSSL, an absolutely disastrous idea. Websites tend to > > store password data (sometimes in plain text!) insecurely enough as it > > is. > > Good point, although I'd expect such a function to require authentication, > presumably by entering the old password. > Hmm, but on further (but little thought), I still would like such a function, maybe it could work something like this: When you login to a site that requires authentication / a password (and you've fulfilled the captcha or equal), you could get a prompt something like: "Would you like to change the password? (Maybe mentioning how old the password is, or how many times you've logged in using it). If you answer yes to the prompt, the password manager starts a programmatic dialog to change the password, including entering the password, but (perhaps optionally, via a per site setting in your password manager) it requires additional authentication (from / with the site, not with password manager) which may include--well, something, maybe another captcha. And it would only work on https:// pages or under similar encryption. > > Also, many websites where security is a big issue do try to ensure that > > logins can't be made by computer. > > Oh, yeah, Captchas (and such)--how could I forget about those...
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-27 03:10 +0200 |
| Subject | Update: Re: Password Manager opinions and recommendations |
| Message-ID | <vxLhD-4wQ-3@gated-at.bofh.it> |
| In reply to | #194186 |
Thanks to all who replied! I thought I'd summarize where I am: I like three of the suggestions (from what I've seen / investigated (slightly) so far, but with some comments: * pass: appeals to me a lot--the one problem for me (for which I believe I've found the solution) is that it stores the encrypted password files in my /home. I have what might be called a "religious" aversion to storing what I consider "real" user data in /home. I've looked at the source code, and I see where $HOME is used to create that directory. If I use pass, I will, at the very least, modify that in my own copy, but also write to the author and suggest that he allow a command line parameter (or config file) change the location of the directory. * I like the approach that http://masterpasswordapp.com/ takes to create passwords and, iiuc, recreate them each time they are needed rather than storing them anywhere. I'll read up a little more on that. * I haven't spent much time on keepass--maybe in the next day or so * I also like the approach suggested by Abdullah Ramazanoglu (and the somewhat similar Diceware), but I almost didn't find the emails from Abdullah-- for some reason my email client did not receive them--I've done a search of all the local email files (on my computer) (including trash, which I have not emptied in the last several days), and I've searched the Google email spam, trash, and all folders. I'll be digging into this and possibly seek help in a new thread.
[toc] | [prev] | [next] | [standalone]
| From | Abdullah Ramazanoglu <ar018@yahoo.com> |
|---|---|
| Date | 2018-03-27 03:40 +0200 |
| Subject | Re: Update: Re: Password Manager opinions and recommendations |
| Message-ID | <vxLKF-4IX-1@gated-at.bofh.it> |
| In reply to | #194191 |
On Mon, 26 Mar 2018 21:02:48 -0400 rhkramer@gmail.com said: > Thanks to all who replied! You are welcome. :) > * I also like the approach suggested by Abdullah Ramazanoglu (and > the somewhat similar Diceware), but I almost didn't find the emails > from Abdullah-- for some reason my email client did not receive > them--I've done a search of all the local email files (on my > computer) (including trash, which I have not emptied in the last > several days), and I've searched the Google email spam, trash, and > all folders. I'll be digging into this and possibly seek help in a > new thread. That maybe because I am not subscribed to the mailing list? I use a news (nntp) client and read/post messages through an nntp server - mailing list gateway (gmane.org) However, my posts to news server nntp.gmane.org are forwarded to the mailing list by Gmane (and vice versa) and then distributed by lists.debian.org mailing list manager to everyone subscribed, so you should have received them (not directly from me, but) from the mailing list. Or I might have possibly misunderstood the actual problem. Regards -- Abdullah Ramazanoglu
[toc] | [prev] | [next] | [standalone]
| From | Kushal Kumaran <kushal@locationd.net> |
|---|---|
| Date | 2018-03-27 07:00 +0200 |
| Subject | Re: Update: Re: Password Manager opinions and recommendations |
| Message-ID | <vxOSe-7m3-5@gated-at.bofh.it> |
| In reply to | #194191 |
rhkramer@gmail.com writes: > Thanks to all who replied! > > I thought I'd summarize where I am: > > I like three of the suggestions (from what I've seen / investigated (slightly) > so far, but with some comments: > > * pass: appeals to me a lot--the one problem for me (for which I believe > I've found the solution) is that it stores the encrypted password files in my > /home. I have what might be called a "religious" aversion to storing what I > consider "real" user data in /home. I've looked at the source code, and I see > where $HOME is used to create that directory. If I use pass, I will, at the > very least, modify that in my own copy, but also write to the author and > suggest that he allow a command line parameter (or config file) change the > location of the directory. > Set the PASSWORD_STORE_DIR environment variable to point to your location of choice. This is mentioned in the "Environment Variables" section of the pass(1) manpage. One thing I like about pass is its ability to encrypt using multiple keys. This lets me use the repository both on my computer and my phone without the private keys leaving either device. > * I like the approach that http://masterpasswordapp.com/ takes to create > passwords and, iiuc, recreate them each time they are needed rather than > storing them anywhere. I'll read up a little more on that. > > * I haven't spent much time on keepass--maybe in the next day or so > > * I also like the approach suggested by Abdullah Ramazanoglu (and the > somewhat similar Diceware), but I almost didn't find the emails from Abdullah-- > for some reason my email client did not receive them--I've done a search of > all the local email files (on my computer) (including trash, which I have not > emptied in the last several days), and I've searched the Google email spam, > trash, and all folders. I'll be digging into this and possibly seek help in a > new thread. -- regards, kushal
[toc] | [prev] | [next] | [standalone]
| From | rhkramer@gmail.com |
|---|---|
| Date | 2018-03-27 14:40 +0200 |
| Subject | Re: Update: Re: Password Manager opinions and recommendations |
| Message-ID | <vxW3o-3UW-7@gated-at.bofh.it> |
| In reply to | #194195 |
On Tuesday, March 27, 2018 12:56:24 AM Kushal Kumaran wrote: > Set the PASSWORD_STORE_DIR environment variable to point to your > location of choice. This is mentioned in the "Environment Variables" > section of the pass(1) manpage. Thanks! I missed that.
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web