Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #194397
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) |
| Date | 2018-04-02 15:30 +0200 |
| Message-ID | <vA7H3-1Tr-7@gated-at.bofh.it> (permalink) |
| References | <vxgdP-5Um-11@gated-at.bofh.it> <vz7pL-2ir-3@gated-at.bofh.it> <vzdOx-6GE-1@gated-at.bofh.it> <vA7nH-1KQ-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On Mon, Apr 02, 2018 at 09:07:16AM -0400, rhkramer@gmail.com wrote: > > The first two situations that come to mind include: > > * during copy and paste operations, the plaintext password could remain on > the C&P "stack". thus making it vulnurable: Some notes: > > (1) I've read about at least one password manager that, somehow, deletes > the plaintext password from the copy and paste "stack" after a time delay--I > didn't make a note of which one that was. > I use keepasssx and it has this feature. It is very handy, but very occasionally frustrating, depending on the UI with which I am interacting. > > * during hibernation (or maybe suspend and resume): (I use neither at the > present time, but, one stores the machine's state (including RAM) to disk, the > other stores the (CPU) state to RAM while preserving the other contents of > RAM.) Hibernation could result in the plaintext of passwords being stored on > disk while the power is off, making the plaintext passwords vulnurable if the > machine is stolen. > Using full disk encryption (or at a very minimum encrypted swap makes this less of an issue. Yet another issue that you did not mention but which, IMHO, is a far more practical one (in the sense that it impacts us every single day yet we tend to not be aware of it) is that every program to which you supply your password must securely manage transferring the password into and out of memory. If you log in to a display manager, it must take your plaintext password from a text box and transfer it to another layer of the OS. If you provide a password to your web browser in an authentication dialog, the browser must take that plaintext password and either produce a digest (for digest-based authentication) or send it in the clear (e.g., over a connection secured with SSL/TLS). It must necessarily reside in memory. I use mutt and I either must store my passwords in plain text in ~/.muttrc or provide them to mutt when prompted. However, when providing the password to mutt when prompted, the default for mutt is to remember the password until the end of the session. It has to be stored somewhere. Now, the kernel provides facilities for storing sensitive information in memory, protecting access to it, and preventing it from getting swapped to disk. However, when you use the wide variety of applications that take passwords as input, you necessarily trust that the developers are using all the appropriate facilities to securely handle the password and also to securely wipe it from memory. Some applications, I trust because of their reputation or because they are high profile receive lots of attention from security researchers (e.g., KeePassX, Firefox, Chromium, etc.). However, I have delved into the code of some random applications (the one that stands out in my mind is an FTP client, though I do not recall which one it was) that make me think that most applications that handle passwords do so improperly and insecurely. I hope I did not open yet another can of worms here for you :-) Regards, -Roberto -- Roberto C. Sánchez
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-25 18:00 +0200
Re: Password Manager opinions and recommendations likcoras <likcoras@riseup.net> - 2018-03-25 18:40 +0200
Re: Password Manager opinions and recommendations Ben Finney <bignose@debian.org> - 2018-03-26 00:10 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 19:50 +0200
Re: Password Manager opinions and recommendations Roberto C. Sánchez <roberto@debian.org> - 2018-03-25 20:10 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 20:50 +0200
Re: Password Manager opinions and recommendations Ángel <debian-user@debian.16bits.net> - 2018-03-25 23:20 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 21:40 +0200
Re: Password Manager opinions and recommendations Mark Fletcher <mark27q1@gmail.com> - 2018-03-27 04:50 +0200
Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-26 02:40 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 04:00 +0200
Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 22:00 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 23:40 +0200
Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:10 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 15:00 +0200
Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 03:10 +0200
Re: Update: Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-27 03:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Kushal Kumaran <kushal@locationd.net> - 2018-03-27 07:00 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:00 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-27 13:20 +0200
Re: Update: Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-28 04:30 +0200
Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-28 12:40 +0200
Re: Update: Re: Password Manager opinions and recommendations Tomaž Šolc <tomaz.solc@tablix.org> - 2018-03-30 14:00 +0200
Re: Update: Re: Password Manager opinions and recommendations Curt <curty@free.fr> - 2018-03-30 14:50 +0200
Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:10 +0200
Re: Update: Re: Password Manager opinions and recommendations Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-31 01:00 +0200
Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:00 +0200
Re: Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-30 16:20 +0200
Re: Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 20:20 +0200
Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 10:50 +0200
Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 15:20 +0200
Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 21:00 +0200
Re: Password Manager opinions and recommendations Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2018-03-31 03:50 +0200
Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 15:10 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) <tomas@tuxteam.de> - 2018-04-02 15:20 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 20:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Roberto C. Sánchez <roberto@debian.org> - 2018-04-02 15:30 +0200
Re: Chaniging focus: security ouitside a password manager likcoras <likcoras@riseup.net> - 2018-04-02 16:00 +0200
Re: Chaniging focus: security ouitside a password manager Ben Finney <bignose@debian.org> - 2018-04-03 01:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) "der.hans" <deb-user@LuftHans.com> - 2018-04-03 02:10 +0200
Re: Chaniging focus: security ouitside a password manager Richard Hector <richard@walnut.gen.nz> - 2018-04-03 08:00 +0200
Re: Chaniging focus: security ouitside a password manager rhkramer@gmail.com - 2018-04-03 13:50 +0200
Re: Chaniging focus: security ouitside a password manager Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-04-03 18:30 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 11:40 +0200
Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 21:10 +0200
Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 03:40 +0200
Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 04:20 +0200
Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 05:10 +0200
Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 04:00 +0200
csiph-web