this post was submitted on 07 Sep 2023
989 points (99.0% liked)
Technology
59578 readers
6111 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each another!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
Approved Bots
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Firefox's password manager is probably just as good.
"Probably"? It's the best! I never have to worry about memorizing 500 different passwords cause Firefox automatically syncs my passwords across every device I use without me even having to think about it.
eh, it doesn't work for credentials of phone apps, bitwarden does and you can access those passwords if you log in into the web version if you are on an unknown pc.
It takes a few taps, but firefox's password service appears when you click the autofill option for me.
On apps besides Firefox? I mean apps like your bank app or ubereats, etc.
Not sure about the banking apps but a few other apps have worked for me. Like the Lemmy ones for instance.
Then it should for all, cool. I still prefer bitwarden becaue I can store credit card info, generic secure notes, and I'm able to access it from anywhere, useful when logging in into my email from my mother's PC and such, but it's cool that it is integrated with the keyboard engine too.
It's great.
I'd be worried about losing access to the entirety of your passwords if Google up and decides that one day your account is suspended. There's been a few reports historically where someone gets their Gmail account suspended for some mistaken reason and all their associated access gets pulled (e.g. from drive, sheets, etc)
You are saying that bitwarden suspended your account?
Bitwarden offers an encrypted backup...
Google has maybe a plain text export.
Bitwarden has run flawless for me for multiple years.
I got a Google account that was shut down after some spammer started using that email as the sender address (sometimes called a Joe job). I somehow got in contact with an employee (friend of a friend) that checked on the account and verified it wasn't my fault and reopened it, but a week later it got closed automatically again, with no easy way to reopen it.
The backscatter was hundreds of emails per day, so the email part of the account was useless anyway, but I used it for other things.
So it can happen at no fault on your own, and impossible to do anything about.
Hopefully you were of legal age to accept the Terms of Service, otherwise it might've been an irregular account all this time.
If it was, and you haven't accepted the ToS as of legal age, then you might want to make a new one.
Google is getting ready to purge inactive accounts starting next year, and it wouldn't be the first time when a service purged irregular accounts many years after the fact, so... better safe than sorry.
Google only just recently introduced encrypted passwords... Before they were stored in plain text on your computer... Tho I'm not even sure how that encryption even works.
So... It may not have leaked yet (or maybe it has but Google suppresses everything, who knows) but I wouldn't trust it to keep something safe.
There nothing to fix in an OS. Windows and chrome have vulnerabilities which are unfixable by regular people. What about malware? What about other people knowing the password to your pc?
It's impossible to trust an OS to not get hacked, because it's always the hackers or OS running behind the other.
You can replace the OS with one you trust more. Can also replace the browser, and "irregular people" can fix stuff in OpenSource OSs and browsers. Malware is easy to avoid, just don't execute random stuff. Other people knowing the password to your PC, is up to you.
Hackers generally don't hack OSs, users are much easier to hack.
And what is your point?
That everyone should change to some Linux distro? First of all Linux is not immune, it only lacks interest from hackers. The second it's not adapted to everyone. Even I who likes open source and learning new stuff is too annoyed by Linux because of compatibility reasons (mostly gaming).
Just don't execute random stuff? Wake up, or I'll use only chrome and nothing else on my pc. You want open source you must execute random stuff.
And people cannot be at their 100% at all time. There is a possible chance that some, even trained user, slips and executes some malware. In that case, antimalware come into play, but it's not always the case. Companies still get hacked with ransomwares and data extractors.
And your solution to the issue is just replacing the browser, like it would make a difference? At that point just use another password manager online...
My point is you start by using whichever OS you trust most: there is Windows, Mac OS, Chrome OS, Android, a bunch of Linux distros, BSD... your choice.
If you don't trust any OS... sorry, you're SOL. Plug the thing off and smash it with a hammer, then dump into salt water to be safe.
There are large OpenSource projects with security audits and security testing. There are random open and closed source projects with zero oversight by anyone.
Execute the former, not the latter.
Executable signing, anti-malware systems, and people running tests to rubber-stamp stuff exist (like distro repos, or app stores). Use those.
In most cases by hacking people, not software. Follow the above rules, don't trust that your CEO's nephew needs remote access to your PC... tell your coworkers not to trust that either... ... yeah, well, that's impossible, it takes only one to ransomware everyone... but you can keep yourself safe 🤷
Replacing the browser is optional, goes with the same trust issues as the OS.
...so far.
For those that don't mind self-hosting, which can be as easy as just running syncthing or resilio sync on your NAS, I can really recommend keepass.
Me with interest, but no technical knowledge reading your comment:
:-)
:-(
I didn't understand any of those words
A NAS is a home storage server, like Synology that you can use to store images, videos and backups, etc on so you can access them from any computer or device in your home. With a couple of clicks, they can easily run applications like Syncthing or Resilio Sync, which are kinda like Dropbox, except you don't have to pay Dropbox, you'll just be storing the files on your own service.
If that's too much to handle, you can still just store your Keepass file in Dropbox, so that it's available on all your devices. But in the end you'll still be storing your personal data on someone else's harddisk.
So in short, is at easy as using a prefab service? No, you'll have to invest some time, money, and knowledge yourself. But in the end, your data is not gathered in silo together with countless other users, which makes it a lot less attractive for hackers to try and steal it.
edit - nevermind I can't even format a comment, let alone self host a... Thingie. What the other guy said.
Self hosting is less appealing for criminals, though. Especially if the protocol is "vanilla" like ssh.
When you hack LastPass you know what you'll find, millions of passwords. When you hack a dude ssh you have one chance over one million that there is one dude password wallet.
It doesn't make financial sense to hack self hosting (unless it's specific server software)
There are plenty of use cases for going after self hosters. Bot farms are basically made up of “regular” computers infected with malware.
While you’re at it and have access to tens of thousands computers, also grabbing their passwords is just a nice bonus.
If anything, it doesn’t make financial sense not to do it. You’re right in that self hosters themselves are not the target per se. but they are targeted for other reasons, and that’s where it ends up becoming problematic.
You need to aumatize any operation... It's not conceivable that an human look at every device for stuff to steal. It would be even more expensive.
Generally all these bit malware do is 1) using a vulnerability to replicate themselves 2) mine crypto or other kind of crap. Sometimes (1) involves also stealing ssh keys but it's not the goal, it the mean.
Self hosting password/code/photos/whatever niches you are almost guaranteed that no human will look at hit because the amount of IoT/Routers/etc with nothing valuable beyond themselves generally composes the majority of these compromised bots
This is just the economic incentive
Oh yes, because automating a search for csv and json files to search for mail addresses and passwords can’t be done by malware. It must be a human.
Common. This happens on massive scale, wether you like it or not.
https://securityboulevard.com/2023/06/the-alarming-reality-the-extent-of-credentials-stolen-by-botnets/amp/
https://mybroadband.co.za/news/security/452972-password-cracker-software-creates-crypto-stealing-botnets.html/amp
https://phys.org/news/2013-12-stolen-credentials-million-compromised-accounts.amp
It's software, everything can be done. Even if username and passwords are not kept in plaintext as you suggest (and likely nobody would do)
Problem is that the number of people that self host password repositories is so little that it makes no financial sense. And so for this reason your "massive scale" is an hyperbole because there isn't a massive scale of people that self host password repositories
Botnets that stole from local password repositories makes more sense because there are more people that use password managers of sort.
Humans looking are flexible enough to look at all possible long tail cases like this.. but not going to happen except for high profile targets.
All in all what i am saying is that i don't see clear evidence that self hosting is more dangerous (in practice) than centralized hosting
PS: pro tip If you link references, make sure to read the references you link... The second one has nothing to do with password stealing, it was about a password cracker that was a trojan horse for a botnet. Yes, it fits the search "botnet password" but it doesn't sustain your point
As a non-Google user, Lemmy is only “Chrome bad”. They’re “Android is the only way”
Well chrome = bad. Just look at all the anti-competition things they are implementing just because they are the leaders on the market.
Now they are blocking cookies, it's great isn't it? NO! now they are targeting you through your browser history while blocking competition.
Manifest V3 introduced by Google, that's amazing, now ad blockers won't be able to update their list individually. It's amazing isn't it? Being able to hinder the adblockers when your revenues comes from ads.