Forum

 
  Back to OzPolitic.com   Welcome, Guest. Please Login or Register
  Forum Home Album HelpSearch Recent Rules LoginRegister  
 

Pages: 1 2 3 
Send Topic Print
Password managers (Read 2371 times)
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Password managers
Oct 17th, 2022 at 1:01pm
 
You can't 100% trust anything on the internet.

Evidence:



https://arstechnica.com/gadgets/2021/04/hackers-backdoor-corporate-password-mana...

Backdoored password manager stole data from as many as 29K enterprises
Compromised update mechanism for Passwordstate pushes malware that steals data.



Dan Goodin - 4/24/2021, 7:55 AM


...



As many as 29,000 users of the Passwordstate password manager downloaded a malicious update that extracted data from the app and sent it to an attacker-controlled server, the app-maker told customers.

In an email, Passwordstate creator Click Studios told customers that bad actors compromised its upgrade mechanism and used it to install a malicious file on user computers. The file, named “moserware.secretsplitter.dll,” contained a legitimate copy of an app called SecretSplitter, along with malicious code named "Loader," according to a brief writeup from security firm CSIS Group.



Back to top
 
 
IP Logged
 
Captain Nemo
Gold Member
*****
Offline


Australian Politics

Posts: 8428
Melbourne
Gender: male
Re: Password managers
Reply #1 - Oct 17th, 2022 at 1:06pm
 
"Bad actors" eh?

I blame this guy:

...


He may have had an accomplice ...

...
Back to top
 

The 2025 election could be a shocker.
WWW  
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #2 - Oct 17th, 2022 at 1:30pm
 
Who trusts password managers?
Back to top
 
 
IP Logged
 
random
Gold Member
*****
Offline


Australian Politics

Posts: 2637
Gender: male
Re: Password managers
Reply #3 - Oct 17th, 2022 at 2:11pm
 
Bobby. wrote on Oct 17th, 2022 at 1:30pm:
Who trusts password managers?


Two iphones ago I was using an encrypted one.  It was good, I thought I was clever and organised.

Then I bought a new phone, restored the last backup onto it then dealt with the usual exceptions.  It said that the pwd manager was no longer supported by the supplier and that the last version did not work on the latest iOS.  I lost the lot probably about 40 -> 50 at the time.

I have not used one since.
Back to top
 

So many farkwits, so little time.
 
IP Logged
 
Redmond Neck
Gold Member
*****
Offline


OzPolitic

Posts: 20696
ACT
Gender: male
Re: Password managers
Reply #4 - Oct 17th, 2022 at 2:14pm
 
I have used Roboform for many years ...No Issues so far!
Back to top
 

BAN ALL THESE ABO SITES RECOGNITIONS.

ALL AUSTRALIA IS FOR ALL AUSTRALIANS!
 
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #5 - Oct 17th, 2022 at 2:19pm
 
random wrote on Oct 17th, 2022 at 2:11pm:
Bobby. wrote on Oct 17th, 2022 at 1:30pm:
Who trusts password managers?


Two iphones ago I was using an encrypted one.  It was good, I thought I was clever and organised.

Then I bought a new phone, restored the last backup onto it then dealt with the usual exceptions.  It said that the pwd manager was no longer supported by the supplier and that the last version did not work on the latest iOS.  I lost the lot probably about 40 -> 50 at the time.

I have not used one since.



You were ripped off.
Back to top
 
 
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #6 - Oct 17th, 2022 at 2:22pm
 
Redmond Neck wrote on Oct 17th, 2022 at 2:14pm:
I have used Roboform for many years ...No Issues so far!


https://cybernews.com/best-password-managers/roboform-review/


Is RoboForm safe?

Yes, RoboForm is extremely secure. Its server is encrypted with AES256, which is about the strongest encryption around. All RoboForm data is encrypted and decrypted locally, never on servers. This is the case whether you’re accessing your data via the RoboForm web portal, the local application, or your browser extension. A single master password, which you must set and remember, holds the key to all of your data. Finally, RoboForm has a range of security features to help keep your passwords safe.

This does not mean it is infallible though. Hackers always look for weaknesses while the best password managers fight to improve. The most obvious weakness is the user. After all, if you don’t use a strong master password, or give it up to someone untrustworthy, then you may well be in trouble.
Back to top
 
 
IP Logged
 
Captain Nemo
Gold Member
*****
Offline


Australian Politics

Posts: 8428
Melbourne
Gender: male
Re: Password managers
Reply #7 - Oct 17th, 2022 at 2:35pm
 
Bobby. wrote on Oct 17th, 2022 at 1:30pm:
Who trusts password managers?


I don't trust them, but I do use the Samsung inbuilt one on my phone.

For the PC - I use an ancient piece of software called PassKeep

It encrypts the manually added passwords. I don't trust my banking passwords to a cloud based password store but I have no real alternative for the ones on the phone.


My master password is 16 characters long so it is "fairly difficult" to crack. and no, it is NOT "fairly_difficult"  Grin

129,629,238,163,050,258,624,287,932,416 possible combinations.


Edit: correction, it is 16 characters long.

Back to top
« Last Edit: Oct 17th, 2022 at 3:06pm by Captain Nemo »  

The 2025 election could be a shocker.
WWW  
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #8 - Oct 17th, 2022 at 3:00pm
 
Many years ago I listened carefully to Edward Snowden.
When he worked in the USA for the Govt. -
he was able to read anyone's email in the world – even the POTUS.
Also – any company can be forced by the Govt. to assist them to spy on you.
Read the terms and conditions of any site and there always an admission
that they will comply with all legal requests by Govts. or courts.
You have to assume that your computer and everything you do online
is compromised by Govt. authorities and that hackers can also use
some of their techniques to break in as well since there are
secret back doors on all software – even if indirectly via Windows and Microsoft.
Back to top
 
 
IP Logged
 
Sprintcyclist
Gold Member
*****
Offline


OzPolitic

Posts: 39506
Gender: male
Re: Password managers
Reply #9 - Oct 17th, 2022 at 6:31pm
 
random wrote on Oct 17th, 2022 at 2:11pm:
Bobby. wrote on Oct 17th, 2022 at 1:30pm:
Who trusts password managers?


Two iphones ago I was using an encrypted one.  It was good, I thought I was clever and organised.

Then I bought a new phone, restored the last backup onto it then dealt with the usual exceptions.  It said that the pwd manager was no longer supported by the supplier and that the last version did not work on the latest iOS.  I lost the lot probably about 40 -> 50 at the time.

I have not used one since.


Oh WOW !!!!!!!!!!

I have thought, what if you forget your password manager password?
Back to top
 

Modern Classic Right Wing
 
IP Logged
 
Gordon
Gold Member
*****
Online


Australian Politics

Posts: 20223
Gordon
Gender: male
Re: Password managers
Reply #10 - Oct 17th, 2022 at 6:46pm
 
Captain Nemo wrote on Oct 17th, 2022 at 2:35pm:
Bobby. wrote on Oct 17th, 2022 at 1:30pm:
Who trusts password managers?


I don't trust them, but I do use the Samsung inbuilt one on my phone.

For the PC - I use an ancient piece of software called PassKeep

It encrypts the manually added passwords. I don't trust my banking passwords to a cloud based password store but I have no real alternative for the ones on the phone.


My master password is 16 characters long so it is "fairly difficult" to crack. and no, it is NOT "fairly_difficult"  Grin

129,629,238,163,050,258,624,287,932,416 possible combinations.


Edit: correction, it is 16 characters long.



Snap. I run it from a usb stick and of couse a long pw is needed to open passkeep Smiley
Back to top
 

IBI
 
IP Logged
 
Setanta
Gold Member
*****
Offline


\/ Peace man!

Posts: 15914
Northern NSW
Gender: male
Re: Password managers
Reply #11 - Oct 17th, 2022 at 6:46pm
 
I've been looking at a password manager that doesn't include external(to me and out of my control) data and thought this may be the way to go if you have your own "cloud services" to host it your self..

https://www.xbrowsersync.org/
Back to top
 
 
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #12 - Oct 17th, 2022 at 7:02pm
 
Setanta wrote on Oct 17th, 2022 at 6:46pm:
I've been looking at a password manager that doesn't include external(to me and out of my control) data and thought this may be the way to go if you have your own "cloud services" to host it your self..

https://www.xbrowsersync.org/



You have to ask yourself -
why would anyone spend so much time and effort to
write complicated encryption software and then give it away for free?   Undecided
Back to top
 
 
IP Logged
 
Setanta
Gold Member
*****
Offline


\/ Peace man!

Posts: 15914
Northern NSW
Gender: male
Re: Password managers
Reply #13 - Oct 17th, 2022 at 7:14pm
 
Bobby. wrote on Oct 17th, 2022 at 7:02pm:
Setanta wrote on Oct 17th, 2022 at 6:46pm:
I've been looking at a password manager that doesn't include external(to me and out of my control) data and thought this may be the way to go if you have your own "cloud services" to host it your self..

https://www.xbrowsersync.org/



You have to ask yourself -
why would anyone spend so much time and effort to
write complicated encryption software and then give it away for free?   Undecided


You would have to ask yourself why people publish their code under GPL LGPL or BSD licenses.
Back to top
 
 
IP Logged
 
Bobby.
Gold Member
*****
Online


Australian Politics

Posts: 95264
Melbourne
Gender: male
Re: Password managers
Reply #14 - Oct 17th, 2022 at 7:24pm
 
Setanta wrote on Oct 17th, 2022 at 7:14pm:
Bobby. wrote on Oct 17th, 2022 at 7:02pm:
Setanta wrote on Oct 17th, 2022 at 6:46pm:
I've been looking at a password manager that doesn't include external(to me and out of my control) data and thought this may be the way to go if you have your own "cloud services" to host it your self..

https://www.xbrowsersync.org/



You have to ask yourself -
why would anyone spend so much time and effort to
write complicated encryption software and then give it away for free?   Undecided


You would have to ask yourself why people publish their code under GPL LGPL or BSD licenses.



Would you know if they were opening any ports and
downloading all the secrets from your hard drive including your passwords?
Back to top
 
 
IP Logged
 
Pages: 1 2 3 
Send Topic Print