Welcome, Guest. Please login or register.
July 24, 2025, 08:40:23 PM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Serious Business  |  Topic: Useless Conversation 0 Members and 4 Guests are viewing this topic.
Pages: 1 ... 596 597 [598] 599 600 ... 1141 Go Down Print
Author Topic: Useless Conversation  (Read 4176257 times)
Hammond
Terracotta Army
Posts: 637


Reply #20895 on: August 10, 2012, 05:37:24 PM

Shrug all you would need to do is compromise the webpage for a short period.  When I was working in the ISP / webhosting world I saw more than a few websites compromised over the years without people noticing.  Heck l have seen servers owned 3 ways to Sunday without people noticing for months.  You could make the change in the backend in such a way that antivirus scanners would never be triggered.   So it would be up to the hoster / sysadmins to catch it.  That being said you are right it is probably a small chance of it happening. 

Really you have to weight the risk / rewards to figure out if it is worth it to  you.  The benefits of a cloud based password manager is essentially nil to me so I do not see creating any risk of potentially getting compromised.

On that note thank god this week is done.  I am going to sit down and enjoy a beer and some TSW
Lantyssa
Terracotta Army
Posts: 20848


Reply #20896 on: August 10, 2012, 06:19:07 PM

I can see how a completely server-side solution (which sounds like Lastpass) would be a little more troubling since in theory somebody could hack Lastpass and replace their server software with something that steals your master password when you enter it.  That's a pretty big stretch from any security breach we've seen so far, though (it's one thing to get a copy of a database, entirely another to actually replace the live page that clients use without anyone noticing).  While it's possible for something like that to happen, I can't imagine that it'd go for very long before someone pulled the plug, and you as a user would only be compromised if you had the bad luck to access the site and give it your master password during that window.  Since, again, assuming they at all know what they're doing, the database is all encrypted.
If they brute-force your master password, then they'll have everything.  These programs may not store the password itself, but the hash is reproduceable if they get the correct phrase.  Maybe some are better than others, but I know with Password Safe if I move the file from machine to machine, I can open it using the individually installed programs.

Hahahaha!  I'm really good at this!
bhodi
Moderator
Posts: 6817

No lie.


Reply #20897 on: August 10, 2012, 06:55:18 PM

Shrug all you would need to do is compromise the webpage for a short period.... Lastpass and replace their server software with something that steals your master password when you enter it.
You still aren't understanding the technology or even basic cryptography. No passwords are uploaded or transmitted in raw form. The file is encrypted on the client and then the encrypted file is uploaded. The entire point of modern cryptography is that without the password, the bits are useless. You must have the master password to unencrypt and the ONLY way to get it is through a local keylogger when you type it in, someone looking over your shoulder, or a lead pipe to your knee.

It literally does not matter if they man in the middle, hijack your session, redirect through DNS poisoning, or even break into the server room and flat out steal the hard drives containing the file in which your passwords are stored. It doesn't matter if you email the file to yourself at mailinator.com or print it out in hex and put it on craigslist. Without a NSA supercomputer brute forcing it (or an undisclosed flaw in the encryption technology) your shit is safe once it's encrypted and the file is closed and out of memory. Period.

Because memory reading and keyloggers are basically the only realistic vector, most of the programs go the extra step to watch for and defeat the common hooks those programs use. Nothing is absolutely safe, but you continue to dwell on a security threat that literally does not exist. You now have THREE people trying to explain this to you.
« Last Edit: August 10, 2012, 06:59:19 PM by bhodi »
Furiously
Terracotta Army
Posts: 7199


WWW
Reply #20898 on: August 10, 2012, 07:09:18 PM

Why is this better than me using a different, hard to figure out password, writing them on a piece of paper and putting them all into a Steven King book on my bookshelf?

Morat20
Terracotta Army
Posts: 18529


Reply #20899 on: August 10, 2012, 07:32:41 PM

Two-factor authentication or some variant of asymmetric keys. And sooner or later, biometrics. I suspect the future of password security is closer to how we handle certificates than passwords.

Wherein basically anyone wanting to know "Is this Morat" goes to the certificate authority and verifies me against that, using the (partial) key I gave it.  Which is effectively what those password managers use, but designed correctly each and every password for each and every website would be different (basically public-key encryption, just large scale).

I know my private key, I shake hands with the certificate authority who knows (say) Amazon's public key. Amazon has a public/private key with the certificate authority.

Kinda a monopoly (or very few centers) solution, though. Of course if you steal my private key I'm fucked, but if you add to the private key a token (like an RSA ID or biometric) they'd have to have my private key AND my token -- or fingers or whatnot).

If the Password authority is hacked you're fucked, since a hack there fucks everyone, but at least the response would (theoretically) be swift and encompassing, and a reset would at least resecure everything, including places you haven't used in years.
Hammond
Terracotta Army
Posts: 637


Reply #20900 on: August 10, 2012, 08:14:56 PM

Bhodi,

I think there is a mis-understanding somewhere.   My last response was to Samwise which was on the previous page.  iI was his comments on how to compromise the website itself.  As far as the technology behind lastpass  I understand it just fine and I understand both the strengths and the weaknesses.  

In my statement  I am talking about is them capturing your password to the lastpass.com website itself and getting a copy of your encrypted data.  This is only a problem if someone is using a weak password of course which someone could then bruteforce.  

On a side note why did you merge both samwise and my quotes?

Shrug all you would need to do is compromise the webpage for a short period.... Lastpass and replace their server software with something that steals your master password when you enter it.

Edit to add
Apparently Lastpass could have been a victim of hacking last year.  No details but this is a interview with the CEO.
http://www.pcworld.com/article/227268/lastpass_ceo_explains_possible_hack.html
Looks like it was just a few people that had potentially been hacked.  I cannot for the life of me find a followup article with a better explanation. 
« Last Edit: August 10, 2012, 08:20:40 PM by Hammond »
Hammond
Terracotta Army
Posts: 637


Reply #20901 on: August 10, 2012, 08:32:23 PM

Why is this better than me using a different, hard to figure out password, writing them on a piece of paper and putting them all into a Steven King book on my bookshelf?

Convenience really. You have one place on your computer to store the passwords so you can paste them directly into website if you want.
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #20902 on: August 10, 2012, 08:57:35 PM

Maybe KeePass requires a bit of reading to set up, but the convenience of pressing CTRL-V and it logging me into things is pretty nice.  I do still put some passwords into text files; it's all relative.

Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
Ironwood
Terracotta Army
Posts: 28240


Reply #20903 on: August 11, 2012, 12:35:23 AM

I forgot our anniversary.

Shit.


"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Trippy
Administrator
Posts: 23657


Reply #20904 on: August 11, 2012, 12:37:34 AM

ACK!
Signe
Terracotta Army
Posts: 18942

Muse.


Reply #20905 on: August 11, 2012, 12:43:30 AM

I forgive you.  Don't know if your wife will though.

My Sig Image: hath rid itself of this mortal coil.
Ironwood
Terracotta Army
Posts: 28240


Reply #20906 on: August 11, 2012, 12:52:45 AM

Indeed.

I'm in such trouble.

"Mr Soft Owl has Seen Some Shit." - Sun Tzu
Signe
Terracotta Army
Posts: 18942

Muse.


Reply #20907 on: August 11, 2012, 01:37:11 AM

Heart my new shoes.




Didn't there used to be a shoe thread around here?  There must have been.  I never go anywhere without shoes.

My Sig Image: hath rid itself of this mortal coil.
Furiously
Terracotta Army
Posts: 7199


WWW
Reply #20908 on: August 11, 2012, 02:34:19 AM

What socks would you wear with those?

IainC
Developers
Posts: 6538

Wargaming.net


WWW
Reply #20909 on: August 11, 2012, 05:13:41 AM

Holy shit it's Signe!

 Heart

- And in stranger Iains, even Death may die -

SerialForeigner Photography.
Lantyssa
Terracotta Army
Posts: 20848


Reply #20910 on: August 11, 2012, 06:46:31 AM

Sweet walk.

Hahahaha!  I'm really good at this!
MuffinMan
Terracotta Army
Posts: 1789


Reply #20911 on: August 11, 2012, 07:06:05 AM

I don't think I'd wear shoes if I were a zombie. I probably wouldn't even wear clothes, fuck it.

I'm very mysterious when I'm inside you.
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #20912 on: August 11, 2012, 08:54:00 AM

I forgot our anniversary.

Shit.



I'd love to give advice, but frankly you're inside the event horizon and my voice would seem unintelligible as you are spaghettified in your descent.  From my experience, there isn't a card for "Sorry I Forgot Your Birthday" or a "Sorry I Forgot Our Anniversary" or "You Said You Didn't Want A Gift".

Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
JWIV
Terracotta Army
Posts: 2392


Reply #20913 on: August 11, 2012, 08:56:47 AM

Signe
Terracotta Army
Posts: 18942

Muse.


Reply #20914 on: August 11, 2012, 09:25:43 AM

What socks would you wear with those?

?

My Sig Image: hath rid itself of this mortal coil.
Soln
Terracotta Army
Posts: 4737

the opportunity for evil is just delicious


Reply #20915 on: August 11, 2012, 09:29:26 AM

RhyssaFireheart
Terracotta Army
Posts: 3525


WWW
Reply #20916 on: August 11, 2012, 10:28:37 AM

Holy shit it's Signe!

 Heart
I thought I was seeing things and had to double-check the date.

proudft
Terracotta Army
Posts: 1228


Reply #20917 on: August 11, 2012, 11:06:59 AM

It's not even 2014 anymore.
Nebu
Terracotta Army
Posts: 17613


Reply #20918 on: August 11, 2012, 11:45:03 AM

Holy shit it's Signe!

 Heart

YAY!  Heya Signe!  Heart

"Always do what is right. It will gratify half of mankind and astound the other."

-  Mark Twain
cmlancas
Terracotta Army
Posts: 2511


Reply #20919 on: August 11, 2012, 12:26:34 PM

Weird.  Signe and I come back in the same week?

Granted, I'm nowhere near an f13 superhero like she is.   Heart

f13 Street Cred of the week:
I can't promise anything other than trauma and tragedy. -- schild
Signe
Terracotta Army
Posts: 18942

Muse.


Reply #20920 on: August 11, 2012, 02:07:02 PM

 Heart I'm not a superhero, YOU'RE a superhero. Heart

My Sig Image: hath rid itself of this mortal coil.
Xuri
Terracotta Army
Posts: 1199

몇살이세욬ㅋ 몇살이 몇살 몇살이세욬ㅋ!!!!!1!


WWW
Reply #20921 on: August 11, 2012, 02:16:47 PM

Welcome back to the both of you! :) Yahoo!

-= Ho Eyo He Hum =-
cmlancas
Terracotta Army
Posts: 2511


Reply #20922 on: August 11, 2012, 02:19:11 PM

Heart I'm not a superhero, YOU'RE a superhero. Heart

Was I inadvertently sexist there?  Fine, fine.  Superheroine!   DRILLING AND WOMANLINESS

f13 Street Cred of the week:
I can't promise anything other than trauma and tragedy. -- schild
Strazos
Greetings from the Slave Coast
Posts: 15542

The World's Worst Game: Curry or Covid


Reply #20923 on: August 11, 2012, 03:32:42 PM

I thought I was seeing things and had to double-check the date.

Heh. +1  Oh ho ho ho. Reallllly?

Fear the Backstab!
"Plato said the virtuous man is at all times ready for a grammar snake attack." - we are lesion
"Hell is other people." -Sartre
proudft
Terracotta Army
Posts: 1228


Reply #20924 on: August 11, 2012, 03:39:21 PM

I thought Nerf's dog was the superhero?

Lantyssa
Terracotta Army
Posts: 20848


Reply #20925 on: August 11, 2012, 06:09:31 PM

Nah, he's Wonder Mutt.

Hahahaha!  I'm really good at this!
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #20926 on: August 11, 2012, 08:15:40 PM

Weird.  Signe and I come back in the same week?

Same day.

Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
Sky
Terracotta Army
Posts: 32117

I love my TV an' hug my TV an' call it 'George'.


Reply #20927 on: August 11, 2012, 09:50:33 PM

Don't forget tonight is peak Perseids, best just before dawn.
murdoc
Terracotta Army
Posts: 3037


Reply #20928 on: August 11, 2012, 11:02:55 PM


Have you tried the internet? It's made out of millions of people missing the point of everything and then getting angry about it
Xanthippe
Terracotta Army
Posts: 4779


Reply #20929 on: August 12, 2012, 09:18:26 AM

I forgot our anniversary.

Shit.



Both my spouse and I forgot our 20th. We usually forget anniversaries, so we forgive each other.

You could try "Every day is an anniversary" and bring her flowers at irregular intervals.
Pages: 1 ... 596 597 [598] 599 600 ... 1141 Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Serious Business  |  Topic: Useless Conversation  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC