Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

so if someone wants access to all your passwords, he just needs to compromise your dropbox.


dropbox plus either passphrase brute force (or guessing), or one of (keylogger, compelled disclosure, shoulder surfing, ...) + dropbox.

I consider the 1Password file sensitive enough that it shouldn't be online, especially not with dropbox. I'd prefer if there were physical protection for it somehow, too (like a smartcard or FIPS module, which wouldn't allow bulk-export normally, and which might impose other rules on use like 5 passwords per hour when outside my home network, etc.) Same way you handle high-security private keys.

(Ultimately I'm not going to be happy until I have a trusted tablet of some kind, but building that either requires being Apple or waiting for WP8 hardware to come out and investing about $5mm in some serious security upgrades. Maybe worthwhile, though, since it solves the general problem of trusting client devices.)


Now sure if PasswordSafe allows using key file, as sbov mentioned above for Keepass, but if it's properly implemented, and you didn't put the key file into Dropbox, it would be pretty much impossible to brute force.


If it works at all like 1Password…no. Not if you have even a half-decent master password.


Something that has happened in the past on more than one occasion.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: