Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

aka 1PointOfFailure. Having spent several years maintaining and repairing computer systems for corporate and professional clients, I can tell you from experience that it is trivially easy to social engineer someone's credentials out of them.


AKA 1FailureToUnderstandTheThreatVector, the common antisecurity argument of lazy or pedantic people. A password manager is not defending against a social engineering attack (how could it?), it's defending against Joe's Blog getting knocked over and your re-used password on Wells Fargo being disclosed.

Your comment is a really lame excuse for not using a password manager and is quite a bit of FUD; there is no technical solution to a social engineering attack, so it's a clever way out as an excuse to avoid doing something difficult. You are not the first person to try it on me. You also sound like you're making the case for social engineering control of their machine, at which point what does the password manager matter? You have physical. Game over.

I have this conversation regarding self-signed certificates and MD5 hashing as well. "But they don't authenticate," or "but MD5 is insecure!" Yep, I know. Do you understand the threat vector for my usage of either? You sure?

Just use one. Seriously.


I'm at a loss as to what benefit I'm supposed to gain by using one. I don't reuse passwords for anything that actually needs to be secure, though I reuse a few for sites that make me create a password even though I don't care about whether those accounts are secure or not. I dpn't see why I should adopt a password manager just because other people don't practice good password security.


How do you remember all of your passwords?


I'm currently having a failure of imagination here, but how would you social engineer a password manager?

The tricks I'm thinking of involve fooling the user into thinking a site is something it's not or guessing some sort of personal information. But with a separate application the former seems unlikely and the latter is stopped if you use a scheme such as diceware (https://en.wikipedia.org/wiki/Diceware). I understand that naive, theoretical musings on security are no match for experience, so how would you break that set up?


By getting the user to give me control of it, same as if the user was moving everything to a new computer. You don't have to do this via a website; you use a website to create a problem and then make yourself available to fix it.

Not that I'm into this sort of thing, but I've had a few people attempt to co-opt me into criminal activity in the past so I wouldn't be at all surprised to read about such attacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: