Re: password-store /dev/shm mfs

broke <[email protected]>
Newsgroups gmane.os.openbsd.misc
Message-ID <[email protected]>
I fail to understand why people use password-store or any standard
password management tools in the first place, there are too many
unknown variables and perhaps a security nightmare.

Your threat model is different and something like password-store has
no way to know that. If you know your threat model, you should know
how to store and secure your passwords.

Without a threat model, thinking of scenarios most likely to not ever
happen is not productive. Here if you want to avoid persistance storage,
but yes for what reason? you don't have full disk encryption? does your
threat model has an attacker that will be able to steal your password
disk? Does this attacker have a relation with you? If so will most
likely try to get the private key out of you by force, which to most
likely you are going to reveal it.

If you have a threat model of an unknown attacker, then again think
about what makes sense, in case of theft, if they care about what
you are hiding, or they know you are rich and want to get out the
banking password, they will have to open the FDE, which is in itself
a massive hurdle, and if they pass, in that situation you need to
encrypt your passwords in the fs as well.

This mechanism of using /dev/shm or a ramfs is stupid, and does not
make any sense. Use FDE and have a good way of locking the FDE as well.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.