Security - Password Security - Unlocked Keyrings

For interesting topics. But remember this is a Linux Forum. Do not post offensive topics that are meant to cause trouble with other members or are derogatory towards people of different genders, race, color, minors (this includes nudity and sex), politics or religion. Let's try to keep peace among the community and for visitors.

No spam on this or any other forums please! If you post advertisements on these forums, your account may be deleted.

Do not copy and paste entire or even up to half of someone else's words or articles into posts. Post only a few sentences or a paragraph and make sure to include a link back to original words or article. Otherwise it's copyright infringement.

You can talk about other distros here, but no MX bashing. You can email the developers of MX if you just want to say you dislike or hate MX.
Message
Author
germany

Security - Password Security - Unlocked Keyrings

#1 Post by germany »

Hi everyone,
I'm starting a new thread because of this posting here: viewtopic.php?p=803036#p803036

I'm a professional computer technician and I've built literally hundreds of machines with Windows and MX Linux for clients as well as businesses. I keep things as secure as requested/needed by a client. But for personal use I keep our personal machines fairly unsafe with login password disabled, screenlock disabled, etc. We don't sync any of our infomation with other computers, web browsers, and most important of all we don't sync anything to our phones. Our internet router uses a 20 character encrypted password (according to hacker conventions anything with 16+ characters/special characters is virtually hack-proof) and we use LAN cables as opposed to WiFi connections.
So my question is this:

Should anyone who uses computers as we do in our household, complete with password protection apps and never saved passwords in a web browser *STILL* make use of the password keyring, and why?

I'm hoping to turn this into a productive debate because different types of people and organizations require different levels of security. Windows does not have some weird keyring password function which causes a message to appear each time a web browser is opened, telling the user that a password key needs to be unlocked. So why does this happen with Linux? And no, before you tell me how terrible Windows is as far as security is concerned, I'll tell you that with decades of experience I have yet to have a single customer who's system got hacked, Windows or otherwise. UEFI has made a huge difference where security is concerned. So have encrypted password phrases with special characters. Where does a user stop worrying about security .... I'm talking primarly about individuals on machines with just that one user, nothing being shared or synced with other users or machines.

.

User avatar
fehlix
Developer
Posts: 12811
Joined: Wed Apr 11, 2018 5:09 pm

Re: Security - Password Security - Unlocked Keyrings

#2 Post by fehlix »

What do you think is Chromiums master key for? Why do they need it?

germany

Re: Security - Password Security - Unlocked Keyrings

#3 Post by germany »

I'm sorry but in context to this thread I do not understand your question. I'm trying to find out how different people perceive security and how different people treat the matter. This has nothing to do with just the Chrome/Chromium keyring.

.

User avatar
CharlesV
Global Moderator
Posts: 7755
Joined: Sun Jul 07, 2019 5:11 pm

Re: Security - Password Security - Unlocked Keyrings

#4 Post by CharlesV »

In today's environment I would never NOT have a password. The ability to loose a machine is too great. (And yes, I have been working with computers for 35 years and also built and support hundreds of computers - still do.)

The reason chrome is asking for passwords is because it wants to have the ability to manage your online passwords. ( bad idea imo ). and there are several way stop it fro asking.

https://easylinuxtipsproject.blogspot.c ... .html#ID15
( or a quick look around on the internet will tell you much more.)

As they say, your mileage may very ... if you have any interest in security then I would strongly suggest a) having a password to get into your computer, b) a second password to get into an encrypted password manager, and then c) use that password manager to handle everything else.
*QSI = Quick System Info from menu (Copy for Forum)
*MXPI = MX Package Installer
*Please check the solved checkbox on the post that solved it.
*Linux -This is the way!

germany

Re: Security - Password Security - Unlocked Keyrings

#5 Post by germany »

Thank you. That makes perfect sense. Of course we have a password manager to manage everything away from the web browsers. Each machine also has it's own password. We just keep the password option disabled most of the time because truly, never ever, is anyone in our home who could muck around with our systems. Nobody. If there's any reason to have strangers or others in the house for a number of hours, then we enable our passwords for reboots, logons, etc. Doesn't take but a minute. ;)
The machines that I build for clients all have passwords but now and then I'm asked to remove even that. At that point I mention the importance of security etc., but end up doing what the client wants. In the end they're responsible for their system, not me.

User avatar
Eadwine Rose
Administrator
Posts: 14999
Joined: Wed Jul 12, 2006 2:10 am

Re: Security - Password Security - Unlocked Keyrings

#6 Post by Eadwine Rose »

Please click the checkmark in the top right of the post (to the left of the username/user image) that holds the solution to mark the topic solved, thanks :)
MX-23.6_x64 July 31 2023 * 6.1.0-37amd64 ext4 Xfce 4.20.0 * 8-core AMD Ryzen 7 2700
Asus TUF B450-Plus Gaming UEFI * Asus GTX 1050 Ti Nvidia 535.247.01 * 2x16Gb DDR4 2666 Kingston HyperX Predator
Samsung 870EVO * Samsung S24D330 & P2250 * HP Envy 5030

germany

Re: Security - Password Security - Unlocked Keyrings

#7 Post by germany »

Eadwine Rose wrote: Fri Dec 27, 2024 12:00 pm Please click the checkmark in the top right of the post (to the left of the username/user image) that holds the solution to mark the topic solved, thanks :)
Hi. This post was actually supposed to trigger some debate / conversation about security. There's not really an actual solution to this since multiple different types of users have different opinions about their security ....

.

User avatar
davidy
Posts: 818
Joined: Sat Jul 03, 2021 1:59 pm

Re: Security - Password Security - Unlocked Keyrings

#8 Post by davidy »

Whenever I open ungoogled-chrome's appimage it asks for the key and I ignore it. I haven't allowed a browser to manage passwords in well over a decade. I reinstalled light-locker recently and then quickly disabled it from startup as I, the only user, don't want to have to login every time the pc starts. But with ight-locker installed I can very quickly change that if needed. I have no idea what the actual keyring password is either and really dont care. I use password safe on every device I own. It works and I can easily share it's db without jumping through hoops or needing an addon or whatever.
Sys76 LemurPro-mx-23.4, EliteMinis HM90-mx-21.3, Deskmini UM350-phoenixLite win10, Qnap 12tb nas, Protectli FW4C-opnsense(=゜ω゜)

zero privacy = zero security . All MX'd Up
UAP = up above people

fan_of_LTS
Posts: 107
Joined: Sat Jun 13, 2020 11:49 am

Re: Security - Password Security - Unlocked Keyrings

#9 Post by fan_of_LTS »

It's important to remember that with security one mistake can be costly. Even if you feel you have no reason to use a password manager or login password now, the practice is useful. Developing good habits can be helpful if your situation changes.

I don't use password managers in browsers either. KeepassXC works well for me. If you have good encryption and passwords don't forget to get good at backups too. ;)

User avatar
davidy
Posts: 818
Joined: Sat Jul 03, 2021 1:59 pm

Re: Security - Password Security - Unlocked Keyrings

#10 Post by davidy »

Isn't the right to privacy in the constitution? When we the people take that entirely back and enforce it we will gain all the security you never thought you needed. All the insecurities in everything will simply vanish as if by magic.
Sys76 LemurPro-mx-23.4, EliteMinis HM90-mx-21.3, Deskmini UM350-phoenixLite win10, Qnap 12tb nas, Protectli FW4C-opnsense(=゜ω゜)

zero privacy = zero security . All MX'd Up
UAP = up above people

Post Reply

Return to “General”