Forums

Supt Centre Fdbk: Security

Quick find code: 278-279-337-66275732

Applejuiceaj
Nov
fmod Member
2011

Applejuiceaj

Forum Moderator Posts: 44,941 Sapphire Posts by user Forum Profile RuneMetrics Profile
This is feedback on the Security Tips Support Centre page. There doesn't appear to be a dedicated place to provide feedback on the Support Centre these days, so I figured I'd put it here.

In particular, my feedback is regarding the 'Set a Unique Password' heading and the callout of password managers.

I don't have an issue with suggesting using a password manager - having a system that can securely manage your passwords and automatically create unique, complex passwords is a good thing to have. Its good to see that using one is suggested both there as well as in the Jagex Account FAQ that was posted in the announcement of the Jagex Account system on 26th January.

What I do have an issue with is the particular recommendation of what to use. The Security tips page specifically links to Lastpass, a password manager that has been in the news a number of times over the past year (most recently this week) for a security breach that keeps getting worse and worse. In my eyes, it is a horrible idea to have an official page recommending a product with a breach as severe as the one they have had.

Instead of linking to a specific password manager provider, it may be best if instead this page links to an overview of what password managers are, the different types of managers (cloud vs. local) and the benefits they might be able to provide to the user, while allowing the user to research and select one to use that best fits their need.

03-Mar-2023 00:15:57

Immortalized
Mar Member 2006

Immortalized

Posts: 34,061 Sapphire Posts by user Forum Profile RuneMetrics Profile
lastpass is terrible. a long time ago i was in a startup intended to compete with lastpass, and some of the practices we were made aware of were shocking to say the least. i assume that the engineers there are not very skilled in web development. most shocking one i saw is it submitting your password to another site, absolutely insane and made me lose trust instantly. Buy Zemomarks / Chromatic Partyhats safely here

03-Mar-2023 02:41:36

Applejuiceaj
Nov
fmod Member
2011

Applejuiceaj

Forum Moderator Posts: 44,941 Sapphire Posts by user Forum Profile RuneMetrics Profile
Its more than just inputting passwords manually.

With security guidance suggesting that we use unique, complex passwords for every site that we have an account on, it isn't practical to memorize every password that we use. It isn't safe to use the same password everywhere (which is what many people do). Password managers can create completely randomized passwords that you don't need to remember because they handle the storage of it. For example, the upcoming Jagex Account system FAQ says it allows for passwords of up to 64 characters in length and now allows uppercase letters and symbols previously not supported - you could create a very strong randomized password of that length, but it may be tricky to remember.

In theory, if a password manager is used correctly, our accounts across the internet will be more secure. But of course, the database which stores the password needs to be kept secure too. That's where the current problem is - Lastpass' breach showed that their database (at least at the time) wasn't properly secured, and it makes no sense to suggest a product that can't keep info secure.

There are 'local' based password managers that don't rely on the cloud for those that prefer to manage things themselves (where the security of the database is left to the user to keep secure, rather than a cloud provider at the exchange of only being able to access it on devices with local access to the database) but that's something that really should be left to each person to decide what 'risk' they want to take.

The tl;dr - if a password manager is going to be suggested, it should be one that can maintain a user's trust. I don't feel Lastpass should be the one suggested given recent events, and instead its better if people can do their own research and make their own decision on what they feel is best for them.

04-Mar-2023 16:02:32 - Last edited on 04-Mar-2023 16:04:21 by Applejuiceaj

Spearmint30
Apr Member 2012

Spearmint30

Posts: 23,350 Opal Posts by user Forum Profile RuneMetrics Profile
Good points, Apple.

Perhaps it might be best to avoid suggesting password managers in the article - simply because things can change so fast. Maybe replace it with a blurb about password managers for people who don't know, and guiding them to do their own research at the time of their exploration of the subject to find the best options.

Due to the circumstances you've pointed out in your thread here, the best manager available today.... might not be a good choice anymore tomorrow.
Spearmint30

¤
Food scientists have finally managed to remove the mint flavor from gum! The ex-spearmint was a success!
¤

04-Mar-2023 18:35:42

Quick find code: 278-279-337-66275732 Back to Top