I use a password manager on my Windows PC. Currently, I have the manager time out after 'x' seconds of inactivity. The story I'm telling myself is that my passwords are safer if only decrypted briefly when I actually need them, and then locked at other times.
Whether this is true, depends on the environment, so I'll explain mine:
- PC is at home
- Everyone in my house is fully trusted
- However, computer could be physically stolen if someone broke in
- Possibly malware from the net could exist on the computer (even though I have a virus scanner)
Is there added security by keeping secured data on the computer locked, and then unlocking it only when necessary?
As a second example, let's assume I have two drives on the same PC: Drive 1: encrypted with BitLocker sitting behind a Windows login password (unlocked 12 hours a day whenever I'm logged into Windows and using my computer, and locked whenever I'm not using it). Drive 2 encrypted with TrueCrypt, that is only unlocked briefly when I need it (5 minutes a day). The TrueCrypt drive times out and relocks on inactivity . Does the timeout on the TrueCrypt drive make it a safer drive to store my secrets on than the BitLocker drive, which is unlocked whenever I'm present at the computer? Or if I unlock a drive at all on the computer (even briefly), is it fully exposed anyway?
I'll attempt to answer my own question to give you insight into what I'm thinking
- If you've got a keylogger on your computer, timeouts are irrelevant, because everytime you unlock your password manager/TrueCrypt drive, you're giving away your password.
- Timeouts will help protect you (somewhat) from new malware that arrives on your computer, that is yet undetected. The probability is that your TrueCrypt drive/password manager (only decrypted on demand) is locked most of the time. If the malware is scanning your hard drives and uploading the contents to some evil site, it might not even be specifically looking at what you're doing for the few minutes you unlock your secrets. By keeping your secrets locked most of the time, you dramatically increase the chance that they will remain safe, even on an infected computer.
- Timeouts are not important if your computer is stolen. Either system requires a password if the computer has been disconnected from the power.
So do you agree that security timeouts are worthwhile in the scenario I've described? Or do you think that if you unlock a password manager/encrypted drive on a PC at all, that it's been fully exposed, so it may as well be left open all the time (when you're logged into your computer) anway?
submitted by [comments]
SOCIAL SHARE CARD GENERATOR