Following the news that Opera, the Norway-based internet browser maker, has confirmed that a hacker breached one of the company’s sync servers, potentially exposing passwords, IT security experts from Rapid7 and Centrify commented below.
Corey Williams, Senior Director, Products and Marketing at Centrify:
Knowing that 2/3 of consumers are ‘likely’ to stop doing business with a hacked organisation, it may mean turbulent waters for Opera in the months to come.”
Tod Beardsley, Senior Research Manager at Rapid7:
While Opera has not gone public with the implementation details of how shared passwords are stored, cryptographic best practices state that it shouldn’t matter to the defender if the attacker knows how secrets are kept; the only secret part should be the decryption key. Regardless, Opera developers reported in 2015 that they’re using the Nigori protocol for password encryption, according to this developer blog post..
People with privacy concerns about syncing passwords across devices should investigate separate, standalone password managers that are purpose-built with security in mind. Offerings from 1Password, LastPass, and other password management vendors tend to be open about critical implementation details, which is an important feature of best cryptographic practices. Browser-based storage for credentials is certainly convenient and better than reusing the same three to four passwords everywhere, but password managers are nearly always going to employ more secure designs and offer more secure features like random password generation and password expiration.”
The opinions expressed in this post belongs to the individual contributors and do not necessarily reflect the views of Information Security Buzz.