Live data from Hacker News

PasswordCard

passwordcard.org

11–20 of 31 posts

Re: PasswordCard

#11
I started doing this a while ago. I have some keys to access a building which needs a security code to disable the alarm, so I wouldnt forget it I wrote it on the key tag mixed in with a series of other numbers.

Alternativly I use KeePass to store all my passwords and for the master password I combined all the passwords Ive used over the years, so its about 15 characters long and easy to remember.

Re: PasswordCard

#12
This site reminds me of another site that has been online a lot longer: http://www.passwordchart.com/

Instead of having to store a number to regenerate your card, the card is (re)generated from a "master" password that you can memorize and never write down. You do not even need to print out your card, as you can generate your card online at any time.

I have a friend who uses this service; he has a complicated "master" password and simply uses the site domain ("news.ycombinator.com" for example) for the second field in order to generate the password to use on each site (HN).

For those who have personal policies of regularly changing passwords, just regularly change your "master" password and be sure to update your passwords on all affected sites (keeping your second field the same).

Re: PasswordCard

#13
post #7
post #3

This would be kind of annoying to pick that card every time I want to enter a password.. no? I Like To Take The First Word Of Easy To Remember Sentences. (iltttfwoetrs) and put some random i->1 and a->@ and o->0. This way, it's fairly secure and easy to remember.

Personally, after some silent wonderment, other reasons don't. (I'm sorry, that was awful.)

Passwords are securely structured with only random data.

Re: PasswordCard

#14
Of course, like the site says, a chain is as strong as its weakest link, so saving passwords in chrome/firefox or using the same one for all of them, or being victim to a phishing attack are all still just as vulnerable as they were before

Re: PasswordCard

#15
post #5

or... you just use something like firefox's master password. you can use as many passwords as you can think of, but only have to remember 1 of them.

But what happens when you have to use somebody else's computer? How are you going to log into your super secure email using a stolen cellphone to warn the president about the terrorists, if you have to run back home, log into firefox then get the password?

While that scenario might not be realistic, for this type of thing, you have to plan for worst case scenario of needed to access you services now, without extra tools. Memorizing the password will always be the best, and if you are in situation where you accounts need passwords so difficult you cannot remember them, then you likely will also need to connect to those services at a moments notice. Start with a simpler password and work your way up in length and complexity over time, your memory can get longer with practice!

Re: PasswordCard

#16
post #12

This site reminds me of another site that has been online a lot longer: http://www.passwordchart.com/ Instead of having to store a number to regenerate your card, the card is (re)generated from a "master" password that you can memorize and never write down. You do not even need to print out your card, as you can generate your card online at any time. I have a friend who uses this service; he has a complicated "master…

Thanks for the mention. Its always fun hearing people use passwordchart - I built it in a day in 2006 after reading a story on Slashdot that gave me the idea.

Re: PasswordCard

#17
post #15
post #5

or... you just use something like firefox's master password. you can use as many passwords as you can think of, but only have to remember 1 of them.

But what happens when you have to use somebody else's computer? How are you going to log into your super secure email using a stolen cellphone to warn the president about the terrorists, if you have to run back home, log into firefox then get the password? While that scenario might not be realistic, for this type of thing, you have to plan for worst case scenario of needed to access you services now, without extra to…

I have a workable but annoying solution to this. I have a master email account for every website I'm signed up on. I have the password for that email account memorized and that passwords isn't saved on my computer. If I need access to photobucket when I'm away from my computer (and 1Password) I can reset my photobucket password to a memorized password. Then when I can get access to 1Password, I can login in and change it back.

Re: PasswordCard

#18
post #11

I started doing this a while ago. I have some keys to access a building which needs a security code to disable the alarm, so I wouldnt forget it I wrote it on the key tag mixed in with a series of other numbers. Alternativly I use KeePass to store all my passwords and for the master password I combined all the passwords Ive used over the years, so its about 15 characters long and easy to remember.

Same here. I save it on my dropbox account, just in case I needed access to my password when I am away from my computer.

Re: PasswordCard

#19
I don't like how (i) the card is pseudo-randomly generated and (ii) the people as passwordcard.org potentially have access to the key used to generate it -- it certainly would cut down on the size of the password space that ~they~ would need to search to steal your password; or the space that someone who steals data from them would need to search.
Post reply on HN