Live data from Hacker News

Write your passwords down

blog.jgc.org

1–10 of 125 posts

Re: Write your passwords down

#3
This is and isn't bad advice. Writing your passwords down and storing them in your wallet isn't necessarily a good idea. You may be able to secure your wallet, but there may be somewhere better to secure it (such as a house safe).

Rather than writing the passwords down, use a decent tool like 1password (http://agilewebsolutions.com/onepassword) or Keepass (http://keepass.info/).

Re: Write your passwords down

#4
Use 1Password, make sure your passphrase for that is long enough to be secure.

Write that passphrase down and put it in a safety deposit box if you want people to be able to retrieve them after you die.

Re: Write your passwords down

#6
In related news, when I'm on a non essential site that requires a password, forces a weird restriction ("Your password must contain at least one number and one non word character) and won't let me save it in Firefox, I just copy the password, log out, bookmark the login page and then add #password to the URL and bookmark that as the new login page.

Then, come login, I can just copy the password from the URL.

Re: Write your passwords down

#7
Its funny I worked for a startup that got acquired by Comcast, and eventually we started having to follow the Comcast security policy which made us change domain passwords every month with requirements around using strange characters etc.

I'd say about 50% of the people ended up with their current password on a post-it on their monitor or desk.

Re: Write your passwords down

#8
I wouldn't store passwords in my wallet either and find this system far too cumbersome. I think if you're really concerned about security, you should never "remember" your password on any site -- see story about stupid criminal who stole a Washington Post reporter's laptop and posted photo of himself on the reporter's son's Facebook page: http://blog.washingtonpost.com/story-lab/2010/12/post_4.html (the security of the teen's FB page isn't getting the same play as the stupid criminal angle).

Re: Write your passwords down

#9
Personally I don't see any reason for having them completely randomly generated.

'thIs1smyp4ssw0rd19%2' isn't any less secure than another 20 character password that includes lower+upper case letters, numbers and special characters.

Obviously, if you do something like 'c0r1np4ssw0rd" then it may get to the stage where enough people do that for crackers to expect it (maybe it already is, but as long as you follow his third and fourth rules ("Use mixed-case, numbers and special characters" and "Use passwords of at least 12 characters") you really should be fine, and you'll have an easier time memorising them.

(I can remember multiple 20+ character passwords that would be very difficult to crack, and have no need to write them down.)

Re: Write your passwords down

#10
post #9

Personally I don't see any reason for having them completely randomly generated. 'thIs1smyp4ssw0rd19%2' isn't any less secure than another 20 character password that includes lower+upper case letters, numbers and special characters. Obviously, if you do something like 'c0r1np4ssw0rd" then it may get to the stage where enough people do that for crackers to expect it (maybe it already is, but as long as you follow his…

The problem with this approach is that you can only remember a few passwords like this, which means that you are going to reuse passwords on multiple sites. One site compromise can compromise multiple accounts for you.
Post reply on HN