Live data from Hacker News

You have exactly three passwords, don't you?

pcmag.com

41–50 of 86 posts

Re: You have exactly three passwords, don't you?

#41
post #15

Earlier quoted context omitted.

This is why I always keep my encrypted keyfile on DropBox (usually a KeePass safe and a standalone installation of PasswordSafe USB mode). This way, you can access your passwords from home, work, or your phone as long as you trust the machine you're logged into enough to log into DropBox and type your password safe password. If you can't tell if the machine is free of keyloggers, you probably shouldn't be logging int…

this. I use Dropbox with Keepass and Truecrypt. You can get these apps anytime from the web, put on USB keychain, or just remember Dropbox and run Keepass and Truecrypt from there. Just make sure to have a very long/secure Dropbox password, as that becomes the weakest link. There's also Dropbox and Keepass for Android.

I use Keepass, but thought it took care of encryption for me. Is there a compelling reason to use additional encryption...?

Re: You have exactly three passwords, don't you?

#42
I'm the person who wrote the comment on Troy's blog about the common 3 password approach, which I suppose inspired the title. What PC Magazine did not write was that I describe how hackers easily exploit it, here:

http://www.filterjoe.com/2010/05/14/the-usual-way-to-manage-...

It's part of a password series with the following central advice for typical home users:

"Use a password manager to assign unique, random 15 character passwords for all accounts, protecting them with a strong master password."

This guide gets them started:

http://www.filterjoe.com/2011/04/14/passwords-guide-without-...

While I'm sure the typical Hacker News community member practices far-above-average password security, the vast majority of people don't see any reason why they should - or if they do, they get overwhelmed by too many complicated rules. From feedback I get, the above referenced guide works for the "average Joe."

Re: You have exactly three passwords, don't you?

#43
post #18

I use one password per account. I have a common shared suffix like "HuRf!z0" and then I prepend a prefix depending on the website, like "gm" for HN. So far, this has been quite simple to use, even when I am not in front of my machine.

Isn't this vulnerable to someone guessing the prefix if the password is compromised? This assumes that you're up against identity theft, not automated spamming, but the algorithm you're using to hide the prefix isn't very robust. Does this matter to you?

This isn't the actual algorithm I am using, but was just an example to make my point.

But true, this isn't perfect, but just makes one step more complex, without having to use an external password manager...

Re: You have exactly three passwords, don't you?

#44

The problem with password managers is, when you're away from whatever machine you managed to get the thing set up on, you're locked out of all your accounts.

Do browsers sync these yet? I know Chrome, Firefox et al. have various syncing options, but I've never looked into how they work exactly. Edit: looked into it, and the situation for password sync is - Chrome: built in since V. 11 - Firefox: available through add-ons/extensions (XMarks) - Opera: since beta 11.5 (the latest as of right now) - Safari: available through extensions/other services (mobileme? not sure) - IE…

Re: Safari, yes, you can have MobileMe sync your keychain, which contains your saved login info, etc.

Re: You have exactly three passwords, don't you?

#45
I'm a bit different. I have approximately 10 important passwords that are only in my dead and are between 20-40 characters long. They are completely nonsense phrases with numbers. I noticed that if I make them nonsense I tend to memorize them better. For the rest of non-important stuff I use a password manager.

Funny note* Once I decided to change my passwords for 2 encrypted drives and a couple of days later I forgot them, so I lost all the information. I recovered some of it cause I also stored it on some non-encrypted drives but still, I learned my lesson. The brain has its shortcoming too. :)

Re: You have exactly three passwords, don't you?

#46
post #19

Some systems don't require a complex password. I don't care if someone breaks into the game center thing on the iphone because my password is prettypony2 - what are they going to do, erase my high scores on Tetris? I'm sure as hell not copying and pasting a 16 character password between the LastPass app every time.

Given that the gamecenter password is the same as your iTunes / Apple account password, they could wipe out your account balance by buying / renting things. If you have any card details stored then they could go onto the Apple Store and order using those. They could see your billing address, and so intercept your mail, thus gaining more documents to eventually steal your identity. Of course, if you only buy using the…

Not entirely true, Game Center can be setup to use a separate Apple Account than the rest of the phone…

Re: You have exactly three passwords, don't you?

#47

The problem with password managers is, when you're away from whatever machine you managed to get the thing set up on, you're locked out of all your accounts.

Keyloggers exist. Ergo, you shouldn't ever type an important password into a machine that doesn't belong to you.

Fortunately, as others have pointed out, it isn't 1990 anymore and I carry a mobile computer wherever I go, disguised as a phone.

Re: You have exactly three passwords, don't you?

#48

Is there any reason for the often-repeated advise to change pws regularly? If I have a unique password like vdknzB4XoAiJIpjlN3PGf for every account, what would changing it protect me against? Hardly keyloggers, because then changing it twice a year is probably too late.

The only reason you would want to do this is if you use the same password for multiple things. You may have signed up with some website a year ago, used it once and then forgot all about it. If they get compromised you might not even know it.

If you change your passwords often then you don't need to worry about this as much.

Re: You have exactly three passwords, don't you?

#49
I thought the second part of his conclusion was a bit hasty:

"... and change all your logins every six months at least."

Does he have any idea how impractical this is? If I could even remember every login I ever made, it would probably take more than 12 hours to do the manual labor of changing the password for them. No thank you!

Re: You have exactly three passwords, don't you?

#50

Is there any reason for the often-repeated advise to change pws regularly? If I have a unique password like vdknzB4XoAiJIpjlN3PGf for every account, what would changing it protect me against? Hardly keyloggers, because then changing it twice a year is probably too late.

I always related it to the military practice of issuing new codebooks periodically. For one concrete example, the Japanese changed their codes right before the Battle of Midway, so the US was not able to under any of the messages sent during the battle. Unfortunately for the Japanese, the US already had enough information from cracking the former Japanese code that this really did not matter.
Post reply on HN