Live data from Hacker News

Write your passwords down (2010)

blog.jgc.org

151–160 of 196 posts

Re: Write your passwords down (2010)

#151
post #11

Algorithmically generated passwords for different sites was a mind-blower. There are so many differentiation algorithms that are trivially runnable in your head. If most sites are salting and hashing passwords correctly (this is 2023...), then that drastically decreases your compromised credential blast radius. -- And it makes me sad that "store your passwords on dead-tree paper" became GOTO. It has serious weaknesse…

Bitwarden. Its dead simple and cross-platform + regularly audited. And either FREE or $10 a year for 2FA and some other nice to haves. Obviously there's other choices for those who want more control over it but you can't go wrong with BW.

2FA in the same app as your password defeats the point doesn't it?

Re: Write your passwords down (2010)

#152

Unless you are a high profile target, the risk of someone burglarizing your house without you knowing it and actually making use of a password book is virtually nil. Plus, you should really keep a physical copy of your passwords anyway in case something were to happen to you and your loved ones need access to your accounts, insurance, banking, photos, etc.

When my brother died suddenly, recovering his passwords was a nightmare. Especially for accounts he managed for his wife’s dental business. Fortunately his son and I were able to guess his main password and a few others. We also found that he was reusing a small set of passwords. We finally were able to get into all of the relevant accounts and then wrote everything down and gave it to his wife. Not a fun process. We…

When it comes to a Stash of Secrets to be only posthumously available, two approaches come to mind:

1. Some arrangement with a law-firm so that your Stash of Secrets will be delivered to your executor in the event of your death, where you trust they won't peek because of financial/legal relationships.

2. A way to unlock your Stash of Secrets that requires a certain portion of keys to be brought together, and you give out keys to different people. (People you trust enough not to all conspire together, but who also are unlikely to pass away the same time you do.)

The latter, secret sharing[0], is obviously more algorithmically-interesting. The simplest approach would be two keys that XOR together to reveal the key needed to decrypt the Stash of Secrets.

That said, don't let perfect be the enemy of good! At the very least proactively set up other people as "beneficiaries" at major institutions in the event of your death, and at least provide them a list of what institutions or accounts exist even if they don't have the credentials to control them now.

[0] https://en.wikipedia.org/wiki/Secret_sharing

Re: Write your passwords down (2010)

#153

It makes me so sad that it's 2023 and we haven't fixed passwords. There's no need for any of this. Your email account (+ multi-factor as desired) will always be the weak link, so just reduce everything to that. Get rid of passwords. Create a new standard that falls back to passwords to work with legacy systems, but going forward will enable a password keepers to just authenticate you with a generated random password…

[deleted]

Re: Write your passwords down (2010)

#154

Unless you are a high profile target, the risk of someone burglarizing your house without you knowing it and actually making use of a password book is virtually nil. Plus, you should really keep a physical copy of your passwords anyway in case something were to happen to you and your loved ones need access to your accounts, insurance, banking, photos, etc.

When my brother died suddenly, recovering his passwords was a nightmare. Especially for accounts he managed for his wife’s dental business. Fortunately his son and I were able to guess his main password and a few others. We also found that he was reusing a small set of passwords. We finally were able to get into all of the relevant accounts and then wrote everything down and gave it to his wife. Not a fun process. We…

I went through something similar when my SO's dad passed. Her mom is not tech savvy by any means and my SO is only somewhat savvy, so it was up to me to break into the Windows machine, check for any spare files that might contain passwords, etc.

I got lucky, because the man kept a .rtf or .doc file with them written down. Bad format, some were out of date, etc, but I was able to get into the e-mail, which led to the rest of it.

After that whole ordeal, it put things into perspective for me. I use FDE and you need a hardware token to even boot my machine. I will need to share a minimum of 3 master passwords for my SO to unlock my digital life. Should I die before any of this is written down and secured, I strongly doubt she'd even attempt. That saddens me because there are a lot of pictures and whatnot, so I need to put together a posthumous security protocol.

Re: Write your passwords down (2010)

#155
post #152

Earlier quoted context omitted.

When my brother died suddenly, recovering his passwords was a nightmare. Especially for accounts he managed for his wife’s dental business. Fortunately his son and I were able to guess his main password and a few others. We also found that he was reusing a small set of passwords. We finally were able to get into all of the relevant accounts and then wrote everything down and gave it to his wife. Not a fun process. We…

When it comes to a Stash of Secrets to be only posthumously available, two approaches come to mind: 1. Some arrangement with a law-firm so that your Stash of Secrets will be delivered to your executor in the event of your death, where you trust they won't peek because of financial/legal relationships. 2. A way to unlock your Stash of Secrets that requires a certain portion of keys to be brought together, and you give…

How does your model account for the lack of trustworthiness of the establishment wrt citizen privacy? What guarantee do we have that the bank won't just yeet your lockbox?

I'm not sure trusting social institutions is a good idea. History shows it will be used against you, before you die.

Re: Write your passwords down (2010)

#156
post #2

Don't use fancy combinations. Word phrases are even more random and much easier to remember. E.G. "touch-some-grass" is rander longer than any recommended minimum and hardly could be connected to any website.

One of my toy projects is https://phrase.shop -- a small webapp that generates grammatically correct phrases that are both random and memorizable.

Re: Write your passwords down (2010)

#157
post #152

Earlier quoted context omitted.

When it comes to a Stash of Secrets to be only posthumously available, two approaches come to mind: 1. Some arrangement with a law-firm so that your Stash of Secrets will be delivered to your executor in the event of your death, where you trust they won't peek because of financial/legal relationships. 2. A way to unlock your Stash of Secrets that requires a certain portion of keys to be brought together, and you give…

How does your model account for the lack of trustworthiness of the establishment wrt citizen privacy? What guarantee do we have that the bank won't just yeet your lockbox? I'm not sure trusting social institutions is a good idea. History shows it will be used against you, before you die.

You could encrypt the Stash of Secrets given to the legal-firm, with not-so-secret key known only to potential recipients. (Who you trust not to conspire with the firm prior to your death, etc.)

However in a way that's just another form of option #2, where different parts must be brought together.

Re: Write your passwords down (2010)

#158

Earlier quoted context omitted.

Times in the last 40 years that... My wallet has been stolen: 0 My house has burned down: 0 LastPass has been breached: 2+ LastPass' browser extension has caused me headaches: 9000+

The piece of paper in wallet browser extension is even worse. No auto-fill or auto-update options at all and you've got to take care of your own backups and recovery.

More trustworthy than software that may or may not work, may or may not protect secrets, may or may not go for-profit in the future, etc.

Password managers make it so that you are utterly dependent on your password manager or you cannot login to anything. How do you get back online to discuss something if your computer burns in a fire, for example? Backups can alleviate this, but the paper is also a backup. Maybe do the triplicate thing?

I've considered using a password manager but there are too many times where I need to login to something from a machine that isn't mine, on a machine that I don't trust with storing secrets, or other circumstance. I simply don't want to be caught with my pants down and unable to login to something because my password manager isn't installed.

Re: Write your passwords down (2010)

#159
post #89
post #85

Earlier quoted context omitted.

I noticed that as well, the fix for me is pretty easy: just create the account in bitwarder first and then autofill it in the actual account creation page. No extra work, and becomes habit quite quickly.

This is fine on desktop. It's less great on mobile.

I used to agree with this until I thought about the order in which to do it. The issue was that I'd open BitWarden manually to create credentials, rather than doing it during the autofill popup.

Here's how I do it on iOS:

1. Select the password field and open BitWarden through the button above the keyboard.

2. The password list will be empty. Press the + to create new credentials.

3. Enter a username, generate a password and press save.

4. The list will now have a single entry. Press it to autofill.

Re: Write your passwords down (2010)

#160
post #75

Earlier quoted context omitted.

> They were already in widespread use in 2010. I'm interested in knowing the stats of this, but 1Password's first release was mid-2006. I know personally I started using 1Password in late 2008, 2009. But I'd argue even then that they were not "widespread" then and even now are not entirely widespread. (Unless you count Cloud Keychain). Arguably I think the more security conscious were using them, but even now, after…

I remember a colleague telling me about this, he used one late 2007. I thought "what unneccessary complexity, I store them encrypted with vim, much better". I know better now.

What do you find better about a password manager compared to having total control and storing the passwords yourself in a simple text file? You still need a master password to access the information, and while there's less automation, there is a degree of simplicity and accessibility that is only paralleled by a built-in OS primitive for it. GPG and Vim are on just about everything.

I would like to read write-ups of people who lost their password manager and were still able to use the encrypted storage and retrieve secrets with alternative tools. Being dependent on a specific tool for accessing dozens of sites feels like adding fragile infrastructure to my online identity. The only SPOF should be whether my body has access to an Internet connection! :)

Granted, the quality of the encrypted text file is dependent on your discipline in managing it. However, it's simple and compatible with most *nix systems out of the box.

Maybe part of it is how one interacts online, too? I try to reduce the number of accounts I have on the Web. Each one is another potential data leak risk. I might have different needs if I kept signing up to site after site, or needed to manage a brand or something else that's interaction- and account-heavy.

Aside from my personal server, I probably have fewer than 10 or 12 passwords to remember or manage. If we add a zero, I see the use for a password manager.

Post reply on HN