Live data from Hacker News

Ask HN: Does anyone use an alternative to a password manager?

news.ycombinator.com

221–230 of 250 posts

Re: Ask HN: Does anyone use an alternative to a password manager?

#221

I am shocked to see a tech literate audience recommending a single algorithm based password. This is pretty basic stuff. Minimize attack surface! With a password manager, your attack surface is your email, and the password to the manager. You can focus your efforts on securing those two things with 2fa, a hardware device, etc. Every other password can be extremely difficult, and only grant access to an individual ser…

Algorithmic password generation from a single master password works fine up to the point where it doesn’t.

What happens when you run into a site that won’t accept your algorithmic generated passwords?

Do you fall back to a traditional password manager?

If so, then you’ve just increased your attack surface area by an order of magnitude.

What happens when you need to change your master password because of a compromise, and now all of your passwords have to change at the same time?

Re: Ask HN: Does anyone use an alternative to a password manager?

#222

I am shocked to see a tech literate audience recommending a single algorithm based password. This is pretty basic stuff. Minimize attack surface! With a password manager, your attack surface is your email, and the password to the manager. You can focus your efforts on securing those two things with 2fa, a hardware device, etc. Every other password can be extremely difficult, and only grant access to an individual ser…

> If one password is compromised, they all are. The point of an algorithm as opposed to a single shared password is that this isn't true. With a basic algorithm, you can avoid automated attacks based on password dumps. With a more complex algorithm, even a determined attacker targeting you would have a really hard time figuring it out. Regardless, it probably would need to be a few passwords, not just one. Also, any…

The keylogger risk is an issue for both password managers as well as those who generate passwords based on an algorithm applied to a single master password.

Re: Ask HN: Does anyone use an alternative to a password manager?

#223
post #82

I have one of these. I personally never use it due to the inconvenience, but it might work for you. https://www.qwertycards.com/

The space bar code and "secret word" portion together are the same across all sites. If your password is compromised on two or three services, the attacker has this constant portion, and the remainder of your password is a simple substitution cipher encoding the service's name.

Well then I guess it's lucky I don't use it!

Re: Ask HN: Does anyone use an alternative to a password manager?

#224

I use an algorithm. In short: 1. Memorize some base password 2. Memorize a way in which you mutate that password based on the name/type/other of the service logging in to. Eg. Hunter2 becomes eHunterG8 Because my example algorithm cares about Google's first letter, length, and service type: email. It allows every password to be different but you only memorize two things. It is meant to be a "good enough" solution tha…

I'm a fan of mixing this idea with something like 1Password. Obviously depending on the application, the security increases or decreases. My approach is to memorize multiple base passwords though & then mix it with some random gibberish. So I might write my password down like this: KXl2h!H (H) That would tell me that the password is KX12h! plus whatever the base password for H is. My hope is that unless someone was r…

>The part I struggle with most, is how/where to store these & Authy/Google Authenticator tokens in a manner that they can be delivered to specific people in the case of my death without decreasing security.

Something I've often wondered about...

Re: Ask HN: Does anyone use an alternative to a password manager?

#225
post #224

Earlier quoted context omitted.

I'm a fan of mixing this idea with something like 1Password. Obviously depending on the application, the security increases or decreases. My approach is to memorize multiple base passwords though & then mix it with some random gibberish. So I might write my password down like this: KXl2h!H (H) That would tell me that the password is KX12h! plus whatever the base password for H is. My hope is that unless someone was r…

>The part I struggle with most, is how/where to store these & Authy/Google Authenticator tokens in a manner that they can be delivered to specific people in the case of my death without decreasing security. Something I've often wondered about...

I recommend reading about Shamir Secret Sharing. You could have a system setup such that (for example) you give 16 friends each a code and 9 of your 16 trusted friends all have to work together in order to get the original secret.

Re: Ask HN: Does anyone use an alternative to a password manager?

#226
This might sound like I'm trolling (honestly not) or trying to seem superior (Again, really not), but I try to simply use long passwords and memorize them. I'm fighting back against what I perceive to be the erosion of memory by my increasing dependence on modern technology. We don't need to remember stuff anymore, we just use this algorithm or that password manager. In the past I've used keepass, and I keep that as a backup for rarely used things, but increasingly I just try to memorise long passwords or pass-phrases for the key services that I use every day. My credentials for google, paypal, amazon, github, dropbox, onedrive, online banking and more are all just memorized rather than stored.

Re: Ask HN: Does anyone use an alternative to a password manager?

#227

Earlier quoted context omitted.

FWIW, it's really rare for a mixed-case alphanumeric password to be rejected. Typically it's only banks and corporate logins. Those are sufficiently special-case to make an exception.

Downvoted! :) Amusing for actual lived experience to be denied! (Data: I have 72 logins currently cached in Firefox. Every single one of those sites accepts 10-character mixed case alphanumeric passwords with no extra special character requirements. About once a year I come across a site that needs one.)

I've checked my password manager and I think your stats roughly match what I see - about 1 in 100 sites seem to have smartass requirements to passwords, others (correctly) don't care.

Still, I'd say it's inconvenient to have "special cases" to remember about. Even if they're something important, like banking.

---

Someone had mistaken downvote with "I disagree" rather than "unhelpful". Upvoted you, as I think your comment was helpful and contributed to the discussion.

But this is going off-topic (and discussing votes is something we should refrain from)

Re: Ask HN: Does anyone use an alternative to a password manager?

#228
Bluink key is a password manager, OTP generator and FiDO U2F key all in one. It is a smartphone app for iOS and Android that stores all your passwords on your phone, not in your browser, not in the cloud. You can generate different, random passwords for everything and add 2FA to your most important logins. Check it out! Bluink.ca

Re: Ask HN: Does anyone use an alternative to a password manager?

#229

Earlier quoted context omitted.

I switched to this after being a long time lastpass user, I'm regretting it. It's visually a lot better but it is terrible at generating passwords and saving them. On both windows and mac with chrome I click the 1pass icon and click generate (nothing happens). If something happens it shows up as a new entry if I go into the vault with no site or anything just a random string that I then maybe copy paste? (ugh). There…

Hm. I just checked on both of these comments, and it seems 1password manages both quite well. re: password generation in-browser - this is working just fine for me. [0] And re: pw integrity or strength - this might not be everything you're looking for, but it's close. under a 'Security Audit' tab, it has categories for: - Watchtower (logins associated w/sites that are known vulnurable/exploited) - Weak Passwords - Du…

Wow, this is not at all what my screen looks like. Maybe it's the extension itself that's lacking? [0]

I don't have any of these other options either. If I click on generate password the box just goes away. Maybe I should scrap the extension and just use the mac/windows application? I was reading a number of reports about not syncing between these. If I have both on maybe it'll cause issues?

[0] https://imgur.com/a/msydX

Re: Ask HN: Does anyone use an alternative to a password manager?

#230
I used an algorithm previously, which was a hassle at times and probably not as secure as I was telling myself. This was until I joined Bluink and discovered Bluink Key.

Bluink Key is a secure (nontypical) password manager that encrypts your passwords locally on your smartphone and automates logins on your computer via a Bluink Key USB device. Nothing is ever stored in the cloud.

Bluink Key is impractical for attackers to target because they need physical access to your phone, they need to know your phone's PIN, and they need to know your master password to Bluink Key. This is very difficult to pull off assuming you usually have your phone with you and have a decent PIN/master password.

Bluink Key is also relatively unprofitable for attackers to target because a successful attack would only yield passwords from one individual, whereas a successful attack on a traditional, cloud-based password manager would yield passwords from millions of users.

Bluink Key is a two-factor authenticator as well (FIDO U2F and OTP).

Here's the website if you're interested: https://bluink.ca/key

Post reply on HN