4 ms·
I replied in general above, but to answer this in particular: It has been told that printing your master password and putting it in your wallet is actually ver
by probably_wrong 10y ago
I replied in general above, but to answer this in particular:
It has been told that printing your master password and putting it in your wallet is actually very safe: no online attack will reveal it, and losing the paper would not be an issue without extra information, the same way losing a physical key is not the end of the world without its address. You are doing something similar.
What you suggest is perfectly fine for one password - you are just moving the entropy from one place to the other. However, you shouldn't use it as a general method (see my other comment), and you should be aware that a determined attacker can find it by looking at your browser history.
- Cozumel 10y agoSecurity is a mindset. Carrying your master password around with you isn't safe, it's only perceived to be safe because you're not a target, like waking down a dark alley is 'safe' only because you're not carrying any cash. If someone wants access to your stuff and you're carrying your master password then you may as well just not bother using a password in the first place!
- probably_wrong 10y agoI'm sure someone could one-up us by saying "your password could be extracted from you under torture, you need a behavioral pattern password that cannot be replicated under stress", and so on. I agree that Snowden should not carry his password in his wallet, but at the same time, I think that we'd see a drastic improvement in security if all regular users did precisely that (and Bruce Schneier agrees [1]). Those that think they can be targets and/or deeply care about the issue can always do it the better (but more expensive) way. [1] https://www.schneier.com/blog/archives/2005/06/write_down_your.html https://www.schneier.com/blog/archives/2005/06/write_down_yo...