8 ms·
"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'." if you can remember your password, its pro
by dmh2000 9y ago
"Justification 2: 'Pasting passwords makes them easier to forget, because you have fewer chances to practise them'."
if you can remember your password, its probably too weak
- simias 9y agoSo by definition your password manager master key is weak? That's an interesting paradox!
- BoorishBears 9y agoIt's remembering one password vs X, and it is pretty hard to remember in my case, almost 4 months into using this password and I still struggle to type it in correctly sometimes
- simias 9y agoYeah I was just kidding, I see what the parent meant. Now I use a hardware token (yubikey) to store my PGP key so I can use a relatively weak PIN code on it (since you need to have physical access to the device to use it and you only have 3 attempts before it locks up). It's a pretty good quality of life improvement.
- majewsky 9y ago> you only have 3 attempts before it locks up Then you better don't use it when you're fatigued or drunk. I nearly locked my SIM card once by not realizing until the third attempt that my phone was asking for the SIM card PIN rather than my lockscreen PIN.
- simias 9y agoThere's also an "admin PIN" that can be used to unlock the key if something goes wrong. It's more complicated than my regular PIN and I didn't memorize it so that should be enough as a defensive measure against drunk me. Well, unless I'm silly enough to try and bruteforce that PIN as well, after 3 failures I'd be left with an expensive piece of plastic... Fortunately I'm rarely that drunk. EDIT: Actually as the sibling comment points out you can still reset the token even if you mess up the admin PIN. So at least you won't "brick" your token completely.
- tokenizerrr 9y agoEven if you mess that up, you can reset it, but it'll wipe. Then you restore from cold backup.
- deleted 9y ago[deleted]
- 0xfeba 9y agoMy password? Sure it's weak I guess. The keyfile? No.
- zeveb 9y agoWell, the password manager master key encrypts a local file, so an attacker must have access to your machine first. And it's only one password to remember, as opposed to a high-strength password for every single site one uses.
- rkeene2 9y agoI don't even have the ability to read my password manager's master key, since all passwords are encrypted with different AES keys, which is then encrypted with a private key I have no ability to read (only ask my smartcard to perform RSA on, if I can authenticate to it). hunter2 is the password manager I wrote for this: https://chiselapp.com/user/rkeene/repository/hunter2/ https://chiselapp.com/user/rkeene/repository/hunter2/
- moosingin3space 9y agoThis is an interesting concept for storing keys. I may end up using something similar in a proof-of-concept I've been thinking about.
- palunon 9y agoWhat if you loose your smartcard ?
- mazamats 9y agoHe could have an encrypted digital copy somewhere else
- rkeene2 9y agoI don't keep my private key, in any format, accessible -- usually the private keys are generated on the card and never revealed.
- rkeene2 9y agohunter2 supports the concept of users, which are named public keys so I can share individual passwords with other users. One of those other users can be a different smartcard or a different person who can then authorized my new card.
- alex95 9y agoNot really. A sentence for a password is easy to remember and isn't weak.
- morinted 9y ago"Probably" being key here. I still memorize all my passwords and the average one is about 30 characters long, with my "more secure" websites going 60+.
- alanh 9y agoOh, come on. All of them? If you're like me, that’s hundreds. Are you a memorization savant? Are you creating low-quality passwords? Mine are actually long and random (generated NOT by me and NOT four Dr Seuss words)
- morinted 9y agoIt wasn't always this way. I had horrible password standards as I'm sure most of us did when we started out on computers. - If it's a website I couldn't care about, I use a simple password, probably a remnant from growing up. - If it's a website I'm concerned about but knowingly won't use, I create a random password and clipboard it during initial creation/login, then every time I use the website I reset it (lazy man's password generator) - If it's a website that I care about, like HN, I have a loose pattern that I follow that includes symbols and numbers (that's the 30ish character I was referencing). Every website is unique. - Financial accounts have their own set of rules (unless it's stupid and has, say, an 8 character limit) - My main email accounts get special treatment with an exceptionally long password. - Use two-factor authentication wherever possible. And yes, I could replace this with: - Password manager - Two-factor authentication E: grammar.
- logfromblammo 9y agoYou just make up a story and use one of the knickknacks you keep near your workstation as a memory trigger. For instance, if I needed a new strong password, I could use, "This#jar#once#held#1111#M&Ms,#but#now#it#is#empty." The only thing I need to remember there is the story of the jar and the padding character I used in place of spaces. If I really had to, I could put "#" on a sticky note under the jar. But of course, I can't use that password now. So I might instead use "I(used(this(jar(as(an(example(on(HN." But now I can't use that one, either. So maybe I use "These!blinds!are!very!dusty.!!Someone!should!clean!them." or "My^dog^once^killed^a^dozen^baby^rabbits^in^the^tall^grass^I^didn't^want^to^mow." or "MyFgreatFauntsFhadFreallyFlongFhair." I get really irritated when sites tell me I have to include numbers, uppercase, lowercase, and symbols in the same password. I get especially irritated when they put an upper limit on the number of characters, or ban certain characters from appearing in the password.
- mrob 9y ago>if you can remember your password, its probably too weak As XKCD famously pointed out[0], Diceware[1]-style pass phrases can be both secure and memorable. XKCD's four word example isn't secure when fast brute-force attacks are feasible, but eight words is still easily memorable and secure enough for anything. The important point here is that "random words" really does mean "random", i.e. not picked by a human. [0] https://xkcd.com/936/ https://xkcd.com/936/ [1] https://en.wikipedia.org/wiki/Diceware https://en.wikipedia.org/wiki/Diceware
- Santosh83 9y agoBut how many of these can you remember? I currently use almost fifty different passwords. I can't imagine committing fifty different pass phrases to memory.
- Tomte 9y agoUse a password manager.
- heypete 9y agoThat's what password managers are for. Just remember the password for the manager, plus maybe one or two critical accounts (e.g. email) and you're good to go. Let the manager deal with the complexity of generating and remembering random passwords.
- thesuitonym 9y agoI use a similar approach and have around 8 of such passwords memorized. The rest are in my password manager.
- lmm 9y agoI don't understand this response? A passphrase is easier to remember than a password. 50 passphrases may not be easy to remember, but they're easier than 50 passwords.
- jschwartzi 9y agoSome of my best passwords were phrases copied from discarded cartons on my desk. For example, I could choose a password, > Distributed_By: WalgreenCo. 200 Wilmont Rd. And it would both be very strong, and be difficult for someone at my desk to guess by looking at things on my desk.
- nemoniac 9y agoIf you can remember your password, better not fly to the UK.
- sundvor 9y agoMy random Adobe password is something in the order of 60 characters long. Just because. If they disabled pasting, I'd disable my account.