10 ms·
This is a good time to remind everyone to use a password manager and to have each password generated. Each service should have it's own password so if it gets c
by electic 9y ago
This is a good time to remind everyone to use a password manager and to have each password generated. Each service should have it's own password so if it gets compromised, your exposure is limited to that one service.
It is clear this is going to be a staple of internet life, so might as well be prepared.
- thekashifmalik 9y agoThis.
- deleted 9y ago[deleted]
- jv22222 9y agoAgain, HN, please explain to me why “This.” was downvoted here. Why is it wrong for somome to acknowledge and undersore what somone else says? It’s the kind of thing that happens in real world conversation and we don’t rebuke people for agreeing and underscoring what somone else says in that context so why do it here? I’m genuinely curious.
- LeoPanthera 9y agoIt adds nothing and wastes space. If you agree, just upvote.
- imron 9y agoThis.
- fossuser 9y agoAt the risk of increasing an unnecessary thread, the parent comment adds nothing to the discussion and the upvote exists for this purpose.
- deleted 9y ago[deleted]
- adventured 9y ago> It’s the kind of thing that happens in real world conversation HN isn't real world conversation. These link comment threads do not function at all like conversations in the real world. And if they did.... Where in the real world would you walk into a physical space, in which a crowd of 187 people are gathered to read and discuss an article (or broadly a topic), and then pull out a bullhorn and declare one word: "this" and then walk back out the door? Your premise doesn't make sense.
- teddyh 9y agoThere is a significant difference between HN and real life; in real life, there are both a limited number of participants, and you are more likely to be interested in what each participant thinks. But consider a very large group, like hundreds of people, in a room. One person gets their turn to speak, and merely says "I agree with the previous speaker" and leaves the podium. Did this unknown person contribute meaningfully to the debate, or did they just senselessly waste everybody’s time? It’s obviously the latter, and it’s the same here on HN; nobody knows who you are, and merely agreeing or disagreeing without backing it up with arguments is a waste of everybody’s time.
- jv22222 9y agoThat’s a very good answer to a genuine question, thanks!
- jMyles 9y agoCan you suggest a good password manager? Ideally, I'd really like something that's deterministic - ie, I can provide a seed, and then that seed plus the domain name becomes the basis for the password. That way, it's trivial to recover passwords when sitting at a new computer. And I imagine if the seed is sufficiently long (say, a 10-word sentence that includes 2 or 3 non-dictionary words) then it'd be highly impractical to force. Right?
- vlunkr 9y agoSomeone please build this if it doesn't exist already!
- 0xfeba 9y agoIIRC Someone has before, either here or reddit but it was terribly implemented. Use LastPass, 1Password, or KeePass.
- zootboy 9y agoExcept this all but negates the benefits of a password manager. Now if someone steals your master password, they can generate every single password you use. Use something like Keepass / KeepassXC. Yes, it's somewhat less convenient, but remember that security and convenience are always a trade-off.
- jMyles 9y ago> Except this all but negates the benefits of a password manager. It preserves the main benefit: that I no longer need to remember a separate password for each domain in order to stop sharing passwords across them. > Now if someone steals your master password, they can generate every single password you use. So it's just a matter of keeping the seed in the user's head and nowhere else. Right? That doesn't seem to be any more serious a security challenge than keeping secure an encrypted datastore full of passwords.
- deleted 9y ago[deleted]
- TheRealWatson 9y agoWhat if you need to update the password of one of the sites (e. g. this disqus breach) ? What if the domain name changes?
- TheRealWatson 9y agoSorry. Replied to the wrong comment.
- AlexCoventry 9y agoYou can delete your comments if you get to them quickly enough.
- deleted 9y ago[deleted]
- scrollaway 9y agoIf you're just starting, here's some guidance on setting up a password manager. First of all: Don't be afraid of using one. It's not just more secure, it's super convenient. Never again will you ask yourself: Did I make an account for this website/service? What email did I use? Never again will you have to remember a password. Using a password manager is a quality of life improvement. KeepassXC is what I recommend to people at this point. It's free and you own your data (your passwords). They live wherever you want them to live. There are plenty of online services that are supposedly more convenient but I have to say I trust them less -- YMMV (1Password is the best I'm aware of). https://keepassxc.org https://keepassxc.org If you do use keepassxc, you get the added benefit of being able to store 2FA settings in it as well (if you store them in the same database as your passwords, be aware that you lose the security benefit of a second factor, however it is still more secure than not having 2FA enabled due to the One-time password component). Put every account you ever made and ever make into keepass. Enable 2fa wherever you don't have it enabled. Add login URLs and notes. Generate your passwords from keepass itself; the password generator is really powerful and lets you very easily deal with site-specific shitty password limitations. I'm telling you this because, seriously, it's incredibly convenient to have this stuff as long as you're rigorous about maintaining it. Oh, also, keepass has the full history of all your passwords. Need to look up an old password? Go into details and look at "History". You can also attach files to items (items don't have to be accounts at all, you can use keepassxc as a simple encrypted storage db). Mobile support: Keepass2Android. Best android client, with google drive support. iOS I have no idea, suggestions welcome. IMPORTANT: BE STUPIDLY PARANOID AND RIGOROUSLY CAREFUL ABOUT YOUR MASTER PASSWORD. That thing, together with your keepass database, unlocks all your accounts ever. Use a really long passphrase that you will never have to write down (if you do decide to write it down because you don't trust yourself, store it in a safety deposit box, don't put it in a bloody drawer). Make sure the device you unlock the database on is malware-free. PS: Wondering what's up with Keepass vs. KeepassX vs. KeepassXC? Keepass is the original app, written in .NET but with poor multi-platform support. KeepassX is a rewrite in Qt and is a fantastic password manager, but has gone unmaintained recently. The open source community picked up the slack in the KeepassXC fork (after continuing countless attempts to upstream the patches) and has implemented lots of powerful features. I've switched to it and at this point I strongly believe it's the better client.
- maerF0x0 9y agoas they become the staple the password manager becomes the target
- cm2187 9y agoBut that's a much much smaller target to aim at than the vast number of websites that you trust with a password
- gsich 9y agoA better reminder would be not to use services like Disqus.
- Steko 9y agoPrevious discussion on Disqus 3rd party tracking: https://news.ycombinator.com/item?id=14170041 https://news.ycombinator.com/item?id=14170041 https://news.ycombinator.com/item?id=15334207 https://news.ycombinator.com/item?id=15334207
- johngarrison 9y agoFrankly, I don't trust password managers. Perhaps I'm naive and they're perfectly safe, but still. My solution is to develop an algorithm for all my passwords that is pretty quick and simple to memorize but allows me to "generate" a unique password for each service that I use. Although I seriously doubt anyone could figure out my algorithm by learning one of my passwords, I'll admit that if they were to gather 3 or more then they'll probably be able to figure out my system. But since I never write down or record any passwords whatsoever (all I need to remember is my algorithm), someone would have to steal my credentials from multilple sources and also be able to know which credentials from one service match a user from another, etc.
- chias 9y ago1. Linkedin, Yahoo, Disqus. Probably a few others for good measure. 2. Search for any combinations of john, garrison, and any other names I can determine by looking up your comment / post history here 3. Check the list of results to see which appear to be reasonably complex and of similar construction to determine which are likely yours. People with "good" passwords are very much in the minority, so this should be pretty straight-forward and mostly automatable. 4. Manually try to determine your scheme, which according to you is probably doable with this information. --- Not saying it'd get you for sure, but if your replacement of a password manager is hamstrung by knowledge of at most three of your previously used passwords, you're probably doing yourself a disservice.
- cm2187 9y agoAnd to provide different email addresses for every website, so that your identity is difficult to correlate between accounts, which partially mitigates the privacy implications of a breach, and fully mitigates the spam / phishing consequences (since you can delete that email alias).
- always_good 9y agoGenerating forwarding email addresses is something password managers like 1Password should do. They should generate a new username, password, and email per service in one click as you please. Thanks to social engineering, email address reuse is the new password reuse.
- j7ake 9y agoThanks for your suggestion, but I am not sure how to implement this in practice? How do you generate different email addresses for different websites for a typical user who uses gmail?
- edp 9y agoFor some websites, you can put a "+" sign and whatever you want after your gmail username. For example: username+dropbox@gmail.com, and you will receive mails at username@gmail.com. Unfortunelately, this doesn't work with websites that have aggressive regexp checking on email fields.