8 ms·
I still don’t get why someone using a password manager would make up passwords themselves instead of randomly generating long and strong passwords... The way t
by grinsekatze 9y ago
I still don’t get why someone using a password manager would make up passwords themselves instead of randomly generating long and strong passwords...
The way they implemented this is nice, but seems a bit pointless to me.
- davidcollantes 9y agoIt is pointless to me too. Yet, one of my co-worker told me: "Because even if not using crazy long random generated passwords, using a different one for each login is still a step in the right direction, and being able to remember 200 discreet passwords is hard for almost anyone." Boggles my mind...
- whichdan 9y agoLots of people may have recently switched to a password manager, and now use it to store old passwords that they haven't regenerated. It's very likely a common use case.
- wlesieutre 9y agoThis was me a couple months ago. Had one password that I reused on a bunch of websites where I didn't particularly care about security. Eventually decided to give them all stronger unique passwords (because why not) and it was a pretty easy process because the password manager could show me all the sites with duplicate passwords.
- r3bl 9y agoHeck, you don't even to switch to it recently! I've imported my passwords from Firefox's password manager to a dedicated one a few years back, and I've been generating new passwords ever since. There's still dozens of occurrences of the one-password-for-all-services I've used previously, because nobody will go through the hassle of changing passwords in hundreds of online services. I do change it whenever the autofill appears too short to be randomly generated, but I still didn't get rid of all of them. With that said, I'm not using 1Password and I've already checked my old password in Troy's service to make sure it wasn't in a breach.
- kuschku 9y agoPassword rotation is a major issue. If we'd use something like certificate auth it'd be less of an issue, but currently password managers are a horrible trend because they encourage using your password for a service for kany years. Ideally you'd rotate them every 60 days. Automating that is hell. It'd be much nicer if we could just use OIDC with user-configurable endpoint.
- mnutt 9y agoHow do password managers make password rotation any worse? If anything, they at least keep a record of which sites need password rotation.
- kuschku 9y agoWe used to have OpenID in the past, now that password managers exist, efforts to fix the problem at the root have been stalled. In fact, Android implements now on OS level an API for password managers, but no way to easily authenticate through a third party app. Password managers are "good enough" that few people care about better solutions anymore. Personally, I'd prefer to see client side certificates, or OIDC login everywhere, with short lived session tokens, and proper U2F 2FA.
- jedberg 9y agoPassword rotation has been shown time and again to be worse than just using a unique strong password. With rotation, there is a tendency to just use the same password but increment a digit at the end, or to write them down because people forget them. A password manager helps with this, but if you're using a password manager, then you can use a different password everywhere. Password rotation was recommended in the days when people used the same password everywhere and had to memorize them because password managers weren't a thing. Password rotation gains you nothing if you're already using strong, unique passwords. The best it will gain you is preventing your account from being accessed if they have already breached the password file, cracked it, and come back after the rotation period. But at that point they've already had access to the system and your password is meaningless anyway, so you didn't actually gain anything.
- dawnerd 9y agoAnd theres some sites where random passwords just don't work because of dumb password rules so hand making them is easier. Also still nice to know when a password, randomly generated or not, is released out there in the wild.
- zie 9y agowell, let's say I run idiotService, and you login with a nice strong randomly generated passphrase, but since I'm idiotService, I just store it plaintext and check against it.. to make matters worse, some bad guy steals my password list, but I'm such an idiot I didn't even notice... Troy hunt, in his ever-long quest of getting copies of these breaches, eventually gets a copy of all of my passwords and adds it to his database, and now suddenly, you the user get a warning, uhh.. this password is in the pwned-passwords DB... and now you know idiotService really is an idiot.
- blakesterz 9y ago"Clicking the Check Password button will call out to Troy’s service and let you know if your password exists in his database. " I think the point is to see if any password you've come up with (either generated in 1password or on your own) has been breached and you don't know it. If you do have unique passwords for everything and you see that it's there, then you would know what's been pwned.
- inetknght 9y ago1) Use password manager 2) get asked to help someone else at their machine 3) need to log-in to a remote resource under my own user to do something 4) password is in the password manager on my workstation on another floor Solution? Should I: * ask the person to give very exact and detailed instructions on what they need me to accomplish so that I can do that work from my own workstation? * go up to my workstation and call the person who needs help and walk him through logging in as me? * remote-login from their workstation to mine to copy/paste (and hope their workstation's clipboard is secure)? * bring my password manager with me on my phone (and risk my passwords being pwned because phones are Not Secure)? * write down 40 character password somewhere (stick-it note?) and hope I neither typo anything, nor allow others to read it, nor carelessly discard it? * just use a password I made up and can easily remember? I'm sure there's better solutions. Each one has their own annoyances.
- heartbreak 9y ago> * bring my password manager with me on my phone (and risk my passwords being pwned because phones are Not Secure)? As someone who uses this solution to your above-stated problem, I disagree with the assertion that phones are "Not Secure." Care to back that up?
- inetknght 9y agoPhysical device small enough to be quickly stolen: Not Secure. (this is self-evident: physical access to device is Game Over) Low battery requires plugging in a cable to charge; the cable may be a surreptitiously-installed data cable. I do not trust the hardware or software stack that handles the data cable to be secure. SMS: Not Secure. http://www.cybersecuritytrend.com/topics/cyber-security/articles/424266-nist-has-it-right-sms-not-secure.htm http://www.cybersecuritytrend.com/topics/cyber-security/arti... Wifi: Not Secure. https://www.bestvpn.com/privacy-news/wpa2-wifi-not-secure/ https://www.bestvpn.com/privacy-news/wpa2-wifi-not-secure/ Many apps "require" silly amounts of permissions to the phone before they'll install. Apps' ability to read what's on screen, to be notified of clipboard changes, to listen to sounds; all when not even in the foreground. On my computer, I can easily check what apps and background services are running. Not so easily on a phone.
- dexterdog 9y agoI do it because lastpass/1pw/bitwarden/etc all seem to generate random passwords which are hard to use manually. If they do a "pronounceable" one it's all lower case or doesn't mix case other than randomly or capitalizing the first letter. Many of us like some kind of variation on xkcd's password generator. I haven't seen an implementation that does it the way I like so I wrote my own. I have that generate a password and then I put it into bitwarden (or whatever I'm currently using). I thank myself when I have to manually type the password into a device because I can look at it and remember it long enough to type it one time. Also, some "long and strong" passwords are too long and/or string for sites that have poor password requirements.
- notheguyouthink 9y agoI'm not sure what your requirements are, but 1password optionally generates passes from words. Eg: > fracas homily unsaddle bonus pueblo victim I vastly prefer it.. by leagues. With that said, I rarely use it. For my feeling of security I want to use many word combos, but it's very common for password input services to limit the number of characters I can use. Some of them (shockingly often) even truncate the password and accept it anyway, so now I don't even know what my password is. Shame.
- rootlocus 9y ago"long and strong" randomly generated passwords can be found in password dumps too.
- craftyguy 9y ago> The way they implemented this is nice, but seems a bit pointless to me. I've always thought that the best way to build a rainbow table is to create a 'password checking service' like this and have people fill it with their own passwords.
- jedberg 9y agoIf you read the details you'll see that's not the case here. They don't get your password or even the full hash.
- Consultant32452 9y agoI use a password manager and still have embarrassingly simple passwords for some things. The reason is that the most common place I'm "typing" this password is an obnoxious interface like a gaming console.
- jzl 9y agoLastpass has an awesome option when generating passwords for cases like this: "Make pronounceable". It will generate a password like "lickyusideno" (just generated that now) which is easy enough to remember between looking at the lastpass app on your phone and then typing it in through a console/netflix/etc interface.
- Bokagha 9y ago1Password actually has the same feature. You can separate the words with a hyphen, space, period, comma or underscore on generation to make it more human readable.
- taco_emoji 9y agoI wrote a little HTML/JS app to generate pronounceable passwords which alternate left-and-right hands. Mainly I use it for my AD logins at work, which I A) have to enter numerous times per day and B) have to change every 60 days. The "pronounceable" part makes them easy to remember for the first couple of days, and then the "easy to type" part means muscle-memory takes over so that it's barely and inconvenience. Data source is a python script which trolls through /usr/dict/words and then counts the occurrence of each three-letter alternating-hand combination, outputting the counts. To start I pick a letter with 1/26 odds, then filter the triplets based on first letter, then continuously pick triplets based on the last two selected letters. (I think this amounts to a Markov chain but I've not studied them well enough to know for certain...)
- Consultant32452 9y agoAll of the bad password traits are rewarded in this scenario. You want a password as short as possible, with as many repeating characters as possible, etc.
- raverbashing 9y agoBecause your generated "long and strong password" is not accepted in some sites, or cause problems or is just a PITA to type on mobile devices, or I can't copy and paste it for some reason or another, for example
- ascagnel_ 9y agoOr because the password itself is leaked somehow (eg a DB of passwords that was stored incorrectly getting hacked, which happens with some degree of regularity). I use a "long and strong" password to lock a password manager, which itself generates long and strong unique passwords for each login (I use 1pw here, which is nice because it can also handle 2FA/rolling codes). I haven't yet found a better way of handling that at scale that isn't "write down your passwords on a piece of paper in clear-text".
- chrisper 9y agoYou can't generate every password. Some you need to remember, but it is good to store them in case you forget them.
- stordoff 9y agoSome passwords I need to memorise (e.g. the logon password for my primary machine), and others need to be input on devices where long, strong passwords would be unduly cumbersome (e.g. my Xbox/PSN accounts are never going to get the same strength I use elsewhere because typing long, mixed case + symbols passwords on a controller is a nightmare).
- twblalock 9y agoI'm more concerned about people using weak master passwords for their password managers. It's a single point of failure in the security of every other password they have.
- technion 9y agoThe only way I can get a password that meets some of the more ridiculous "security" policies some places have is to go through the criteria and make one up myself.