7 ms·
I've never been a fan of password managers, but I've found a much better way than paper: 1. Create a complex password to re-use everywhere. Memorize it and don
by tobiasSoftware 8y ago
I've never been a fan of password managers, but I've found a much better way than paper:
1. Create a complex password to re-use everywhere. Memorize it and don't write it down.
2. Create individual simple passwords when you need one. Write them down
3. Create a method to combine the complex password and the simple password. Memorize it and don't write it down.
I figure there are two main attack vectors: online and offline. Online attack vectors are either a dictionary attack, which requirement 1 solves with a complex password, or using hacked passwords in one site to gain access to other sites, which requirement 2 solves with different passwords for each site. Offline attack vectors are someone discovering your written passwords, which requirements 1 and 3 solve by memorizing pieces of it.
The only weakness to this scheme is if someone is A. deliberately targeting you as opposed to a mass attack, and B. gains access to two or more of your passwords, allowing them to figure out your password system.
- jcmi 8y agoNot gonna argue the merits of your approach, but the use of "online" and "offline" attacks have meanings in this context that don't seem to match up with how you're using them: https://crypto.stackexchange.com/questions/25715/what-is-the-difference-between-online-and-offline-brute-force-attacks https://crypto.stackexchange.com/questions/25715/what-is-the... A dictionary approach is something I'd normally associate with offline attacks since online requires you go through the active system which should hopefully have some sort of rate-limits to prevent that. Offline attacks can be more brute-force and don't necessarily require pre-existing knowledge.
- tobiasSoftware 8y agoOh I wasn't thinking of that kind of terminology, thanks for pointing that out. I was using online as someone who is at a distance and can only try social engineering, brute forcing, and looking for re-used passwords (much more common, especially with Russian hackers), whereas offline is someone who would have access to local areas and could find a password book (much rarer but still happens).
- anonred 8y ago> 3. Create a method to combine the complex password and the simple password. So what happens when a site / service limits the length? Do you truncate your complex password? And what about cases where only a certain subset of characters is accepted? Do you now need to memorize multiple variations of the complex password? I used to do something similar to your proposed method, but the number of exceptional cases and work simply made if not worth the effort compared to a real password manager.
- freehunter 8y agoI found the same problem. I found too many places where passwords change far too often and are forced to be far too unique for a standard template to be replicable. Even something like HNspring2018 for my HN password, if I had to change it and did HNfall2018 I've seen sites kick it back saying it's not unique enough, or I can't use the date or year. Many won't let you use full dictionary words, even when paired with more complex stuff. My work password needs to be changed every 60 days, must be longer than 16 characters, can't repeat three characters in a row over two password iterations, and passwords have to be unique for two years before you can repeat them. I write that password down on paper every time. I hope we've reached peak ridiculousness when it comes to passwords and this is as bad as it gets before something better comes along.
- tobiasSoftware 8y agoHaving a complex password that I use for everything allows it to be nonsensical. Mine is actually based off of a phrase (an idea inspired by XKCD) but the words have some dropped characters and it includes a name (so instead of correcthorsebatterystaple, think crrctChampbttrystple). I avoid making the simple password actual words as well, but it's simple enough that if I want to use the password at work but store it at home, I can memorize it easily for a day. I agree that we've hit peak ridiculousness though.
- user5994461 8y agoThat's completely insane requirements. I don't get how anyone could remember any password like that.