3 ms·
Actually Schneier wrote one: http://www.schneier.com/passsafe.html http://www.schneier.com/passsafe.html (now OSS) I use one (actually three) but it's not a go
by zwp 15y ago
Actually Schneier wrote one: http://www.schneier.com/passsafe.html http://www.schneier.com/passsafe.html
(now OSS)
I use one (actually three) but it's not a good solution for everybody (what is?). Mostly the pros/cons are obvious but two less obvious risks:
* Beware the clipboard
* Don't forget the vault passphrase...
- king_jester 15y agoSome managers (e.g. KeePass/KeePassX) have a feature where it will clear the copied username and password from the clipboard after an ellapsed period of time (say, 15 seconds). What's great about this feature is that it still preserves the rest of the clipboard history. The best way to avoid losing the vault passphrase is to make it a strong, rememberable password and move the passwords within the vault to randomly generated character strings (where sites permit it, there are a frustratingly large number of sites where certain characters or lengths of passwords simply do not work). That way, you remember only one password. The biggest issue I've encountered with over a year of daily use of a password manager is making sure you can access the password database file consistently. Having the file on Dropbox is no use if your Dropbox password can only be fetched from the password database! So, always always always keep a local copy somewhere just in case.
- Timothee 15y ago(I'll sound like a 1Password fanboy in this thread but so be it) I'm not sure that's what you mean by "beware the clipboard", but 1Password actually clears the clipboard some time after you copy a password to it. In my case, it doesn't really help since I'm also using a clipboard history through Quicksilver… As for the passphrase, this can be a problem. I was planning on regularly sending my list of password to my close family but never got to it yet.
- zwp 15y ago> what you mean by "beware the clipboard" It's not that long ago that certain browsers would give up your clipboard to any site that asked for it. IE: http://www.securiteam.com/windowsntfocus/5CP0C1F61O.html http://www.securiteam.com/windowsntfocus/5CP0C1F61O.html Similar (attacks paste), for FF: http://www.digitaltrends.com/computing/firefox-clipboard-hack-attack/ http://www.digitaltrends.com/computing/firefox-clipboard-hac...