3 ms·
>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all). Nothing wrong with writing passwor
by triangleman 6y ago
>Or, this was fun, my first gov't job the guy had stored passwords on a sticky underneath the keyboard (I changed them all).
Nothing wrong with writing passwords down. Or at least it's the least wrong thing you could do among all things mentioned here.
- vorpalhex 6y agoIt depends entirely on your security and threat model. Me, working from home? I'll write down the password for my netflix account and wifi - sure. In an office? Absolutely not, never, not once. Offices are not private and not secure and in any kind of even vaguely sensitive setting allowing a colleague to have access to your password and impersonate you is a massive risk.
- m4rtink 6y agoYeah, it really depends - in many cases an attacker gaining local access is game over anyway & less technical users will at least have harder to guess passwords. In other cases it's indeed a bad idea.
- Jtsummers 6y agoI would partially agree with this. It's not wrong to write down passwords. It is wrong to write them down and not secure them. Securing them is the same step that happens (or is intended to happen) with password managers. The passwords are, themselves, encrypted in some fashion so that they're not (easily) accessible to others. If these passwords were at least put in a locked cabinet, I'd have felt better about it. A safe would've been even better (and this is assuming that they needed to be shared, we had security tokens that, if used properly, meant we didn't need the passwords at all and each person would have a unique access token for better accountability). It is moronic to write passwords down and stick them underneath the keyboard.