5 ms·
Which is why I use password manager, with one unique & strong password per site. Risk management is important as there is no way to know what website has any k
by PikachuEXE 5y ago
Which is why I use password manager, with one unique & strong password per site.
Risk management is important as there is no way to know what website has any known or unknown security holes in it. (Especially those built years ago)
When possible use password manager with End to End Encryption (E2EE). Maybe Independent Security Audit too.
- lillecarl 5y agoI use my own domain and give each website their own e-mail address too, so I know who is breached/selling my information. For password management I use BitWarden, to which I am a paying customer of 15$ a year for their premium features (Premium features being TOTP integrated into the password manager, probably something else too that I don't use). BitWarden is open source, both server and clients. There's even a third party implementation of the server in rust that seems to be mostly compatible. Both the official and the third party server are self-hostable. BitWarden runs their infrastructure on Azure, uses Azure managed databases and Azure managed backups. So I'm quite comfortable having my passwords there. The only feature I miss is that I'd like BitWarden to send me an email with all my passwords, encrypted so that I own a backup of my data too in case the worst happens.
- toyg 5y ago> TOTP integrated into the password manager Is this portable, like Authy does it? Last time I moved phone it was a real pain to move authenticators...
- lillecarl 5y agoYes, you have the same TOTP keys in both your phone and browser ext
- diarrhea 5y ago> There's even a third party implementation of the server in rust that seems to be mostly compatible. Not just mostly. Vaultwarden also offers server-side features usually only found in paid Bitwarden plans.
- gck1 5y ago> I use my own domain and give each website their own e-mail address too I wish this was a supported feature on @gmail.com domain (not the +{string} thing). I like the idea, but keep thinking that I'll be uniquely identifiable on every database, since it's almost always going to be just 1 entry for the domain I own.
- npteljes 5y agoYou could use your own domain, and Google's business offering maybe? I'm not sure if you could register a catch-all email then, but it would enable you to use custom domain, and Gmail's infrastructure and interface.
- lillecarl 5y agoA proprietary Fastmail feature generates anonymous @fastmail.com addresses for you, but I mostly use my own domain since I don't want to be locked in to one provider.
- dzmien 5y agoGmail [0] ignores dots in your email handle and so you could use a different pattern of dots for each website you register at and record it in a spreadsheet or something. The first and last characters cannot be dots, and I do not think you can have two or more dots in a row, but there is no limit to how many "legal" dots you can use. Not as elegant, but definitely doable. [0] https://support.google.com/mail/answer/7436150?hl=en https://support.google.com/mail/answer/7436150?hl=en
- COGlory 5y agoIs exporting your passwords and encrypting the file not an option for you?
- lillecarl 5y agoWell yes and no, I'd like it to be automatic but I have an old archive around somewhere.
- g19fanatic 5y agoI use keepass with the app.keeweb.info frontend and a gdrive backend. keeweb.info has totp as well. Seems pretty straight forward and its free. Make the backend file accessible by link and forward a bit.ly to it and you can pull it down anywhere you have internet. Phone app works great too. Everything works offline too if gdrive isn't your thing Every computer I normally use will have a copy of the file in the case that I can't access my gdrive (which I don't see happening really).
- verytrivial 5y agoCan anyone talk me out of the Firefox password manager? It has a poor "general" use case for non-website passwords and treats mobile as a second-class satellite, but it seems to just work and the sync between mobile and desktop is very handy. https://hacks.mozilla.org/2018/11/firefox-sync-privacy/ https://hacks.mozilla.org/2018/11/firefox-sync-privacy/ I read and understood just enough of this when it was published to know it would make the foundation an object of ridicule if it was ill-conceived, but I obviously rely on implementation details being tickety boo.
- wasmitnetzen 5y agoKeepassDX (Android) has a really nifty keyboard feature which allows you to even put passwords in apps, which the regular Firefox Sync doesn't support. Maybe that's the use case which makes you do the switch?
- chompychop 5y agoDo we need to toggle this feature somewhere in the settings? I use KeepassDX but I've never been asked by the app to auto-fill in passwords on websites or other apps.
- wasmitnetzen 5y agoIt's a separate keyboard, and needs to be enabled in the keyboard settings of Android. There's a link in the KeepassDX settings. There is a separate autofill feature, but that works quite rarely, maybe 10% of the apps support that, but that makes things even easier.
- shudza 5y agousing chrome's manager and android 11 has native autofill for apps which works 100% so far
- verytrivial 5y agoBouncing via the system clipboard does feel a little sketchy, yes. The other is the password generation feature is entirely missing on Android, so I need to use another good source of randomn characters or delay until I'm at my desktop. It's really only these two features that are missing for me, but since I create new password relatively rarely (once or twice a month), I find just having it there to be the winning feature. Also the 'copy these random files' as a back-up mechanism for disaster recover seems a bit ... like something I would design, so not great.
- BlueTemplar 5y agoWell, for this kind of negligible importance website risk management is simple : just use a variation on "password for opensubtitles" as a password (and maybe even have it saved by your browser). (If like me, you find the idea of a password manager not acceptable.)
- TedDoesntTalk 5y agoAgreed. If they don’t have anything personal but my email address, I use a password that’s been compromised and reused for 10 years but easy to remember. Weigh the risk and exposure against.