7 ms·
Algorithmically generated passwords for different sites was a mind-blower. There are so many differentiation algorithms that are trivially runnable in your head
by ethbr0 3y ago
Algorithmically generated passwords for different sites was a mind-blower. There are so many differentiation algorithms that are trivially runnable in your head.
If most sites are salting and hashing passwords correctly (this is 2023...), then that drastically decreases your compromised credential blast radius.
--
And it makes me sad that "store your passwords on dead-tree paper" became GOTO. It has serious weaknesses, but also serious strengths... especially in a post ~2005 always-on, networked-everything world.
It turns the security requirement from electronic security into physical security (and appropriate recovery and disposal procedures).
I'm not sure that's a bad trade-off these days. I don't hear about too many people having their password pickpocketed off them...
Full disclosure: Never hopped on the password manager train, because I couldn't find a combination of (a) easy to use multi-device/OS/program, (b) open source, (c) secure from host / corporate ownership. If anyone has recommendations today, would love to revisit...
- dangitnotagain 3y agoPasswordsafe/password Gorilla(Apple) It’s been around for ages, I don’t know how well supported today, though it is what you asked for!
- hirundo 3y agoThe KeePass unhosted ecosystem seems to fit your requirements. I recently switched to it from 1Password and am happy with it. I distribute the database to my various devices with (open source) Syncthing.
- gochi 3y agoThe distributed part is crucial, especially to avoid potential hardware failure. Happened to me, older machine ram (might be misremembering, that old machine had several parts replaced) failure made keypass unable to validate, claiming a corrupt database.
- falcolas 3y agoA problem solved by a backup strategy, not a cloud service. I firmly believe you can't expect cloud services to do anything but serve up exactly what you give them. If you give them a corrupt database, they will happily serve you up a corrupted database.
- gochi 3y agoTechnically, the problem is solved by either one. A service like 1password is in the business of not serving you up a corrupt database. A backup solution also works here if you don't want to rely on other services.
- godshatter 3y agoI use keepass2, and I keep a copy on a USB stick that I carry with me. Almost every device I log into regularly has a copy of the file, but I'll have to sync from the USB stick at times if the particular password I want was changed recently. I also keep a copy in the cloud, but it's usually out of date.
- Obscurity4340 3y agoBitwarden. Its dead simple and cross-platform + regularly audited. And either FREE or $10 a year for 2FA and some other nice to haves. Obviously there's other choices for those who want more control over it but you can't go wrong with BW.
- flangola7 3y ago2FA in the same app as your password defeats the point doesn't it?
- cjcampbell 3y agoIt’s not my preferred method because I want 2FA to save me if my device is compromised, but it does still add protection against traditional password attacks, credential stuffing, etc. It even adds a layer of phishing resistance, as long as the user doesn’t blindly jump to copy/paste when autofill fails.
- flangola7 3y agoWhat is the phishing resistance it adds? Bitwarden auto copies TOTP to the clipboard.
- cjcampbell 3y agoDepends on the password manager. 1Password will not autofill if the domain doesn’t match. It’s up to the user at that point to check the url before copy/pasting the code. My guess is that the average user would do that by reflex without a second thought.
- GoblinSlayer 3y ago2fa is mitigation for weak passwords. With a password manager you can use a strong password, and 2fa becomes redundant.
- rkangel 3y agoI am currently trialling Bitwarden. I have found that it's not that great at picking up that you are creating an account, offering to generate and then saving the result (using Firefox with Bitwarden extension). I am looking at the other options as they are reportedly better at that sort of thing. It's a shame though because Bitwarden is philosophically what I'm looking for.
- lgvld 3y agoSpectre does that, is OSS and multiplatform: https://spectre.app/ https://spectre.app/ i.e. it generates password given your name, a master password, and the website hostname (or whatever). Quite handy.
- happymellon 3y agoHow do you rotate the password when the site requires you to?
- Ajedi32 3y ago> If most sites are salting and hashing passwords correctly Wouldn't it have to be "if all sites are salting and hashing passwords correctly "? I suspect most "differentiation algorithms that are trivially runnable in your head" would be easily cracked with a couple examples.
- ethbr0 3y agoI'd hazard no, because 'at scale'. You could mechanical turk puzzle them trivially, but the realistic threat model is tens of thousands of credentials, tried against high value login prompts.
- sjducb 3y agoKeePass + Dropbox Works on all platforms and all the good keepass apps and programs integrate with Dropbox.
- remram 3y agoThe problems I see with this: * Websites will be hacked or expire your password, so you will have to generate a new one. Even assuming you have a way to make a new password for the same site name, how do you keep track of which version number you are now? * Website names are not evenly distributed, especially if taking the first two letters. Example: twitter/twitch.tv/twilio would all share a password
- jmcphers 3y agoI like pass, the "Unix standard password manager": https://www.passwordstore.org/ https://www.passwordstore.org/ It is very barebones -- basically a collection of GPG encrypted text files stored in Git. For that reason it's trivial to make clients for it and selfhost the repository if you're so inclined.
- aborsy 3y agoSecond this too!
- deltarholamda 3y agoI second this. If you keep it in a container or a jail or something, you can run it on a server you control, set sshd to do password authentication, have one really good passphrase, and now you can access it anywhere you can get to a shell with ssh and Internet access. (This is obviously less secure, but the convenience is great if you need it.) I've also done a version of this where it's stored on a Pi Zero, but the Zero (and SD cards) isn't the most reliable thing in the world and lost it a couple of times before I gave up, but it may work for others better. It's more fiddly than a more featureful service, but I like it because I understand all of it and control all of it.
- JohnFen 3y ago> It turns the security requirement from electronic security into physical security (and appropriate recovery and disposal procedures) Good physical security of things like passwords is generally much easier than electronic security of them. In the old days, my password manager was a slip of paper I kept in my wallet that listed my passwords. I kept duplicates at home and in my safe deposit box. Now I pretty much do the same thing, except using an (offline) password manager instead of paper.