4 ms·
This times a lot. I'm far from a naive user, but I recycle a handful of easily memorable passwords for most of the services I subscribe to. And I'm willing to
by vec 13y ago
This times a lot. I'm far from a naive user, but I recycle a handful of easily memorable passwords for most of the services I subscribe to. And I'm willing to bet that most of you do too.
Security is a tradeoff, and we tend to forget that complex, unique passwords have a very real cost. They drastically increase the risk that I will lock myself out of some service, and dramatically increase the workload of authorizing myself when I do want to use it. With a few obvious exceptions, this tradeoff is a huge net loss for the average user.
In other words, the risk of some stranger wanting to post as me in HN is acceptably small. The cost of having to install KeePassX, then download my passwords file from Dropbox then decrypt and copy/paste, then make sure the paste register is clear, then securely delete my passwords file every time I borrow a friend's computer is prohibitively high.
- marshray 13y agoJust write your passwords down in a safe place.
- evolve2k 13y agoReal question: assuming you live alone is 'next to your computer' eg in your own home considered a safe place? What's the risk of a physical robber stealing bits of paper next to your computer desk then hacking your accounts?
- scott_karana 13y agoThe risk, I suspect, is considerably LOWER than having a password guessed by a brute-forcing script on the Internet. Thievery isn't typically a frequently recurring operation, and when it occurs, the user is apt to notice.
- eli 13y agoWell, consider that if an attacker has physical access to your computer there's a pretty good chance you are screwed even if your password isn't written on a sticky note under the keyboard.
- jfb 13y agoAnd you're much more likely to be aware of the intrusion.
- marshray 13y agoThe category of attackers who are willing and able to commit a (possibly violent) physical crime to obtain one or more of my login passwords is much smaller than those who will successfully exploit weak and re-used passwords over the internet.
- dredmorbius 13y ago"A safe place" really depends on your threat model. If you live in a place where home entries by persons with an interest in your online accounts is common, then no, your home would not be a safe place. This could include: living under an oppressive nondemocratic regime, living in a democratic regime with broad search and investigation rules, living with your snooping parents, having an ex with (authorized or otherwise) access to your home, roommates, roommates friends, being a highly social person hosting parties and not being able to secure your computer area. Among others. A friend tells doing consulting work with a national diplomatic corps in a foreign country, using his personal Linux laptop, had the device scanned on his exiting the country by a known, trusted, and competent security expert. Several surveillance mechanisms were detected. The offices of faculty and staff at major universities associated with that foreign country are also subject to surveillance software, according to the same source. Those offices and the buildings they are in, as well as the associated computer networks, are generally readily accessible. Computers are complex enough, even for sophisticated users, to be difficult to secure completely. An advantage of physical, nondigital records of passwords is that they provide a much smaller attack surface. Computers (especially always-on systems) can be attacked from anywhere on the Internet (at least in theory). A slip of paper concealed in some out-of-the-way place in your home is much less likely to be found, though unless it's encrypted, it's much more likely to be useful if found.
- marshray 13y agoYes, if your adversary has physical access to your home, your computer, or other methods of installing backdoor software on it then the question of password security is rendered moot. You can't have a secret and type it on a compromised computer too.
- dredmorbius 13y agoMy point wasn't to moot the question. My point was to put the question in its appropriate context: it really depends on your threat model. And if that model includes those whom you'd prefer not acquire information having ready access to your house, then no, it's not safe. Similarly: if that's not a problem for you, it's a perfectly reasonable practice. That said: I'd probably try to find a slightly more obscure and/or secure location than in plain sight. Your threat model matters. It includes possible attackers, their modes of access, likeliness of access, the assets you're trying to protect, and how they might be used in ways damaging to you. Any significant discussion or assessment of security should be framed in this context, and it's very much generalizable beyond online, electronic, or data systems. http://en.wikipedia.org/wiki/Threat_model http://en.wikipedia.org/wiki/Threat_model
- scott_s 13y agoMaybe store it with the other bits of paper in your wallet?
- egsec 13y agoSecure password safe anyone? Keepass...