4 ms·
How is Lastpass any less secure? Anyone with access to your computer could put a USB keylogger on it and get all your passwords that way. The only way to preven
by nobodysfool 13y ago
How is Lastpass any less secure? Anyone with access to your computer could put a USB keylogger on it and get all your passwords that way. The only way to prevent that would be to use an on screen keyboard, but then all the attacker would have to do is stand behind you or remote control your computer.
- criley2 13y agoMy point is simple: Memorizing a few unique passwords for mission critical services while using generic throwaways for low-priority sites is more secure than LastPass can ever be. I started this thread asking if there was a better solution that memorizing 5-10 passwords and using some variable of a throwaway for the majority of everything else, and I'm still not convinced that my method isn't the best outside of just hard memorizing a unique password for every site. Fact is: my memorized passwords can only be compromised where they are stored on servers (or through a keylogger). LastPass can be compromised every single way that my memorized passwords can, in addition to being compromisable on any computer you use it on, and the LastPass services stores all of your passwords offsite, all of them, adding in another huge vector for attack against your entire catalog--- in a way that my memory can never be attacked (without say, interrogation/force). I don't know, I don't like the idea of a digital store of all of my most critical information put behind a password that doesn't even pop-up on your computer. Mine as well just store all your passwords in Chrome. Same amount of security. Actually Chrome probably does better since it won't automatically push your passwords to the cloud unless you sync...
- subsection1h 13y agoI started this thread asking if there was a better solution that memorizing 5-10 passwords and using some variable of a throwaway for the majority of everything else, and I'm still not convinced that my method isn't the best outside of just hard memorizing a unique password for every site. When I was younger, I had only 5-10 important accounts and I memorized unique passwords that I thought were strong. Now I have many more important accounts, including four brokerage accounts, several bank accounts, half a dozen credit card accounts, two domain registrar accounts associated with tens of thousands of dollars worth of domains, etc. I have a separate computer that I only use to access these important accounts, and my passwords for these accounts are stored in KeePass, which allows me to have unique passwords with 200+ bits of entropy. I prefer my current setup more than my old setup.