6 ms·
This should be a lesson not to manage your own passwords, use a password manager there are many to choose from. I was also caught up in the Adobe breach but my
by da_n 13y ago
This should be a lesson not to manage your own passwords, use a password manager there are many to choose from. I was also caught up in the Adobe breach but my password was randomly generated by my password manager.
- elwell 13y agoWhat do you do when you are using a different computer and need to login to site?
- BlackDeath3 13y agoIf you don't mind paying a small annual fee, Lastpass is a very nice tool for automated password management across devices.
- zenojevski 13y agoPresumably you can open your password manager's web service and do it from there.
- baddox 13y agoThat or use your phone. Most password managers have apps.
- elwell 13y agoOk, that makes the most sense to me.
- mcv 13y agoI wouldn't want to use a webservice to look at my passwords. I want to open my password safe locally. Less likely to be snooped upon (though still possible, obviously).
- Habesha 13y agoYou can have the password repository in dropbox to sync between different machines, and also use the app
- SideburnsOfDoom 13y agoYou can. I would not. I don't want my password file uploaded to any remote server.
- nhaehnle 13y agoUse a browser add-on for exporting/importing passwords, transfer the exports on an encrypted USB stick.
- rfnslyr 13y agoI carry a little piece of paper in my wallet that has my private key further encrypted by myself, and that encrypted key is used to decrypt other passwords through a private web/mobile app I made. The top encryption key I have is just some sort of simple algebraic mumbo jumbo formula I used to scramble my private key just a bit, and I change it up once in awhile, and have that written down. What's in my memory is how I jumbled it.
- Morgawr 13y agoI use a yubikey that outputs half of the password used to unlock my keypass database, the other half is in my head (so even if they steal my yubi they can't do much). The database is backed on my own owncloud which is hosted on my own vps and replicated on other 3-4 servers (all mine). My little personal cloud setup. Call me paranoid but it took me half an hour to set it up and the monthly fees for the servers are very very low.
- bigiain 13y ago" … hosted on my own vps … " Might want to think through whether that really counts as "your own". Who's got hypervisor access to the hardware? Any keys or passphrases that ever hit the disk or memory on someone else's hardware should (at least at some levels of paranoia) be considered "possibly compromised". (I store "sensitive stuff" on AWS/DigitalOcean/other-vps-providers, but only if it's first encrypted locally and the key/passphrase never gets used/stored on the vps. EncFS works pretty well dealing with that for me... I do, though, "trust" 1Passwords datafile encryption enough to take advantage of the iOS/MacOSX sync features they've implemented over Dropbox. That's possibly not achoice I'd make i I thought I were a target of someone like the NSA.)
- deleted 13y ago[deleted]
- ams6110 13y agopasspack.com But I would not really be comfortable using it on an unknown computer, unless I had good knowledge that it was properly administered.
- jfb 13y agoI don't. I carry my passwords (via 1Password) on my phone, so I'll just use that.
- bigiain 13y agoFor some logins, the answer is "Sorry Dave, I can't do that." If I don't have the private cert, or the ssh cert, or the right hole in the firewall - there are many thing I've chosen intentionally to not be able to log in to using someone else's computer. For lesser security critical logins, I've got my password software (1Password) on my phone (and iPad). For some intermediate level logins, I need my phone or iPad anyway, I've got TOTP two favor auth (using Google's Authenticator app) on a bunch of important stuff (Amazon/AWS, DigitalOcean, Dropbox, Guthub, the email account that all my domain names are registered with and to which password resets go, and a few other things…)
- Figs 13y agoWhat will you do if your primary computer gets stolen?
- bigiain 13y agoPrivate SSL/TLS certs, ssh keys, and 1Password database are all stored on encrypted fiesystems (EncFS) and synced across four machines (two at work, one at home, and my laptop) using Dropbox (which is another off-site copy, and has revision archives) and/or BTSync. Those four copies are all OS X Time Machine backed up (and revision archived) - and two of those Time Machine backups are rsynced nightly to separate drives in opposite locations - so all up (not couning Dropbox) I've got copies on 10 separate spindles in two physical locations, two of them in a locked filing cabinet (the work time machine and rsync disks). I've had a "primary computer" stolen before – and I don't intend to ever have that much grief if (when?) it happens again. I'm confident that even if all the electronics from either one of my work or home get stolen, I could be back into fully productive work-mode in half a day and one maxed-out-creditcard at the local Apple store. (If someone hits both my work and home locations simultanously, I suspect I've got bigger problems that whether I'll have angry clients shouting at me before the weekend…)
- Timothee 13y agoMy first question would be "how often does that really happen?". It's a legitimate concern at first sight, but for me, I pretty much never need to do that since I always have my phone with me. But if I do need to, I have 1Password on my phone as well and can get the passwords from it.
- SideburnsOfDoom 13y agoI have the encrypted password file on a usb thumb drive. I remember the master password. I view as fatally flawed any password store that uploads the encrypted password file to a remote server.
- gmisra 13y agoI am surprised by how few people are aware of this: https://www.pwdhash.com/ https://www.pwdhash.com/ Convenience provided via Chrome/Firefox extensions, portability provided by the website.
- Periodic 13y agoI second this. I've been using it for a few years now. It gives me great peace of mind knowing that my password on a site like HN is something like "e5wLoMB1kZ". I only have to remember a few passwords and yet each site has a unique password. Even in the event a leak of plain-text passwords I'm still secure in knowing that my other accounts won't be compromised unless there is a very determined attacker. However, you do have to put some trust in the extension and the website. Fortunately, the website has some good credentials and the extensions have appeared clean... for now.
- jervisfm 13y agoYeah, I did not hear about pwdhash and it sounds like a nice idea. One thing I have noticed though is that when one enters the same site password, you get the same "Hashed" password back to use. Yes, there is an extra step involved here so that buys you some security but I will be cautious in reusing site passwords. Imagine an attack where for the top 100 sites in the world, all of the most commonly used passwords are used to generate the "Hashed" (pwdhash) passwords for each site and compile that info into a big list. This can then be added to the candidate list of password that can be tried in cracking leaked hashes. The take way here is that even though pwdhash gives you domain-specific generated passwords, you will make to sure that you use a different site password as input to pwdhash for each site.
- Pxtl 13y agoIt's a start, but you'd need all the mobile platforms on it too.
- jdmichal 13y agoThere is also http://supergenpass.com http://supergenpass.com, which uses a JavaScript bookmarklet to do the hashing.
- ChuckMcM 13y agoWell until the recent 4.x / 3.x screwup [1] that 1Password did it has been quite useful (and like you, my 16 character password at Adobe, even if guessed, would not be useful anywhere else) [1] My 3.x was upgraded to 4.x on my Macbook (unbidden) and the only way to restore compatability with my 3.x on iOS is to pony up another $20. Can't go back to 3.x on the Macbook, not particularly happy about the upgrade fee on iOS.
- cstejerean 13y agoFWIW, I think version 4 is a worthwhile upgrade on iOS, and I see the price at $9.99 at the moment (at least in the US store).
- lancewiggs 13y agoIt was quite an astonishing move to break 1Password (mine is still broken) when Apple released their own free product.
- bentcorner 13y agoCrap, looks like my wife's email was caught up in the Adobe breach. I think she created an account for reading ebooks with Adobe DRM downloaded from our library. Consider this a heads up for married HN'ers, you should check their emails too.
- prawn 13y agoIn Australia, both my wife and I got mailed out letters from Adobe regarding our accounts being potentially compromised. Did that happen elsewhere as well?
- bricestacey 13y agoGot the same one -- USA
- vxNsr 13y agoI got an email but assumed it was a phishing attempt until I read that they were actually doing this.
- aragot 13y ago... Aren't password manager the #1 target for hackers nowadays? Imagine how much that wallet could be worth... How much bribe does the weakest 1Password engineer need?
- Twirrim 13y agoThen use a local storage one, like password-safe (Win & Mac. password-gorilla for Linux). Combine that with spideroak, dropbox, google drive or whatever file syncing utility you want.
- fuzzix 13y agoI generate passwords with something like: printf "/" ; openssl rand -base64 32 | sed 's/.$//' The leading slash was a nice tip someone gave me to not echo if you accidentally paste the password into IRC... Though if the password itself contains a slash then your client won't consider it a command and will echo it anyway, so do what you will. Anyway, each new account gets a new password you couldn't beat out of me, though you could probably get my password safe phrase, so do what you will. Generating long passwords like this highlights providers who enforce password length limits. Paypal's limit is ludicrously short. Hetzner's is limited too. edit more guff.
- shurcooL 13y ago> there are many to choose from This is the reason I don't use one... I still haven't decided which, even if _any_ is better than nothing.