3 ms·
> Use a password archive (e.g. KeePassX) encrypted with one really, REALLY good password you'll memorize (plus a keyfile, should you feel paranoid). One more v
by sehrope 13y ago
> Use a password archive (e.g. KeePassX) encrypted with one really, REALLY good password you'll memorize (plus a keyfile, should you feel paranoid).
One more vote from me for KeepassX with both a long, unique passphrase and a keyfile. Once you start using a password manager it's impossible to go back to trying to memorize individual passwords (which is a good thing) and you'll be hooked for life at the convenience.
One tip: make sure to increase the number of rounds of key derivation for the master password (should be under "Database settings"). The default is relatively low. There's a handy button with a clock on it that will perf test your computer and pick a number of rounds that is approximately 2 seconds of CPU time.
> For default, I have chosen 60-character password length, upper-lower-numbers-spaces-special characters mix (as a rule of thumb, a longer password is preferable to a more complex password).
Yep when it comes to passwords, long beats strong.
For answers to "secret questions" (which arguably are one of the stupidest concepts in account security) I follow the same rule. Long, random gibberish answers. Ex:
Q: What's your first pet's name?
A: gVr5nlLy0BLPu6OpW5YUPVMtHXqy5xxr2UMUbCoSTIR3KmPTfdl8Ml8ckfbDC7Pw
Q: Where did you go to high school?
A: Wdn3hohFxq2H4f7y8n501gwlPGZLlKDIDusWA0dGm9NEaabwogh9DUKngDy2zabC
I think it'll be pretty funny if I ever have to read one of those over the phone.
>One of the worst offenders seems to be Skype, with its "maximum password length: 20 characters, no weird characters allowed."
Yes that's pretty stupid and it's not just Skype, it's also Hotmail/Outlook and "Microsoft accounts" in general (ex: Windows Azure). I don't remember if it was always like that for Skype or if it happened after the Microsoft acquisition though.