6 ms·
> The main issue I have is password that I don't use often at all. I usually can't remember them, or if I can, I cannot associate between password and website.
by sehrope 12y ago
> The main issue I have is password that I don't use often at all. I usually can't remember them, or if I can, I cannot associate between password and website.
Yet another reason I love using a password manager[1]. Besides letting you have unique passwords for everything (which is a must), it solves the "What the heck was the password for XZY?" issue when you haven't logged into XYZ in 6 months.
People really should just use a password manager. Yes it's a pain some times (mainly using mobile) but that's just something you live with. The rest of the time though it's way better than trying to remember silly thing like "Capitalize the second letter of each word" or "Replace the last letter with a digit that denotes the number of words in the phrase"[2].
Long passwords are a solved problem and the solution is not reinventing the Caesar cipher, it's to have a single long diceware password and use a password manager for the rest.
Oh and enable two-factor auth everywhere that allows it and vote with your wallet to choose businesses that do. For example, if your bank doesn't support it, find a new bank.
[1]: I suggest KeePassX: https://www.keepassx.org/ https://www.keepassx.org/
[2]: The article suggests things like this to make sure your password unique/dictionary proof. Forget that and just use the password manager directly.
- higherpurpose 12y agoWhat if there is some bug that resets your Keepass/Lastpass keys? Don't you worry about something catastrophic like that could happen? Because then you'd lose access to all websites, right? Or do you rely on the fact that if you lose them, you can recover say your main e-mail password through another e-mail, and then you can recover all the other passwords with your main e-mail?
- Adirael 12y agoYou should keep incremental backups of the password database. I have four backups of my 1Password database: * Dropbox (which lets me recover a deleted file up to 30 days) * Time Machine * BackBlaze * Monthly HDD clone
- reedlaw 12y agoI also like KeePassX but its major flaw is not being able to sync or merge databases. That has led me to consider using password-store[1]. Has anyone found a way to overcome the sync problem with KeePassX? 1. http://www.zx2c4.com/projects/password-store/ http://www.zx2c4.com/projects/password-store/
- mikegioia 12y agoI store the keypass database in dropbox so that my phone and other computers can all access the same db. if you're worried about the security of that you can even take it 1 step further and add a keyfile to your login requirements. you could just store the keyfile outside of dropbox on the devices.
- reedlaw 12y agoThat doesn't solve the merge problem. What happens when you edit a password on one computer and then another password on another computer before syncing?
- fractalis 12y agoIs there much difference between KeePass and KeePassX? I'm assuming the latter is a bit more cross-platform friendly? I use the former, since I'm on Windows, and use VMs for any dev related work. KeePass seems to have a good system in place for synching versions. Using GDrive, if I edit my pass on one machine when I try to add a new password from a second machine I get prompted to either Sync the file first or just completely overwrite it. I've yet to encounter an issue where KeePass gets confused as to what's changed and end up losing passwords in the process.
- sehrope 12y agoYes the lack of syncing is notably missing. That's kind of the tradeoff you get for not using a central service or listing the sites themselves in plaintext (see my note about pass below). I handle it by having a separate private repo for KeepassX and syncing the repo whenever it's updated. It's an opaque blob so there's no real history but it makes it easy to keep my desktop and laptop in sync. I don't modify it too often (seriously how often do you create new accounts?) so it doesn't feel like much of a pain but maybe I'm just set it in my ways. Pass looks interesting though the convenient way of using it (plaintext name for each site) leaks information. If you're willing to give that up then it sounds like a good idea.