5 ms·
I am using KeePass Password Safe v2 (while on Windows), and KeePassX on linux and OS X. I use a strong password, and a key file, which is just a blob of random
by jiayo 11y ago
I am using KeePass Password Safe v2 (while on Windows), and KeePassX on linux and OS X.
I use a strong password, and a key file, which is just a blob of random bytes. The encrypted password database (.kdbx) is published to Dropbox, which handles sync across devices. The key file (.key) stays on an encrypted USB stick on my physical keychain, and is physically backed up in a few safe places. It is never published online. This makes it effectively a second factor.
I have a domain, example.com, which is set up for wildcard email forwarding. When I sign up for a service, I use servicename@example.com (recently I have started obscuring this a bit more, e.g. srvcnm.49jg49kf34@example.com). This limits password reset exposure, and also the ability for other services that are in cahoots with each other to link my accounts together by email address.
Everything connected to this domain (registrar, DNS provider, email provider) is protected by separate TOTP 2FA tokens.
I simply do not access any authenticated services if I don't have access to KeePass and my password vault.
I have over 250 entries in my vault. At this point, it's less about remembering and generating passwords than it is about keeping track of what I've signed up for and when. Some things, you only look at once every few years, and my S.O.P. before KeePass was usually password resets.
For extremely high value accounts, I have memorized a "prefix" which I prepend to generated passwords. This limits exposure in the case my entire password database leaks, to just things like hackernews, reddit and other low value services.
I do not use KeePass for my dropbox password, because I could end up locked out entirely.
So this is really 3 things to remember: Password vault password, Dropbox password, and high security prefix.
There are some weaknesses in this scheme. As another user mentioned below, I am not invulnerable to an @N style hijacking. Someone could socially engineer my registrar, DNS provider or email provider, hijack my email and then initiate a password reset. I'm not sure how to defend against this. Common knowledge is to not use custom domains, since it's easier to hijack example.com than gmail.com, but for me the value of having unique email accounts per service is too high to give up.
The other obvious point of vulnerability is keyloggers and trojans that attack the KeePass processes directly. This is not something I've spent a lot of time thinking about. It is a scorched earth scenario, and in that case I won't be the only one in trouble.
This method has served me well for over 5 years. I've acknowledged there's some flaws here, but I fundamentally do not trust any of the online password management services (LastPass, 1Password, etc.) and I find the idea of paying to store/access them distasteful at best and extortionate at worst.
edit: I also use KeePass to generate my security questions. Very few online services are savvy enough to use a one-way hash on these questions, that are the keys to the castle. I've had to recite these to support reps over the phone, who can see them in clear text.
e.g.,
What was the name of the street you grew up on? => xcmqbbpgpuuxyrdw
What was your first pet's name? => owuynnfhwscgigciq
- ams6110 11y agoNitpick, "mydomain.com" is a real domain (registrar). Use "example.com" for example domains.
- jiayo 11y agoFixed, thanks!
- crobertsbmw 11y agoYou probably already know this, but you can set up unique emails through gmail using the "+" character. name+servicename@gmail.com. This will let you keep track of who is using what email address. Although, as this becomes more common knowledge, people could just strip off the anything after the "+" when saving email addresses.
- unclebucknasty 11y agoSad part is that, even with all of this, you're only as secure as each service not being otherwise breached, and that scenario is probably more likely in aggregate than your credentials being compromised. We are all as vulnerable as the engineering practices of each service with which we engage. We (especially in the tech community) tend to focus strictly on tech solutions. But, one of things that isn't discussed nearly enough is the legal aspect of all of this. That is, penalties for hacking, international cooperation, etc. As it is, the scammers have an unlimited free pass to just keep coming at us/services. The worst that can happen to them in most cases is that they simply don't get what they are after. It's all upside and little risk. With that motivation, they will simply persist until they find the weak links.
- Buge 11y agoWhat registrar do you use?
- tokenizerrr 11y agoWhy not use regular Keepass on Linux? It runs under Mono.