How do you manage your passwords?

Well you are saying you do not trust security of 3rd parties, but yet you store your files on Azure. So you are trusting their security.

You're trusting everyone along the way too - you're not going to be able to exclude your ISP and GMail from the equasion. It's not about not trusting anyone, it's about mitigating the risks sufficiently to ensure a comfortable level of security for the secrets. I mean - the passwords themselves are to access Gmail, Dropbox, etc. etc. and yet you trust Google with the mail itself and Dropbox with the files themselves.

The secret is not to store the passwords in the cloud (like Lastpass does) but on your own device(s) and only and index on in the cloud. That's what I prefer to do. The master password directs the app to the index used to locate the correct credentials.

I should probably release this as $ware.
 
The secret is not to store the passwords in the cloud (like Lastpass does)

Lastpass stores your encrypted vault in the cloud which is protected by your master password. A salted hash of your master password is sent to lastpass so even if hackers got hold of your encrypted vault or salted hash there is no way for them to decrypt it.

With 2FA it makes it virtually impossibly for unauthorized access.
 
Lastpass stores your encrypted vault in the cloud which is protected by your master password. A salted hash of your master password is sent to lastpass so even if hackers got hold of your encrypted vault or salted hash there is no way for them to decrypt it.

With 2FA it makes it virtually impossibly for unauthorized access.

2FA is optional and call it what you like, your passwords are in the cloud. Bottom line? Lastpass software is not open source and you're trusting them to keep your secrets. You can be guaranteed they are a hot target. I prefer to DIY.

Any guesses what happened on this day a year ago?
http://www.pcworld.com/article/2936...at-you-need-to-know-do-and-watch-out-for.html
 
Well each to their own. I prefer using lastpass and am pretty confident knowing my data is safe.

I know about the hack. They didnt even get access to anyone's vaults and even if they did then it would have been useless - they are encrypted.

Just because something is open source doesn't mean its anymore secure. How many open source solutions have really been vetted properly. It takes a huge amount of effort and knowledge to go through thousands and thousands of lines of source code looking for cryto flaws. Look at what happened to TrueCrypt when they finally decided to audit the code after years.
 
Last edited:
I have a personalised scrambling system ("key") in my head, which I use to encrypt every new password. I store clues to the scrambling method (i.e. not the key or the password) on a page in Google Drive, easily accessible from anywhere I can log in to Google. So I can reverse engineer my passwords by just looking at a site.

I have more problems remembering my username, which has evolved over the years... For that, there's LastPass.
 
Well each to their own. I prefer using lastpass and am pretty confident knowing my data is safe.

I know about the hack. They didnt even get access to anyone's vaults and even if they did then it would have been useless - they are encrypted.

Just because something is open source doesn't mean its anymore secure. How many open source solutions have really been vetted properly. It takes a huge amount of effort and knowledge to go through thousands and thousands of lines of source code looking for cryto flaws. Look at what happened to TrueCrypt when they finally decided to audit the code after years.

Not having a go, just personal preference. I'd choose Lastpass of the lot if I didn't do my own system.
 
No problem. Would love to see your code if you ever go open source :)

I am toying with the idea - though I'll admit that part of the point of DIY is to be the only one who knows and uses it. I've always maintained - do your own home security for the same reason. By all means link up to armed response, but be the only guy who knows where all the stuff is hidden :)
 
...and very easy to crack if you guess / see just one.
You are more than welcome to crack mine if it's that easy!

Edit: But you're not completely wrong... I'd say alternation is the key.
 
Last edited:
how do I manage my passwords?
I managed to loose it :erm:

Therefor I've...


;)
 
Top
Sign up to the MyBroadband newsletter
X