Two-factor paper passwords
blog.jgc.org
blog.jgc.org
You will soon come to the conclusion that it is still easier to teach people to use a password manager for this because these schemes are nice but only get you this far before you have to revert to remember that single password again.
For example; your "password" could be a combination of words, numbers, and characters while the "thing you know" is something like capitalizing the even or odd first character corresponding with the even or odd number corresponding to the first letter of the site or company, and combine that with the even or odd sequenced number and character in their sequential location in the password or at the end or beginning of the entered password.
I'm sure I could describe that more clearly if I tried.
The second main reason passwords suck (after the fact users trend to choose weak passwords) is that developers implement all sort of contradicting password rules.
Can't wait till we check min entropy and otherwise don't care.
Oh, but they have a 4-digit pin, too! That makes it oh so much more secure.
They had two factor authentication though, with a phone call or SMS. What happened if you forgot your password? Well you had to reset it, using only phone call/SMS, of course!
It's the most bizzare password requirement I have ever seen and I am pretty sure it's not secure. Have I mentioned it only works in IE and uses ActiveX controls?
Inclusive, I hope.
american express use to enforce insane limits on passwords back in 2010[0]. 6-8 characters for passwords, no special character and had to have 1 letter, 1 number and it wasn't case sensitive. unfortunately _I_ had an amex card.
that page i linked to also has a reply from amex support who shows little knowledge about the difference between passwords and website encryption.
they eventually started expanding that limit from 6-8 characters to 8-20 characters around 2012? 2013?
[0] http://securitywatch.pcmag.com/e-commerce/284119-amex-passwo...
At Schwab I'm using 31 characters randomly generated by LastPass for a login name but they limit things to 8 characters for a password.
Absolutely crazy. Even if they are not having problems, why should customers like us have to worry about it?
http://www.schwab.com/public/schwab/client_home/password_for...
Between now allowing very long passwords, the free 2 factor token (hardware symantec vip, not SMS based), and being able to lock your accounts with a voice password/passphrase that you must give the rep to discuss your account on the phone (so then just SSN/mothers maiden name/birthdate isn't enough), I think they've pulled quite far ahead lately. It's better than any of the other banks I've used.
[Note: voice password is not their voice fingerprint sillyness their reps will think you are asking about at first]
I hope neither it nor my email has any security breaches.
1. I would 100% forget which symbol goes with which site.
2. The length I choose for my password may be too long/short for a given site.
3. Some sites require special symbols; some sites forbid them. Now I have to pick out my symbol based on the site's requirements, not ease of memorization.
I could use a password manager but I don't want to be dependent on one piece of software, there's too many failure modes. It's already bad enough that all my accounts share a limited set of email addresses.
The main issue I have with schemes like this is that there's no repository of global identifiers for websites and services. I can build a password for blizzard.com, starting from say "bl", then I forget about it and five years later their website is now activision.com, and I wonder why I can't log in with a password built from "ac". It's a minor issue since password resets are a thing and rebrands are rare but still..
[1] https://en.wikipedia.org/wiki/Tabula_recta
[2] http://lifehacker.com/5715794/how-to-write-down-and-encrypt-...
You also have the problem of some domains requiring alphanumeric only, etc., which then limits what characters you can use in all your passwords.
alphanumeric only (some would say avoid such sites [shrug]): just continue along the path skipping over the non-alphanumerics until you've got the length you want.
> PS If you are planning to do this... please consider using a password manager first.
which shows that he is aware that this is only a second-choice solution.
For example, to get your password book, the attacker must have physical access to you. This immediately lowers the attack surface. Your passwords can't be sniffed out of your clipboard. Your passwords can't be brute-forced by someone who compromises by one of your accounts (even the account which stores the encrypted password vault). You can burn your password book to ensure secure deletion.
Yeah, a password manager is still probably better; even the OP acknowledges that. OTOH, how secure is your password to access that manager? How frequently do you rotate it? What happens when that password is compromised?
So if you change the master password regularly, they'd need to hack a database in that time window and steal your codebook. I highly doubt anyone would put that level of effort in.
I think that that format acceptably blocks the two most dangerous groups for a persons privacy: tech savvy remote hackers, and tech inept local snoopers.
Remote hackers are tech savvy, but probably don't have physical access to your house and don't care enough about a single user to get it.
Local snoopers are probably not tech savvy, and therefore probably won't have access or know how to find a hacked database.
If there really is a tech savvy local snooper, they will know they can just install a keylogger onto the computer that they almost certainly also have physical access to.
You could just open the LastPass Vault in a separate window and copy passwords out of there and it would still be worth $12/year for me.
That being said, try right-clicking in credential fields to find more fine-grained account selection.
And maybe stop by their support to find out if something is wrong with your setup.
1. Remember a high-entropy “base” password that is likely to pass complexity and length requirements
2. Invent a weird way to incorporate the name or domain name of the product you’re using into this password to make it unique (e.g. “put the second letter of the domain name as the third-last character of your password”)
Advantages: Memorable but unique password for all or most services, no need for physical books that can be stolen, works on any machine. If one of your passwords is discovered, it's basically useless beyond that service unless the attacker knows your step 2.
Fair point but often there are not too many possibilities.
What is my username
Your email address, in most cases.
My password is too long. My password is too short. My password has the wrong characters. My password does have enough numbers. My password doesn't have enough special characters. My password has too many numbers. My password had too many special characters.
Occasionally a problem, but I have been using this method for years and have maybe two or three passwords that I have to manually remember for reasons like this.
If you are specifically targeted they can compare your password in two hacked databases and find out your scheme.
True, but then one can similarly come up with scenarios for most other schemes.
I agree it's not perfect and won't cover every case, but it has worked well for me.
>Your email address, in most cases.
I have accounts with, like, a bazillion different financial institutions. They all require user names that have length requirements and special character/number requirements. I would forget all my user names if it weren't for password managers.
If you have one bank, no 401k, no IRA, no credit cards, two social media accounts, one email address, and do all your online shopping on Amazon, and not much else this sort of disadvantage won't pop up but once you get into multiple accounts on multiple sites it does not scale.
If you have many password schemes you'd also have to remember the password rules for every single site.
1) go to site 2) enter email address (cached by the browser) 3) go to email account 4) click on long, unguessable link which is only valid for 2 minutes)
er..that's it.
You could even skip the `enter email address` step and just get users to keep a link provided in the initial signup process. This link could either be the one you always use to log in, or for better security could prompt the remote site into sending you another single-use login link (as above).
I use keepass, but sometimes for services that I use once per year, I just go via password reset and change password to a long random gibberish and do not even bother to write it down to keepass.
Do yourself a favour and use Chrome, buy two U2F keys, register them both, and put one in a safe-deposit box.
It's also phishing-proof, unlike SMS or TOTP.
Soon: Chrome is the new IE.
Ironic if John's blog caused more checks for that site.
But I have a good memory and I trust it much more than my ability to keep things organized and make routine backups. It's easy for me to generate more or less secure passwords that I can memorize, like:
shrebangodiKe24+ binarKedonado!3297 Miregofinar--0009
etc.
Those will last for a few more years, until password crackers will become so fast that it will be impossible to remember any kind of secure password anymore.
Then, I'll be screwed.
Dropbox with KeepPass on Windows / KeePassX on Mac / MiniKeepPass on iOS works beautifully for me.
The biggest issue is that the passwords are usually copied via the clipboard, so any program accessing the clipboard could copy your passwords. It's of course up to your own assessment whether this is a problem worth consideration or not.
Unfortunately many places consider this information sensitive and protect it fiercely.
I don’t think you need to worry about that. See https://news.ycombinator.com/item?id=3140898
Comparing this to not using password managers, (in my opinion) I would say that LastPass is both easier and safer alternative than not using one.
Generate your passwords with a simple algorithm with a servicename and a keyphrase. Works really well.
Note that "a good memory" doesn't "scale" or remain constant over time. Plus more importantly you are assuming that something minor or major won't happen to you where for some reason you aren't able to remember things very clearly like you thought you would be able to.
Reference? https://www.schneier.com/blog/archives/2014/03/choosing_secu...
Ten years ago, this scheme might have worked, but now, attackers now about such schemes and have integrated them into their tools.
Yes, LastPass and its ilk have their challenges, but they are far superior to this security snake oil.
Which means it is no alternative at all. I'm a professional security consultant. If a client were to ask me to list the alternatives to using a password manager, I would say "Being hacked".
They would ask what else? I would say "That's it, that's the list".
Bad security advice is as bad as no security advice.
Having amateurs provide well-intentioned, well-stated, well-described, terrible, terrible ideas, ideas articulated well enough that they seem plausibly good, and having them being supported by people who ought to know better does the entire industry a disservice.
What would I tell my Mom? "I'm sorry, I really am, I know it's hard to use, but it really is the best alternative, the only really secure alternative, unless you want to keep a book of really strong passwords locked in your desk and only ever use your computer there."
Which, for average users and average use cases, is no alternative at all.
Really? Attackers steal physical password books? Do you have any examples?