PasswordCard
passwordcard.org
passwordcard.org
Instead of having to store a number to regenerate your card, the card is (re)generated from a "master" password that you can memorize and never write down. You do not even need to print out your card, as you can generate your card online at any time.
I have a friend who uses this service; he has a complicated "master" password and simply uses the site domain ("news.ycombinator.com" for example) for the second field in order to generate the password to use on each site (HN).
For those who have personal policies of regularly changing passwords, just regularly change your "master" password and be sure to update your passwords on all affected sites (keeping your second field the same).
And it can be brute-forced too.
Just use something like 1Password or LastPass.
Security is tricky.
Compare that to a plain paper with a password written on it!
But yes.. security is all about trade of.
In this sense, Lastpass (passwords stored online) or Roboform (passwords stored locally) is imho better in that it makes it easy to use secure, one-time passwords for each website.
Thanks for the link. I'd run across some of those some years ago but since lost the references.
This may not be as secure as a random SHA1, but it's so random (and usually pretty long) that I think it's pretty solid.
One bad thing is that I have taken to having one password for all of my "really don't care about this" websites. Only for stuff where if it were compromised, I really wouldn't care (though I might care a little), but it's still not a great practice, and that password is weaker than my other ones.
Alternativly I use KeePass to store all my passwords and for the master password I combined all the passwords Ive used over the years, so its about 15 characters long and easy to remember.
However, I will occasionally need to set a new temporary password for an online account when I do not have r/w access to my KeePass file. In this case, I tend to use the same simple password until I have the opportunity to change it, so the Password Card / Chart can still come in handy.
I Like To Take The First Word Of Easy To Remember Sentences. (iltttfwoetrs) and put some random i->1 and a->@ and o->0.
This way, it's fairly secure and easy to remember.
(I'm sorry, that was awful.)
you can use as many passwords as you can think of, but only have to remember 1 of them.
While that scenario might not be realistic, for this type of thing, you have to plan for worst case scenario of needed to access you services now, without extra tools. Memorizing the password will always be the best, and if you are in situation where you accounts need passwords so difficult you cannot remember them, then you likely will also need to connect to those services at a moments notice. Start with a simpler password and work your way up in length and complexity over time, your memory can get longer with practice!