Jesus Christ, Use a Password Manager Already
pzxc.com
pzxc.com
The most universal and silent restriction seems to be on NUL bytes.
I don't know how they uniquely identify your system, but the technology is Java-based.
And that iTunes now forces one capital letter. I dunno, I think if you've used a special character you should be forgiven for not using a uppercase letter
Maybe they don't have proper parametrized queries and are afraid of SQL injections :)
1. I don't want a single point of failure, though I suppose an email account fulfills that role no matter what you're using. My email account password is 30-34 characters long.
2. I use multiple computers, multiple OSes, sometimes not owned by me, and sometimes multiple browsers.
3. Many accounts I couldn't care less if they got compromised; they get the same password as each other, which is still complex.
> hashing your master password with SHA-256, encrypting the result a default of 6000 times with AES, and then hashing it again
Any crypto-geeks around to say whether this makes it more secure or less? I've heard it said many times that multiple encryptions and hashings can actually make the encryption weaker.
> Many accounts I couldn't care less if they got compromised; they get the same password as each other, which is still complex.
Sign up on mywebsite.example. I now have the password to (depending on what accounts you couldn't care less about) your Facebook, Twitter, Hacker News, etc. accounts and can ruin your reputation by spreading false information.
See the PBKDF2 algorithm for a standardised example.
What I do have access to from most of those systems is SSH to a machine I control. I'd be willing to run a password manager on that system, but I haven't yet found one I'm willing to install. I'm not going to put Qt and X11 on the system just to run KeePassX. I'm tempted to write my own at this point. It'd at least solve the password management problem in way that I'm comfortable with (i.e. any problems in the solution are my own fault and if I get owned, I'm the only one to blame) and without having to send a copy of the encrypted database out to the cloud (except in tarsnap backups, but I'm already trusting cperciva with the keys to the kingdom there!).
Good luck getting into all my accounts. First you need to crack my dropbox account. Then you need to guess which file out there on the interwebs I use to protect it. Finally, you can try to crack the password I use. I'll even give you a clue: the password is less than 40 characters.
So yes, use a password manager. It's trivially simple and stress free.
- Set up dropbox on every computer I use.
- Figure out how to get keepassx to work on Android.
- Open up a password manager when I want to log into something. Oh, I can leave it open? Wait, is that secure?
- Figure out if there are any limitation of the password manager you've suggested, which you may have missed.
- Deal with a "password migration" if I decide to switch browsers, which will include an absolutely non-trivial search for some software that replaces an app that is now a crucial part of my daily routine.
I could go on, but password managers are most definitely not a trivial task -- they add a layer of friction that I simply can't bring myself to care about when it comes to security to my Gawker account. Computers exist to make my life easier, not as a creator of problems that require working around.
KeePass features an "Auto-Type" functionality. This feature allows you to define a sequence of keypresses, which KeePass can automatically perform for you. The simulated keypresses can be sent to any other currently open window of your choice (browser windows, login dialogs, ...).
By default, the sent keystroke sequence is {USERNAME}{TAB}{PASSWORD}{ENTER}, i.e. it first types the user name of the selected entry, then presses the Tab key, then types the password of the entry and finally presses the Enter key.
For sites or apps with weird forms you can customize the sequence.
The way OS X's "Keychain Acccess" handles this feels like a good compromise. After some timeout (a minute or so) the password gets hidden and you have to put in your master password to see it again.
At least if your passwords are in your head they will only have access to sites you entered while on that machine.
So my faith in password managers has been shaken. I greatly enjoyed having to ask all my clients for their passwords again.
I have a new system, but if someone ever got ahold of my drives who knew what they were looking for, that would be hellish
I worry about Dropbox + security. The fact that I'm sharing folders publicly with other people in the same directory that I have private data, worries me. Lots of room for human error
Why does 1Password need dropbox? It would make much more sense if they had their own cloud solution
Edit: Don't get me wrong, I love dropbox and I'm sure 1password is great. But I don't feel secure with dropbox (ever lost a file that was in your dropbox because you or a colleague made a mistake on a synced computer?) and I hate the idea that a person could have a copy of a single file with every one of my clients critical passwords, encrypted or not
There was a Security Now episode about it this summer [http://www.grc.com/sn/sn-256.htm], and it got the Steve Gibson seal of approval.
And it's not like 1Password doesn't encrypt what it puts on Dropbox.
The interface is less polished than 1Password, but since it comes by default on every OS X install I just use it. Meanwhile 1Password seems really annoying from time to time: it always asks to save passwords but seldom autofills for me. Maybe I just use it wrong…
Despite popular belief, writing down your password and storing it in a lock box is leagues better than storing it online. The number of people who have access to your physical belongings is many orders of magnitude less than the number of people who can attempt to compromise an encrypted database.
"Don't write your password down" might have been good advice in the 90s when most people only used a computer at work and the internet wasn't as ubiquitous as it is today.
You can also setup vim to read/write it easily
augroup GPG
au!
" decrypt before reading
au BufReadPre *.gpg set bin viminfo= noswapfile
" decrypted; prepare for editing
au BufReadPost *.gpg %!gpg
au BufReadPost *.gpg set nobin
" encrypt
au BufWritePre *.gpg set bin
au BufWritePre *.gpg %!gpg -ear email@wherever
" encrypted; prepare for continuing to edit the file
au BufWritePost *.gpg silent undo | set nobin
augroup ENDIs there any chance you or anyone else could point me to a howto or something similar?
1) Add the text block above to your ~/.vimrc file, change the email address to be one of your gpg keys.
2) Edit the file: vim somefile.gpg
3) Save the file
Am I missing something? Is there some inherent flaw in these managers? Firefox will even encrypt the passwords by default and allows the user to set a master password. Exporting passwords is a little annoying, but how often is there a need for that?
-Genuinely curious
I find it interesting that they are generally used to express awe, surprise, or to invoke a sense of gravity or urgency -- opposed to other swear words which generally seek to disgust, communicate an offensive attitude, or invoke taboo to draw attention through shock. The religious oaths seem to me more like the oaths of fantasy ("By Turin's beard!", "I swear upon the sword of my father", "In Vela's name") than the language of shock and offense ("scurvy maggots", "Why don't you go stick your foo in a bar and then baz it?")
I'd speculate that they're referencing the strong emotions religious people actually feel -- the awe and gravity of the sacred, a cry for help in a moment of fear, not the offensive force of blasphemy. The amplification is always toward the sacred ("sweet Mary, Jesus, and all the saints") or the silly ("Jesus H. Christ on a pogo stick"), never toward the offensive. "Jesus" amplifies to "Jesus Christ" or "holy Jesus", never to something like "Jesus' stinkin' piss".
Most chinese swearing has to do with a) actual cursing (damn you!), b) penis and vaginas and c) insulting your parents. So basically the same as English once you strip out god/lord/christ.
I realized that without a password manager you're forced to choose between 1) having one super-secure password and 2) having multiple easy-to-remember passwords.
My compromise is this: have a password template. This is a string that changes in a predictable way based on the site. This could be something as silly as "password_${site_name}", making my gmail.com password "password_gmail" and my twitter password "password_twitter".
Obviously, the formula won't be terribly complex, so if I tell yo my gmail pass you can probably figure out my twitter pass given though time. But that doesn't bother me, since I'm mostly concerned about gawker-type incidents where my password is among thousands of others, in which case the bad guys will exploit the 90% of the passwords that do work instead of trying to reverse-engineer those 10% which don't.
There are also several options for multi-factor authentication for an additional level of security.
Okay, for a serious situation, I'm using a basic text storage then encrypt it with a trusted modern encryption system, high bit level.And some cloud computed storage web app that already moving on the new way to store and encrypt your password. That's it? Nope, it's useless.
But for real, there are lots of another way to store your password than using a password manager or a computer. Sometimes we can do it manually. For your life, use your idea. Peace.
• It's based on MD5.
• It repeats the hash 10 times. Typical key strengthening functions will do at least 1000 iterations, and at least 10000 seems to be becoming more common.
• Each time it repeats the hash, the output is encoded with a variant of Base64.
• The implementation of Base64 is deliberately nonstandard. + and / are replaced with 9 and 8 in the output (respectively). It pads with A, not =. The point is presumably to avoid generating special characters that could be disallowed by some password systems. This actually seems like an unintentional benefit to me: while it theoretically increases the probability of a collision, it does make it slightly more difficult to recover the original passphrase from the hash, or so it seems to me. (Any cryptographers want to comment on this one?)
• Hashing is repeated until it generates a password that starts with a lowercase letter and contains at least one uppercase letter and at least one number. The first restriction must come from some actual site, but it hardly seems common enough to enforce.
The biggest risk is in a site fishing your master password, though their "mobile" version allows you to run it in a different window. All in all, I think the concept has promise, but the implementation could be significantly improved.
Even if that problem didn't exist, I'm not sure I'd want all of my passwords anywhere in browser memory.
I can't seem to find information about it anymore.
But seriously, I visit so many sites and use so many different computers that I have my passwords indexed in a little black book encoded with my own personal code. They would have to pry it from my cold dead hands to get them.
set cm=blowfish
:X filename <--- encrypts with blowfish
I have Vim everywhere I work. Blowfish is "good enough" for me. :-)
This is me, happily switching from my hacked together aesfilter solution.
https://github.com/scrod/nv/wiki/Database-Security