How I salt my own passwords and sleep a little better at night
peebs.org
peebs.org
The problem with this method is that if one of your passwords is leaked and cracked then it wouldn't be too hard to guess how your scheme works. This gets even easier if they have 2 or more of your passwords.
It seems to me that a scheme like this would have to be much more complex, which unfortunately would just make it a pain to use.
I really wish Google, Mozilla, Microsoft, etc would step up and build a better authentication system right in to the browsers, perhaps with public key cryptography like SSH uses - then we'd have automatic logins to any site you decide to trust, and no more passwords.
It's not about storage, it is about how to get people to use different passwords. Arguably, the passwords are not very different, but what matters is that they are no longer identic
Its still good advice to people who use the same password on all their accounts. 'just prefix the password with the first three letters of the hostname' will make sure they're slightly better protected in case of a password leak.
Try explaining this to a small child or elderly person, it's just not going to work.
The technology to do away with passwords all together already exists, we just need the right people (lets face it, it's probably going to be google) to standardise and implement it. It's no easy job but in my opinion is necessary for the web to move forward.
I just changed all my passwords so they're prefixed with 'www' but I'm not sure how that will help make them more secure. (j/k)
We definitely need better authentication methods. For example, why couldn't Google open up their 2 factor authentication method? Why is it that my battle.net account can have better security than my bank account?
Frustrating!
https://code.google.com/p/google-authenticator/
They include a JavaScript implementation and a PAM module. In fact, Dreamhost just implemented two factor auth that uses the Google Authenticator app last week. It works really well.
http://wiki.dreamhost.com/Enabling_Multifactor_Authenticatio...
In addition, Clavid OpenID integrates with the Google Authenticator app if you're an openID user.
I've been looking at the Yubikey+LastPass combo, which can also integrate with Google two-factor if you install a helper app. It seems like a nice solution, except that I'm really not a fan of the LastPass user experience.
But it sure beats using an identical password everywhere, and it does have the one major (and massive) advantage of using an identical password on n sites: you only have to remember O(1) things as opposed to O(n). And it can still be done completely in your head, as opposed to other schemes ("real" hashing schemes, password managers) which may introduce their own invulnerabilities or will lock you out from accounts on other computers.
I'm using a free password manager (KeePassX) with the file hosted on Dropbox for a couple of years now. I've not had any major trouble with it.
People might like to note, though, that my 16 character randomly password (lowercase letters and numbers for over 128 bits of entropy) was still cracked during the LinkedIn incident. I'm switching to 24 character passwords now.
Came across this forum that you last visited 7 years ago? Remember the password? With this technique you will, without resorting to password managers - and still have a unique password on every site.
Remember not to make your salt obvious though. In other words don't just append the domain name in front of the password or it will be quite worthless. Instead take for instance the third letter in your password and let it be the second-to-last letter in the domain name (and do some further transformations), and you're good to go. You will remember the specific password for sites you go to often but for any site you will be able to "re-generate" the password in your head.
What do you find so hard about "resorting to password managers"?
For me, I reckon adopting 1Password has _reduced_ the amount of hassle dealing with passwords causes me. 95+% of every website login has become command-slash-return. Registering for new sites has added a single click to the "do you want to save this login" popup.
Since I always carry my smartphone, I've _always_ got my passwords securely stored in my pocket, as well as on my Pad, laptop, and work machine. I find it hard to understand why people _don't_ use some sort of password safe software…
"command-slash-return" isn't acceptable security either, I must be able to lend out my computer without reducing the barrier to my online accounts.
Also if I lost my phone (it breaks or get stolen) I must still have the freedom to be able to use the internet...
Everyone I've ever met that to my knowledge uses a password manager has, in my presence, been limited by it. No way on earth I'd put up with that.
Transcribing passwords off my phone is always available as a last resort (most commonly used at the terminal in the datacenter, so extremely rarely). Almost all password entry is autofilled (via browser extensions) or cut/pasted from the 1Passwrod app.
"command-slash-return" - also needs my password safe passphrase (unless I've entered it in that last 5 mins and the machine hasnt slept or entered screensaver mode).
My phone is only one of devices with synced copies of my password safe data.
The only "limit" I've ever felt I've had since getting properly invested in using 1Password is that I now occasionally waste time having to "back down"from my default 16 random char passwords when somewhere won't accpet that length or charset.
Even without the cases of your phone being stolen/lost/battery-empty the hassle is just waay too much to even consider it.
then i tried lastpass, but i don't like the idea of my passwords beeing stored somewhere else (even though they are encrypted).
this sounds like a solid solution to the easy-to-remember but different-password-for-each-site problem. definitely gonna give it a try.
The integration might be less than for Windows and OS X. It works great for me on those systems, though.
i don't have my passwords on other computers.
I just keep a KeePass file in Dropbox. I also have a KeePass app on my phone.
Try KeePassX http://www.keepassx.org/ which works really well in Linux. It even has a hot key to push username and password into the appropriate fields in the browser.
I installed it a week or so ago (after trying others) and am pretty impressed so far.
Edit: I notice it uses MD5 though. Question: how secure would this kind of system be with bcrypt and an OS X Password Assistant "memorable" 12 char password?
OK, so with that out of the way, let's say you've chosen a weak (and common) password. If people start using this self-salting scheme, it's a fair bet someone else that will use the same self-salt as you, and that means two identical hashes in the database. That's bad news.
But it's also easy to fix. Simply choose some fixed salt to also add to your password. It could be the first two letters of your username, for example. That way, if "bobmarley" and "jackblack" both have the password "champagne" and both used the first four letters of the website for their salt, then on linked in one will be "linkbochampagne" and the other will be "linkjachampagne", and they can rest knowing that it's very unlikely that their password will hash the same as someone else's.