Why your tiered password scheme is flawed, and what to do about it.
weblog.masukomi.org
weblog.masukomi.org
Also, without claiming that password managers are a bad idea, I can confidently say that the thing you can do that is worse than having a "tiered password scheme" is not having a "tiered password scheme". I just watched someone in the security industry go through this:
Blog SQLI -> Blog Password -> Yahoo Mail Password -> GoDaddy Password, Bank Password.
An email with your password is a sign of a bad security policy. Better put a unique password for that site. Use this for remember all those passwords:
And in the event of losing GMail access I download all my GMail emails to the local client.
That said, I trust more in Google than in my own ISP or domain registrar, I have lost my personal domain with my personal email address one time due their errors in the renovation.
This means that every account I have uses a unique password composed of both alphabetical and numerical characters.
I store each of them in my head, or re-calculate it if I forget them, but I actually tend to just remember them, maybe because they follow an algorithm (or rather, a set of rules) it makes it easier to remember them.
And, I'm not contingent on any software to remember my passwords.
While it might be a better approach than just using the same insecure password on every site, based on the attack suggested in this article, there isn't much benefit from your approach.
But hey, give it a shot; here are three random passwords (calculated using a slightly different algorithm than the one i actually use):
hotmail: 3m4m349 facebook: w45c033 aol: t41m325
Now, tell me what my Gmail password is.
password = sha1(masterpw1 + sitename + masterpw2)
I'm not sure you can deduce masterpw1/2 from a few passwords.
> Many perfectly smart people I know have one strong password they use for one or two online banking type sites.
Unfortunately, banks are among the worst offenders when it comes to disallowing special characters and limiting password lengths.
http://supergenpass.com/about/
It's a bookmarklet so you can review the code behind it and use it on any computer. You only have to remember your master password and it converts to a new password for each site. Usability-wise it's usually only 1 extra click - you put your master password into the web form's password field and the bookmarklet writes the generated password for that site over it.
I still wouldn't use it for banking or my email, but for most other things it's worked well.
I think it's too much of a bother to be using a password manager all the time. Especially when using public computers. It's not just the effort that bothers me. I have a feeling that doing something as extravagant as using a different password for each service will somehow make it more probable for people to steal your passwords.
I've been using the internet since the mid 90s, and I remember only one time when my password was compromised. (Granted, it is possible there were more cases that I just never found out about.) It was about 3.5 years ago, and I logged on to ICQ in a sleazy internet cafe. Some kid had a keylogger installed there and he later stole my ICQ account. I changed this password in all the places I used it.
Think of how much fun life would be if you woke up one morning and someone had compromised gmail, had godaddy send a password reminder, and then used your credentials to initiate and then authorize a transfer of your business domain to their registrar. Then a month from now you get a call: $2,000 or your site goes dark within the next minute.
And that goes without saying things like OpenID or equavalents. Ideally you just have one Very Trusted person to give a password to. (Of course OpenID has its own share of problems. )
Bottom line is that your passwords are always with you - either on your iPhone, or (in a pinch) on any nearby PC with a web borwser.
Overall it looks like a pretty nice app, and I like that it works across browsers and makes it so easy to retrieve your passwords.
I really don't like the reliance on .mac for syncing between computers though. I feel that .mac is totally overpriced.
To be honest, I don't use the iPhone app so much mostly because I would still have to type my primary password there and it's not convenient on the screen keyboard. Also it uses a custom browser (or a browser element inside the app) and not the regular Safari. That can be an issue for some sites. But I still have it in case I need access to one of my randomly-generated password.
Overall I highly recommend 1Password.
That argument does not make sense. Most sites do not send things out using my name, and those that do have very limited options for spammers. For example flickr, or Hacker News.
I certainly wouldn't consider "they may know my password, but they'll never guess my email address" to be reasonable security.