I know none of my passwords
aley.me
aley.me
Just use a long and random 1Password, and store it in the OSX Keychain (1Password supports this). Then back up your user keychain with the rest of your files and don't forget your login password. Alternately, Mavericks (which comes out in a week) will sync your Keychain items to iCloud for you.
This is all moot though because 1Password is a pain in the dick to use on iOS, and Apple's using their lack of plugin support for MobileSafari to hinder competition. In Mavericks' Safari, you can now save passwords for forms that specifically attempt to disable password storage, and sync those encrypted passwords to iCloud. This wouldn't matter much... but that sync now works with iOS7's MobileSafari, where 1Password can't load a browser extension to compete.
TL;DR: Cool story, but 1Password unfortunately becomes OS-bundled obsolete in a week.
So it's more than just a secure password storage/generation program, it's a centralised system for all your important, easy to lose/forget details.
I don't know how much work Apple are going to put into Keychain, but it would have to be a lot for me to switch.
On iOS7, it uses the iCloud keychain (written to by Safari from 10.9 Mavericks) to autocomplete forms. Also, all the iOS tabs are available on the desktop and vice versa.
Yes, I use 1Password to store other data, but its primary function is credentials for websites, and anything that does that inside of MobileSafari automatically blows 1Password out of the water.
Also, I always think that it's well and good having a super secure password/password manager, but that's not going to stop me accidentally typing it into a search box, someone looking over my shoulder, accidentally copying and pasting it into and email, or something equally stupid.
1P has some cool features to help prevent some user error (deletes the copy and paste history after a few seconds, auto locks the phone app, etc) but all it takes is some other dumb error on my part to circumnavigate all of their encryption.
The convenience outweighs the risk for me at the moment.
Before that, I used to use secure notes in Keychain.
I can't speak for 1Password, but in general you can have more than one yubikey so that doesn't happen. I have a couple of backup keys in case something goes wrong myself.
Which is why I keep a single GPG encrypted text file with all the login stuff to things that matter. Only one password to remember and everything is backed up regularly.
OP made it clear one of the two items being combined is "short" and hence if the other item is known it would be much easier to brute force.
(In your lingo, it would be like knowing the password and then having to derive the salt, which is easy with a small salt.)
Once you've set it up, you require two passwords to log in: one you memorise; the other you read off your mobile app, and is regenerated every 30 seconds.
[0]: https://helpdesk.lastpass.com/security-options/#Multifactor+...
Personally, I would not recommend any of the cloud based solutions, for the simple fact, that any slip up in their security and you are hosed. These are your crown jewels, do not outsource this!
UPDATED: sentence structure.
EDIT: with your edit everything now makes sense :)
Not sure what the advantage is.
Dropbox keeps historical versions of your files. My concern is that, if an adversary can get multiple versions of my Keepass file which they know are a sequence with small changes between them, then they are much more likely to be able to devise an attack. I haven't looked into this any deeper yet.
I've been working on my net security as well and I've had a hard time compromising security vs convenience and fault tolerance. My situation is made a little more complicated because I don't have a smartphone which rules out mobile based key vaults.
I want a minimal set of dependencies to access necessary accounts, like my gmail. No file I can lose, or password I might forget. I've decided to rely on an ok password and google's two factor auth.
Less important accounts are stored in keepass protected by a key file and password, but I'm worried about losing the key or vault file.
I am putting a lot of faith in the security of KeyPass, as I don't put a lot of faith in DropBox to keep the file secret. If DropBox's sync system wasn't so simple/unobtrusive I'd use something else.
Then as a last step measure, there are backups of the keepass file in case a machine or dropbox have issues.
Perhaps consider using Bittorrent Sync[1] for synchronisation.
For practical purposes, it's similar to using DropBox, the key difference being that instead of syncing with DropBox in the cloud, you are syncing folders across hardware you control. The hardware could be different computers, phones, tablets etc.
As an extra safeguard for KeePass, I use a key file in addition to the password. The key file I also keep in cloud storage (in case any of my machines die in a fire), but on a different cloud storage provider. That way I can always reconstruct my password environment, but it would require compromising two cloud stores and keylogging my password to open the safe. (Or access to one of my local machines and a keylogger, but in that case I'd be hosed anyway.)
It seems like this is an interesting counter to the recent budding trend of arguing that "something you know" (passwords) is broken and we should all throw it out and switch to "something you have". This shows that a user can unilaterally convert "something you know" into "something you have", and unlike the inevitable clusterfuck of trying to standardize on "something you know" with the inevitable gold rush of competing, fragmented standards, resulting in users having to have an unbounded number of "things" in their possesion [1], authentication consumers can continue to work with standardized password approaches.
It seems to me that rather than rewriting the Internet to not use passwords, we'd be better off making this approach even easier (although it's not all that hard right now, really).
[1]: Yes, I'm aware of things like RFC 4226. History's pretty clear though; if there was more value to capture in this space it would break into proprietary fragments in a heartbeat. All the proprietary fragments would probably be beaten down by RFC 4226 in the end, but there would be an unhappy few years in the middle.
It really doesn't. This essence of "something you have" is that you really, truly must have it for authentication to work -- every time. In this case, if you capture the data on the Yubikey once you never need to have the Yubikey again (since he's using the static slot). Or to flip it around, if you just once leave your Yubikey in your pocket in coat check, or in a checked airline bag, or in your USB slot when you go to a meeting, etc., it is potentially 100% compromised without your ever knowing.
This is why true "something you have" systems like Google Authenticator, or the actual Yubikey system as it was designed, use constantly changing keys.
He needs both to log in.
Something you have exists in the form of things like smartcards. Crypto stick, https://www.crypto-stick.com/, being a great and user friendly example of.
Unfortunately, by default it uses MD5 and 8-character passwords. I always set this to SHA256 and at least 12 characters when first installing the extension on some device/browser.
Most sites play well with this, but there are exceptions: having to change a password is a bit ugly when the passwords are generated from a given master password and the site's domain name. A more common problem is when a site refuses to accept certain characters in the hashed password or when a site requires some number of digits and uppercase letters, for instance. I currently just store these exceptions with Keepass.
I see 1Password being mentioned a lot but I started using PasswordMaker and Keepass well before I'd first heard of 1Password so I don't know how it might compare.
I only know my master password for Lastpass which is a kind of random 14-16 char long and complex. I type it once each morning and it goes fast to type. With that I access my other 334 random generated passwords. But I do know my password for email just in case.
My e-mail password was created randomly based on 12 uppercase/lowercase letters, numbers, and symbols. I memorized via muscle memory. My master-password-database password is the same, but 18 characters. I know more passwords, but these are the only two I need to retain.
You can also be pragmatic about your accounts. Do I care if my PontiacSunfireCarClub.com account is hacked? Or my NewYorkDailyNewsTime.com account? No, I don't. So the password is irrelevant.
This doesn't make too much sense. While stronger passwords are harder to remember, if you use them multiple times per day, you'll have stronger memory of that password. Its hard to forget a password you have to use a few times per day...no matter how long or short it is.
Additionally, stronger passwords are not always harder to remember. There are some great password and memory techniques that makes long complicated passwords easy to remember.
E.g. LifeislikeaboxOfChocolates,youneverquiteknowwhatyou'regonnaget!
http://arstechnica.com/security/2013/10/how-the-bible-and-yo...
1) setup your password store up with a strong password and a key file
2) keep your keyfile on your local machine and a backup on usb etc, not cloud
3) now you can backup your db into cloud eg. spideroak, dropbox
4) on your other machine (work laptop, mobile, ..) copy in the key file, sync the db from the cloud
Now, you have a password manager that works on all of your devices - syncing automatically, safely.
This works for me. I know where the db is at (which cloud provider) and can be sure it's inaccessible without the key file + password. Any thoughts?
a) Get a fire-resistant lockbox, and b) have a safe deposit box at a bank.
Hmm how is 1password synced... you could corrupt the file and trust it to be synced somehow?
1. Use a different password for every account
2. Always use a gigantic, mixed case alphanumeric password with special characters for maximum entropy
3. Never, ever write any of these passwords down! ;)
Write the master password down until you've learnt it, and write it down in a safe place in case of brain injury.
Treat that piece of paper with the respect it deserves - keep it very safe.
Obviously, don't leave passwords in draws or on post-its near the computer or pinned to the wall.
However as others have said, you need to have a way to get to the full password somehow, likely in the form of it written down and stored in a safe, at home or in a bank. Or in somebody else's password vault.
Actually, that's something I haven't seen much and that I have done myself manually only: the ability to secure this information by spreading the database with multiple trusted parties. Similar to what Snowden has done I understand: no-one can access the information by themselves, but you can piece together whatever information you need from multiple people. I know some stuff exists like this, I just haven't seen for password vaults specifically.
{EDIT: Was the submission edited after being posted here? Because a bunch of people are saying that the password dies if the Yubikey dies, even though the submission says that the password is backed up independently of the Yubikey}
Yubikey is nearly brilliant. Not having a battery and a clock makes it a bit sub-optimal. But it's still a cool bit of tech. They don't help by having a terrible website. They need to split it into "info for developers", "why you want Yubikey" and "how to use Yubikey now you have one".
And it's kind of scary to see how many different password safes there are and how few of them have had any kind of auditing.
As for mobile, I have not tried the workflow on iOS but I hear you can use the USB camera connection kit to connect your Yubikey.
Lastpass has worked well, but going forward there are two major concerns. Lack of a mobile browser plugin makes it difficult to use on mobile (Android). Second, is that all major browsers appear to be dropping plugin support out of security and performance concerns.
What's best for password management without using browser plugins? Chrome clear text password storage is troublesome. Bitlocker and mobile encryption may help. Are more OS implementations one the way?
You also need to know your app store password. If your computer crashes, you will want to be able to reinstall 1password.
Additionally, you probably want to use dropbox to sync your passwords and act as a psuedo remote backup. If that is the case, then you also want to know your dropbox password.
All in all, I think you should have 3 passwords memorized: 1) 1password master password 2) app store 3) dropbox
If you have this knowledge, you can gain access to all your credentials from a freshly installed OS.
The trust lies with LastPass being able to uniquely identify my device as mine, and not someone spoofing me.
Yubikey is soley used from PC where I can plug in the yubikey. I could also have trusted computers, but I prefer to keep trusted devices to a minimum.
It has a large number of benefits over the traditional account/password paradigm.
If the password is for a realy dumb service that i dont care about i just write it in a text file located on my server /home/user/shitty_passwords.txt
Dashlane does encrypted cloud storage with local decryption - but I'm just wondering if there are good reasons to switch to 1Password or LastPass.
The rest of his argument is based on convenience alone and rather weak. A YubiKey, nice as it is, doesn't help with mobile devices, where transactions are increasingly taking place.
How do you account for this in your algorithm?
The only problem I still occasionally run in to is when a site requires a password change for whatever reason. I have a couple of minor permutations on the algorithm that I use in those cases, but sometimes that does trip me up.
http://blog.danielfischer.com/2011/05/12/its-time-to-start-u...
http://arstechnica.com/security/2013/10/how-the-bible-and-yo...