Please use a randomly generated password that is as long and complex as the site you're using will allow, stored in a password safe.
Please use a randomly generated password that is as long and complex as the site you're using will allow, stored in a password safe.
I recently created a website that generates a random 'password square'. It should display nicely on latest browsers (which support flexbox). You can optionally supply a seed if you want to reuse the same path but have it yield a different password.
https://caurea.org/passwd/ https://caurea.org/passwd/#seed
The website is intentially barebones, to allow you to print it out and store offline.
So after years of telling people "Don't use table tags for layout", web devs have finally got that message... and they've started using layout tags for tables instead :(
FWIW, I use "pass", which is a short bash script that's a thin wrapper around gpg. If you can't trust that, I'm not sure how you can use a computer.
http://zx2c4.com/projects/password-store/
Btw, your password square generator isn't using a secure source of random numbers, which makes me highly doubtful.
Unless you are verifying the source and compiling yourself, your password manager IS a third party.
> FWIW, I use "pass", which is a short bash script that's a thin wrapper around gpg. If you can't trust that, I'm not sure how you can use a computer.
Sure, I probably trust GPG and the devs behind it. But unless you are downloading from them directly and verifying binaries, or building yourself from their source (and comparing source), you aren't really just trusting them, you're trusting the people that are distributing GPG to you. If the provider is a well respected linux distro, I probably trust it, but it's quite a bit less trust than the GPG devs themselves get. There's a lot more hands involved there and many more places for someone to inject some nefarious code, or just plain screw up[1].
I guess the real point is that "decent" in "decent password manager", or any security product for that matter, has higher bar than in many other industries, but this many not be common knowledge.
Edit: For that matter, I guess the only reason I trust GPG at all is that enough decentralized volunteers will look at it that coercing them all into keeping silent (or silencing them in another manner) about any backdoor they find is probably impossible (or at least requires enough effort as to make it unfeasible).
[1]: https://www.schneier.com/blog/archives/2008/05/random_number...
Looking at the whole picture, using something like LastPass or 1Password in place of bash+gpg is only marginally less secure, and since non-techies are more likely to actually use them than some console-based thing, encouraging their use is a net win for security. Saying "you shouldn't trust a password manager that you haven't inspected line-by-line" is ultimately counter-productive. The people that have the most to gain from password managers can't even read code, and certainly couldn't spot a hidden side-channel.
Manage your passwords like this: change them frequently. Remember them. Never write them anywhere you don't intend to use them.
I have a KeePass which can generate random passwords. I trust that because it's open source, so I could look at what they're doing--and build it myself--if I wanted.
I store the db file in Dropbox, but I don't trust them either: my file is encrypted with both a unique password and a second key file which I've taken pains to only ever transmit by copying on removable media.
Reuse is the main reason why theft of password dbs (as distinct from just compromise of the site) is a problem for the user.