Know the rules The Paceline Forum Builder's Spotlight


Go Back   The Paceline Forum > General Discussion

Reply
 
Thread Tools Display Modes
  #1  
Old 04-19-2024, 08:35 AM
Veloo's Avatar
Veloo Veloo is offline
Senior Member
 
Join Date: Sep 2013
Location: Toronto
Posts: 4,221
OT - How secure is your password

Since we talk about scams often enough here.

Think it was on the news that I saw this. Adding numbers and special characters does make a big difference. At least according to this site.

https://www.security.org/how-secure-is-my-password/
Reply With Quote
  #2  
Old 04-19-2024, 08:36 AM
benb benb is offline
Senior Member
 
Join Date: Apr 2007
Location: Eastern MA
Posts: 9,887
I long gave up on making them up myself. Use a program to generate a super secure one and then obviously you have to use a program to store them, it's impossible to remember them all when you have hundreds and they're totally random.
Reply With Quote
  #3  
Old 04-19-2024, 09:39 AM
Likes2ridefar Likes2ridefar is offline
Senior Member
 
Join Date: May 2009
Location: Arizona
Posts: 6,888
Hopefully pretty secure. I use Bitwarden with random 30 characters for all passwords unless other requirements.
Reply With Quote
  #4  
Old 04-19-2024, 09:55 AM
MikeD MikeD is offline
Senior Member
 
Join Date: Jan 2015
Posts: 2,933
Quote:
Originally Posted by benb View Post
I long gave up on making them up myself. Use a program to generate a super secure one and then obviously you have to use a program to store them, it's impossible to remember them all when you have hundreds and they're totally random.
Then what happens if that program fails or you don't have access to it? I've been unwilling thus far to put all my faith in a password manager.
Reply With Quote
  #5  
Old 04-19-2024, 10:05 AM
benb benb is offline
Senior Member
 
Join Date: Apr 2007
Location: Eastern MA
Posts: 9,887
There's generally a reset procedure on most things you would log into.

Let's put it this way, the chances of your self generated password that you probably share on multiple sites getting hacked is way higher than the frequency things like the Apple iCloud passwords or Google password manager have been hacked, those two have never failed IIRC.

I use both of those two, so they'd both have to fail. The weakness there is there are two password managers that could be hacked and expose your passwords. The other weakness is I have to keep the two managers synced.

But again, the frequency of "Site X" turning out to not encrypt your password properly in it's DB and then Site X gets hacked is WAY higher than the frequency of the password managers being hacked. Nobody hires a bunch of security neophytes to build security systems, but many "Site X" places have zero security experts on staff. "Site X got hacked and didn't secure their passwords properly" is almost a daily thing.

Also passwords are going extinct anyway. I work in computer security. All of our important stuff is triple factor security. You need your RSA key, a password, AND a time based code from a security system. Of those 3 the password is the least useful, there is a lot of work going towards getting rid of passwords.

The thing with using the encryption keys instead of passwords is the private parts of encryption keys are never transmitted over the network. The site you are logging into only gets the public part of the key. Someone stealing the public key does not gain the ability to impersonate you.

Last edited by benb; 04-19-2024 at 10:13 AM.
Reply With Quote
  #6  
Old 04-19-2024, 10:26 AM
gravelreformist gravelreformist is online now
Senior Member
 
Join Date: Aug 2023
Posts: 185
A password manager is a required part of a digital life as far as I'm concerned. If you're not using one, your chances of a serious compromise is orders of magnitude higher.

I've been using one for over a decade. Never any issues. It's backed up, so it's hard to see how it could fail in a way that was not recoverable.

And if it did, I would simply have to reset a lot of passwords. Irritating but not the end of the world.
Reply With Quote
  #7  
Old 04-19-2024, 10:29 AM
jkbrwn's Avatar
jkbrwn jkbrwn is offline
Senior Member
 
Join Date: May 2020
Location: Kernville, CA
Posts: 2,287
Quote:
Originally Posted by gravelreformist View Post
A password manager is a required part of a digital life as far as I'm concerned. If you're not using one, your chances of a serious compromise is orders of magnitude higher.

I've been using one for over a decade. Never any issues. It's backed up, so it's hard to see how it could fail in a way that was not recoverable.

And if it did, I would simply have to reset a lot of passwords. Irritating but not the end of the world.
If I could upvote a post, this would be it. A password manager is imperative to modern life involving computers. I have 500ish passwords in mine and they're all unique. How could one possibly manage 500 unique passwords without a password manager!?
Reply With Quote
  #8  
Old 04-19-2024, 10:43 AM
fmradio516 fmradio516 is offline
Senior Member
 
Join Date: May 2010
Location: Long Island, NY
Posts: 4,563
Quote:
Originally Posted by gravelreformist View Post
And if it did, I would simply have to reset a lot of passwords. Irritating but not the end of the world.
I think the other poster meant like, what if the password manager service is down.

One option is to keep a second app that isnt web-based, like KeePass, which stores all your passwords on an encrypted database on your device. So if your regular web-based service goes down, youre not without your passwords. Only pain would be having to manually sync passwords that you add or change to KeePass, but im sure theres a way to sync it automatically...
Reply With Quote
  #9  
Old 04-19-2024, 10:45 AM
bikinchris bikinchris is offline
Senior Member
 
Join Date: Mar 2004
Location: Little Rock, AR
Posts: 4,333
I use a spreadsheet to keep up with my passwords.
__________________
Forgive me for posting dumb stuff.
Chris
Little Rock, AR
Reply With Quote
  #10  
Old 04-19-2024, 10:46 AM
NYCfixie NYCfixie is offline
Senior Member
 
Join Date: Dec 2015
Location: 10065
Posts: 933
I work in Cybersecurity as well and what I tell friends/family/co-workers is:
- Use a password manager
- Have it create and store the passwords for you (15 characters minimum but the more the better)
- DO NOT use the same password for multiple accounts/services
- Make sure ALL accounts/services are setup for multi-factor authentication
- Your email password should be the STRONGEST password
(because if hackers can into your email they can often reset passwords for all other accounts/services since most people do not use multi-factor authentication)
- Your password manager should have your second strongest password
- Write your eMail and Password Manger passwords on an index card (yes, I mean paper) and store them safely some place in your home. DO NOT save them anywhere else.


Many commercial password managers can be (or have been) broken. Nothing is perfect. The safest method is to keep everything on paper, locked away at home, and never share with anyone.

Multi-factor authentication is not perfect. Hackers have found interesting ways to get around it (i.e. they can clone your mobile number to receive the multi-factor code you need to authorize yourself to a system after entering the password they have been able to figure out or steal from you).

The point is, most hackers are lazy so if you use a few different methods to protect yourself, hackers will move on and try to terrorize another person who may not have safeguards in place.

Be careful out there.
Reply With Quote
  #11  
Old 04-19-2024, 10:56 AM
C40_guy's Avatar
C40_guy C40_guy is offline
Senior Member
 
Join Date: Aug 2008
Location: New England
Posts: 5,970
Quote:
Originally Posted by jkbrwn View Post
If I could upvote a post, this would be it. A password manager is imperative to modern life involving computers. I have 500ish passwords in mine and they're all unique. How could one possibly manage 500 unique passwords without a password manager!?
Easy. Nine common letters plus four unique ones relevant to specific use...

i.e. Poopystuffebay# for ebay sign-on, Poopystuffamaz# for Amazon sign-on...

(examples only, although I actually like "Poopystuff" as a base..

...and of course you can mix in numbers in the base...as most sites want a mix of alphas, numbers and special chars...
__________________
Colnagi
Seven
Sampson
Hot Tubes
LiteSpeed
SpeshFatboy
Reply With Quote
  #12  
Old 04-19-2024, 11:09 AM
tellyho tellyho is online now
Senior Member
 
Join Date: Jul 2019
Location: Boston area
Posts: 1,551
+1 to password manager. Always amazed when people don't use one. Have it generate the passwords for you.

That said, I am totally fine to use a known-to-the-world throwaway password for services that I don't care about.
Reply With Quote
  #13  
Old 04-19-2024, 11:37 AM
jkbrwn's Avatar
jkbrwn jkbrwn is offline
Senior Member
 
Join Date: May 2020
Location: Kernville, CA
Posts: 2,287
Quote:
Originally Posted by C40_guy View Post
Easy. Nine common letters plus four unique ones relevant to specific use...

i.e. Poopystuffebay# for ebay sign-on, Poopystuffamaz# for Amazon sign-on...

(examples only, although I actually like "Poopystuff" as a base..

...and of course you can mix in numbers in the base...as most sites want a mix of alphas, numbers and special chars...
Insane when pw managers exist lol
Reply With Quote
  #14  
Old 04-19-2024, 11:50 AM
rkhatibi rkhatibi is offline
Senior Member
 
Join Date: Aug 2014
Location: SF, CA
Posts: 271
your data is cached locally in some (most?) password managers though you may need to configure that behavior.

https://support.1password.com/sync/
https://support.lastpass.com/s/docum...tml&_LANG=enus
Reply With Quote
  #15  
Old 04-19-2024, 11:52 AM
cgolvin's Avatar
cgolvin cgolvin is offline
#RYFB
 
Join Date: Nov 2016
Location: The Boss Basin
Posts: 5,103
Quote:
Originally Posted by benb View Post
The other weakness is I have to keep the two managers synced.
Would appreciate you sharing your approach to this. Are you able to automate this when you change or add a password, or do you have to do it manually? Thanks
__________________
Gios Peg
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 05:00 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.