User Tag List

Page 1 of 3 123 LastLast
Results 1 to 20 of 46

Thread: Password managers

  1. #1
    Join Date
    Dec 2011
    Location
    Tejas
    Posts
    1,369
    Post Thanks / Like
    Mentioned
    6 Post(s)
    Tagged
    0 Thread(s)

    Default Password managers

    I could have sworn there was a password manager thread on here somewhere. I searched and could not find it.

    Would someone please link me over to that thread (mods, please delete this one) or would someone give me some recommendations for a smart way to manage passwords?

    Thanks

  2. #2
    Join Date
    May 2010
    Location
    Chicago
    Posts
    3,008
    Post Thanks / Like
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    If you searched and couldn't find it I'm sure I won't do better.

    I use LastPass. It seems like they do it right. I figure when super-nerd Steve Gibson switches to something else I will too.

    https://twit.tv/shows/security-now

  3. #3
    Join Date
    Jul 2011
    Location
    Middle America
    Posts
    1,092
    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Another vote for LastPass. Solid on all platforms. It has continued to improve.

    Nick

    “If today is not your day,
    then be happy
    for this day shall never return.
    And if today is your day,
    then be happy now
    for this day shall never return.”
    ― Kamand Kojouri

  4. #4
    Join Date
    Sep 2012
    Location
    Oakland CA
    Posts
    342
    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Oh yeah, been meaning to set that up...
    Nash Taylor - Oakland CA

  5. #5
    Join Date
    Mar 2009
    Location
    Colorado
    Posts
    4,684
    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    I use KeePass on my iOS/OSX and Linux boxes. It stores an encrypted file on your box and not in the cloud which is what I prefer for a password stash. As an example LastPass was hacked in 2015 and a huge vulnerability was found in 2016.

    Hack Brief: Password Manager LastPass Got Breached Hard | WIRED

    LastPass Bug Lets Hackers Steal All Your Passwords

    Cheers,
    -Joe

  6. #6
    Join Date
    Dec 2014
    Location
    Centennial state, USA
    Posts
    164
    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Msecure on Apple platforms



    Ken

  7. #7
    Join Date
    Oct 2009
    Location
    Portland OR
    Posts
    815
    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Strange, I definitely remember that thread too. It's what prompted me to finally start using a password manager, so I remember it well. But I can't find it either.

    At any rate, I also use LastPass, have been happy with it. The integration across platforms has been nice. I've got it added as an extension on multiple browsers across both Mac and Windows machines and use it on iOS. I recall xjoex mentioning KeePass in that original thread but feeling like the degree of difficulty was somewhat beyond what I was looking for. Now, especially after seeing the articles that Joe linked above, I will probably revisit the option to see if I still feel the same.

    I know people also like 1Pass. It's got a bigger upfront cost but is just a one time purchase. LastPass is a yearly renewal. I'm probably coming up on the time where I'll have spent more on LastPass than I would have on 1Pass, but that's okay. It's not a large expense. $12 per year or thereabouts.

  8. #8
    Join Date
    Oct 2009
    Location
    Portland OR
    Posts
    815
    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Joe, I'd love to hear your thoughts also on Apple Keychain, if you have any. Hell, ApplePay or Google Wallet too if you don't mind.

    Thanks!

  9. #9
    Join Date
    Oct 2012
    Posts
    11,084
    Post Thanks / Like
    Mentioned
    12 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    No reliance on cloud/third party services here.

    I use keepass (keeweb app on desktop, keepassdroid on the phone) with my kdbx files being automatically synced by syncthing when I connect them to the household wifi network.
    --
    T h o m a s

  10. #10
    Join Date
    May 2008
    Location
    DC
    Posts
    29,892
    Post Thanks / Like
    Mentioned
    58 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    I used to be in the game. Lastpass. Pay for premium.

  11. #11
    Join Date
    Jun 2008
    Location
    USA
    Posts
    3,644
    Post Thanks / Like
    Mentioned
    5 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    I started to use Keepass a while back, chose a super-strong password for Keepass itself, and started to save my various passwords in it, then a few weeks later promptly forgot the Keepass password.

    Anyone have a password manager for password managers? ;)

  12. #12
    Join Date
    Jan 2016
    Posts
    30
    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Lastpass has been treating me right since about 2010. Shelled out for Premium a couple of years ago essentially as a thank you for the great software.

  13. #13
    Join Date
    May 2008
    Location
    DC
    Posts
    29,892
    Post Thanks / Like
    Mentioned
    58 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Quote Originally Posted by Mabouya View Post
    I started to use Keepass a while back, chose a super-strong password for Keepass itself, and started to save my various passwords in it, then a few weeks later promptly forgot the Keepass password.

    Anyone have a password manager for password managers? ;)
    PM me an I'll teach you a strong password creation method you won't forget...probably.

  14. #14
    Join Date
    May 2013
    Location
    NYC
    Posts
    3,101
    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Lastpass at home.
    Lastpass Enterprise at work with my IT/Tech team.

  15. #15
    Join Date
    Apr 2011
    Location
    Hillsdale NY
    Posts
    25,679
    Post Thanks / Like
    Mentioned
    74 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Based on the advice of an old friend who grew up to be one of those people, I keep all my passwords in an encrypted file that I back up regularly to a flash drive that I keep in a safe.
    Jorn Ake
    poet

    Flickr
    Books

  16. #16
    Join Date
    Jan 2009
    Location
    Wellington, New Zealand
    Posts
    2,589
    Post Thanks / Like
    Mentioned
    4 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    This sort of stuff isn't for geeks and hackers any more: infosec is a serious societal problem.

    Chrome's in-built password manager is really good and syncs across multiple browsers however won't work for apps.

    I use Strong Random Password Generator to generate passwords. 16 characters is enough to stop most brute-force attacks and if it's a password I'll also need for an app I don't include any symbols which makes it way easier to type.

    If you're going to go down the password manager route you NEED to have a very secure master password / passphrase. No point in going to all this effort if your master is the same one you've used for 10 years or which was part of Yahoo's 500 million leaked passwords.

  17. #17
    Join Date
    Jun 2014
    Location
    Boston
    Posts
    263
    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    I tried Dashlane for a while, but it was too buggy to be reliable.

    I currently use 1password which is great on Mac and iOS and serviceable on windows. I'm mostly on the former 2 platforms so it's fine.

    I recently discovered that I can get Lastpass free through work, but inertia is keeping me from switching.

  18. #18
    Join Date
    Oct 2012
    Posts
    11,084
    Post Thanks / Like
    Mentioned
    12 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Quote Originally Posted by Mabouya View Post
    Anyone have a password manager for password managers? ;)
    Quote Originally Posted by Tristan View Post
    16 characters is enough to stop most brute-force attacks and if it's a password I'll also need for an app I don't include any symbols which makes it way easier to type.
    A moderately long passphrase is better remembered than 16 randoms characters, is easier to type than a non spellable thing with symbols and is even stronger against bruteforce attempts. Bonus point if that sentence is not in english.
    --
    T h o m a s

  19. #19
    Join Date
    Mar 2009
    Location
    Colorado
    Posts
    4,684
    Post Thanks / Like
    Mentioned
    1 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Quote Originally Posted by C.Dyer View Post
    Joe, I'd love to hear your thoughts also on Apple Keychain, if you have any. Hell, ApplePay or Google Wallet too if you don't mind.

    Thanks!
    The Apple keychain is neat, its a built in password stash. But then they made available across all iPod, iPhone, etc by syncing to the cloud if you chose to use iCloud Keychain. So once again you have the cloud problem, but at least the app is more secure as Apple does not allow un-vetted apps to be installed like Android devices. The walled garden of Apple iOS is a bit more secure (I used to run the mobile malware research division at an AV company). Although interestingly we saw most malware came in two flavors: Stream FIFA online for free or Naked pics of asian celebrities.

    Regardless the best thing you can do for security is use some type of password stash. Have a different password on each site.

    As for Apple Pay and Google Wallet, I view it as just an alternative to a credit card. At least it is more complicated than just writing down a 16 digit number to steal it!

    I love to talk about this stuff, so ask away!

    -Joe

  20. #20
    Join Date
    May 2013
    Location
    NYC
    Posts
    3,101
    Post Thanks / Like
    Mentioned
    7 Post(s)
    Tagged
    0 Thread(s)

    Default Re: Password managers

    Since nobody else has said I will:

    If you talk to any serious industry information security expert they will tell you that the most secure password storage is pen and paper and then keep that list in your wallet because these days you are more likely to have your electronic password storage system compromised than be mugged and your physical wallet stolen.


    This system assumes that you are already using strong passwords and/or passphrases.

Page 1 of 3 123 LastLast

Similar Threads

  1. Replies: 3
    Last Post: 10-15-2016, 02:28 PM
  2. Replies: 12
    Last Post: 07-18-2016, 11:45 AM

Tags for this Thread

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •