Password managers?

Discussion in 'Networking and Security' started by Scataphagos, Sep 30, 2016.

  1. I was thinking of using, 3rd grade girlfriend's name followed by "I bet she turned out to be one great piece of ass"... Too long?
     
    #11     Sep 30, 2016
    tango29 and FreakofNature like this.
  2. Something you should consider before using a password manager is using 2FA for your important logins.

    I've enabled 2FA on every important login to mitigate password loss. These include:
    • Google mail
    • Yahoo mail
    • Interactive Brokers
    • Oanda
    • Purse.io
    • Github
    • Cex.io
    • Coinbase
    I don't consider forums and message boards as important enough to worry about aside from having a reasonable password on them. Anything involving personal information and money are priority #1.
     
    #12     Sep 30, 2016
  3. Keep in mind many account hacks occur by hackers resetting your passwords and not by brute force attacks.
     
    #13     Sep 30, 2016
  4. Now that's worth a "like"!
     
    #14     Sep 30, 2016
  5. Geez, Louise. I was beginning to wonder if everybody lost their sense of humor..
     
    #15     Sep 30, 2016
  6. http://masterpasswordapp.com addresses these issues. I think there's a Wiki page on how it works. Just began using it. Some effort is needed, though, to get migrated.
     
    #16     Oct 1, 2016
  7. Overnight

    Overnight

    When it comes to brute forcing a password, wouldn't it be simpler and more secure to use very strong passwords 10 digits long?

    A strong password would apply to a system that allows upper and lower-case letters, 10 numbers, and special characters. Let's say there's 10 special characters.

    So that's 52 letters, plus 10 numbers + 10 special characters. Over the course of a 10-character password, it's

    72^10 = 3,743,906,242,624,487,424. That's ~3.8 quintillion combinations. Since most websites needing tight security with their password formats usually allow only 3-5 tries before a lockout and need to manually reset, doesn't it follow that the chances of being brute-forced are just about zero?

    As far as an account being hacked, well, just keep a post-it note in your room/office where you work with the passwords listed, and don't store them on your machine. And use a unique password for each website, so if one account is compromised, they can't get to the rest.
     
    Last edited: Oct 1, 2016
    #17     Oct 1, 2016
  8. Surgo

    Surgo

    That's what we like to call an analog password manager. It works just fine. The convenience of using Lastpass cannot be beat, however.
     
    #18     Oct 1, 2016
    Overnight likes this.
  9. userque

    userque

    Typically, the attack is on the database(s) storing all of the passwords, and not just on your login screen. :) So a lot depends upon how the passwords are being stored by the company (e.g. Yahoo, etc.), regardless of how long your password is.

    And, it may not take as long as you think. Research 'Rainbow Tables.'
     
    #19     Oct 1, 2016
  10. Overnight

    Overnight

    Indeed. Thus the admonition that you do not use the same password for each site. If one is hacked, at least that is the only password that is compromised.
     
    #20     Oct 1, 2016