Storing Passwords S...
 

MegaSack DRAW - This year's winner is user - rgwb
We will be in touch

[Closed] Storing Passwords Safely

37 Posts
33 Users
0 Reactions
195 Views
Posts: 0
Free Member
Topic starter
 

Can anyone recommend a method of storing passwords securily in a way that I can access them easily but with minimal risk of someone hacking in to my laptop and finding them all in one place. It doesn't have to be an electronic method, on paper would be fine too.

I cannot remember most of my passwords. I have previously tried setting them all the same (bad I know) but different sites have different requirements. I'm tired at having to spend two days and a phone call logging into my ISAs!

Many thanks,


 
Posted : 21/10/2013 8:07 pm
Posts: 460
Free Member
 

http://passwordsafe.sourceforge.net/


 
Posted : 21/10/2013 8:08 pm
Posts: 30656
Free Member
 

Something like [url= https://agilebits.com/onepassword ]1password[/url]?


 
Posted : 21/10/2013 8:08 pm
Posts: 0
Free Member
 

Yes - something like 1password. Basically, if you have a Mac, you get equivalent functionality built right into the Operating System in the next version - OSX 10.9 (and it syncs your passwords with ios7)

Rachel


 
Posted : 21/10/2013 8:11 pm
 br
Posts: 18125
Free Member
 

[i] It doesn't have to be an electronic method, on paper would be fine too.
[/i]

🙂

Write 'em down, keep them somewhere none-obvious.


 
Posted : 21/10/2013 8:11 pm
Posts: 0
Free Member
 

I use LastPass and it works a treat


 
Posted : 21/10/2013 8:11 pm
Posts: 23104
Full Member
 

On a piece of paper is perfectly acceptable. Hackers aren't so advanced yet that they can access your desk drawers via the internet. I've generally switched from jumbles of upper and lower case mishmash such as gHz3bx0O2 to [url= http://lifehacker.com/5796816/why-multiword-phrases-make-more-secure-passwords-than-incomprehensible-gibberish ]longer phrases[/url] of three or four words. Easier to type a sentence than to try and make sure you get all the upper and lower case right. I don't generally need to write them down as I've usually taken them by looking across the spines of books on the shelf next to where I sit


 
Posted : 21/10/2013 8:12 pm
Posts: 20649
Free Member
 

A common practice is to have your own unique password suffixed with the name of the service - so no two are the same and easy to remember.

For example
gfd34fg_facebook
gfd34fg_twitter


 
Posted : 21/10/2013 8:12 pm
Posts: 0
Free Member
Topic starter
 

Wow! That was quick!

I've tried adding the name of the service on the end, but lots of sites seem to blocking these types of passwords.

For 1Password. Surely this is all my passwords and accounts in one place. One online place. How long before that gets hacked?

Paper seems to be the best suggestion so far. Anything else?


 
Posted : 21/10/2013 8:22 pm
Posts: 23104
Full Member
 

Anything else?

Vellum 🙂


 
Posted : 21/10/2013 8:24 pm
Posts: 0
Free Member
 

Written in my diary - if I lose my diary I change my passwords not unlike if I was to lose my bank card, I would cancel the card.


 
Posted : 21/10/2013 8:24 pm
Posts: 30656
Free Member
 

Yes - something like 1password. Basically, if you have a Mac, you get equivalent functionality built right into the Operating System in the next version - OSX 10.9 (and it syncs your passwords with ios7)

Rachel

If it works as well as keychain, then I'm ooot.

*shakes fist at forgetful keychain*

For 1Password. Surely this is all my passwords and accounts in one place. One online place. How long before that gets hacked?

Good to see you actually read the info linked.

...from 1password.com:

All of your confidential information is encrypted using AES, the same state-of-the-art encryption algorithm used as the national standard in the United States. (Fun fact: AES stands for Advanced Encryption Standard.) 1Password uses 128-bit keys for encryption, which means it would take millions of years for a criminal to decrypt your data using a “brute force” attack.

[b]Of equal importance is where 1Password stores your data: neither an Internet connection nor an online storage is required. All your data is stored locally, on your computer. Even if you choose to sync your 1Password data with other devices using an online service like Dropbox, though, your master password keeps you in complete control of your data.[/b]

-[url= http://help.agilebits.com/1Password_Windows/index.html ]Sauce[/url]


 
Posted : 21/10/2013 8:25 pm
Posts: 30656
Free Member
 

Double Bubble 😡


 
Posted : 21/10/2013 8:26 pm
Posts: 0
Free Member
 

Papyrus is known to last a lot longer than paper.


 
Posted : 21/10/2013 8:30 pm
Posts: 0
Free Member
 

KeePass is good and free.

It is available for lots of different platforms. I run it on my Win7 PC and Android phone. I use Dropbox to keep the files synchronised.


 
Posted : 21/10/2013 8:35 pm
Posts: 77692
Free Member
 

I've tried adding the name of the service on the end,

Throw in a couple of letters.

So you have your master password, "norbertcolon," interspersed with say the first two characters of the domain at points you recognise. Eg, [b]fa[/b]cebook, "nor[b]f[/b]bertco[b]a[/b]lon."

Then, lettershift to stop reverse engineering. "norgbertcoblon" is your new facebook password, "norfbertcoclon" is eBay; long enough to prevent brute forcing, memorable, and won't grant access to all your other sites if it gets compromised.


 
Posted : 21/10/2013 8:37 pm
Posts: 4954
Free Member
 

maccruiskeen - Member
I've generally switched from jumbles of upper and lower case mishmash such as gHz3bx0O2 to longer phrases of three or four words.

http://xkcd.com/936/


 
Posted : 21/10/2013 8:38 pm
Posts: 8328
Full Member
 

I've whispered them in my elephants ear.*

*getting him to type them in for me is proving problematic.


 
Posted : 21/10/2013 8:43 pm
Posts: 621
Free Member
 

keepass does this. Encrypted and stored in a single file with a master password.


 
Posted : 21/10/2013 8:46 pm
Posts: 13594
Free Member
 

All mine are written on paper and kept in a safe in the house....


 
Posted : 21/10/2013 8:52 pm
Posts: 101
Free Member
 

[url=www.safe-in-cloud.com/]www.safe-in-cloud.com/[/url]

I sync the secure file across all my devices using SkyDrive... but you can use other cloud-based services.


 
Posted : 21/10/2013 8:57 pm
Posts: 110
Free Member
 

+1 for Keepass: *cough* 256 bits encryption too. More bits innit, gotta be better.


 
Posted : 21/10/2013 9:02 pm
Posts: 2
Free Member
 

I use a system very similar to the one Cougar describes. It's actually very effective once you get into it.

I also use simple passwords for sites that I don't really care if they get hacked. Like this one.

Always use phrases or abbreviations to help your remember too. Random characters is crazy and counter productive. Use song titles, advert phrases or sayings.

This site is called Singletrack and this is my password for it.

Ts1cSat1mpf1

Absolutely impossible to guess but easy to remember and repeatable for many sites.


 
Posted : 21/10/2013 9:08 pm
Posts: 13594
Free Member
 

+1 for Keepass: *cough* 256 bits encryption too. More bits innit, gotta be better.

The encryption algorithm is very rarely the weakest bit, it's normally the implementation which lets encryption down, eg not scrambling data, known key words such as always starting the payload with "Password 1=" etc, which makes breaking the encryption orders of magnitude easier. Also storing passwords in the clear in memory / on the stack during encryption which means they are accessible to nasty apps looking for them. Hackers always look for the weakest link and that's never the encryption algorithm (unless the NSA recommend it, in which case they've nobbled it).


 
Posted : 21/10/2013 9:09 pm
 dh
Posts: 0
Free Member
 

+1 lastpass.

nice iOS integration too.


 
Posted : 21/10/2013 9:19 pm
Posts: 3294
Full Member
 

Password protected Excel not very clever then?

I'm not really sure my life needs to be any more secure than that if I'm honest.


 
Posted : 21/10/2013 9:51 pm
Posts: 0
 

https://www.schneier.com/passsafe.html

... ought to be worth a look


 
Posted : 21/10/2013 10:03 pm
Posts: 0
Free Member
 

So, is my spreadsheet that is password protected with a really (what i think) quite difficult password no good?


 
Posted : 21/10/2013 11:09 pm
Posts: 0
Free Member
 

So, is my spreadsheet that is password protected with a really (what i think) quite difficult password no good?

Crackable in minutes unfortunately.


 
Posted : 21/10/2013 11:21 pm
Posts: 7995
Free Member
 

http://arstechnica.com/security/2013/05/how-crackers-make-minced-meat-out-of-your-passwords/

http://arstechnica.com/security/2013/10/how-the-bible-and-youtube-are-fueling-the-next-frontier-of-password-cracking/

Dustin's computer can perform 30 billion guesses per second against standard Windows hashes. The $800 system uses four AMD Sapphire Radeon 7950 cards.

Be afraid.

Also
[img] [/img]

KeyPass for me, BTW.


 
Posted : 21/10/2013 11:27 pm
Posts: 10980
Free Member
 

Most of mine are written cryptically on a scruffy old piece of a tear-off pad that is usually buried under a pile of others on my desk. So for example instead of "Specialized15" I've written "bike/street number", which seems to work.


 
Posted : 22/10/2013 5:30 am
Posts: 39501
Free Member
 

In my mind. I hope the hackers dont get in there .


 
Posted : 22/10/2013 5:48 am
Posts: 578
Free Member
 

I put them in a .txt file and store it in a hidden, locked folder. I have a mixed character/case password to unlock the folder. I only have to remember one password.
[url= http://www.tweakandtrick.com/2012/12/lock-folder-password.html#Folder ]This is the software I use[/url]


 
Posted : 22/10/2013 6:04 am
Posts: 6621
Free Member
 

Notebook in drawer.

If the house is broken into they will probably nick my phone, tablet, jewellery, cash, car keys,bikes but I doubt they'd go looking for passwords on the off chance I'd written them down.


 
Posted : 22/10/2013 6:18 am
Posts: 0
Full Member
 

Interestingly a number of security experts agree that very strong passwords written down and hidden offer much better protection than weak passwords and repeatedly used passwords.

Its also amazing how quickly you can learn to remember complex passwords for commonly used sites.

I use Oplop (appspot.oplop.com) to generate the random password as I can recreate that password using Oplop if I am not at one of my own computers.

On my own computers I use Keepass to store them.

Cheers

Danny B


 
Posted : 22/10/2013 6:30 am
Posts: 92
Full Member
 

+1 for LastPass, used mainly because work requires me to manage lots of online credentials on multiple computers. I do a lot of work around software security and in my view there's no perfect solution - many of the suggestions above are as good as anytying. GoFaster's cartoon hits one nail on the head!

If you're interested, here's some thoughts on password managers
[url= http://ask-leo.com/are_password_managers_like_roboform_and_lastpass_safe.html ]http://ask-leo.com/are_password_managers_like_roboform_and_lastpass_safe.html[/url]


 
Posted : 22/10/2013 7:41 am
Posts: 1254
Free Member
 

+1 for this, works a treat, no need to reply on third partie software or websites.

A common practice is to have your own unique password suffixed with the name of the service - so no two are the same and easy to remember.

For example
gfd34fg_facebook
gfd34fg_twitter


 
Posted : 22/10/2013 7:54 am
Posts: 6330
Free Member
 

How many do you need. I have ebay, Pp and all these stupid forums plus email. Only the first two have any importance.


 
Posted : 22/10/2013 8:47 pm