[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y ] [Search | Free Show | Home]

Are password managers worth using?

This is a blue board which means that it's for everybody (Safe For Work content only). If you see any adult content, please report it.

Thread replies: 73
Thread images: 5

File: LastPass.jpg (59KB, 600x257px) Image search: [Google]
LastPass.jpg
59KB, 600x257px
Are password managers worth using?
>>
>>56189597
They're pretty comfy.

All my 300 different passwords under one roof available on desktop and phone.
>>
File: 1467314511455.jpg (128KB, 1500x1500px)
1467314511455.jpg
128KB, 1500x1500px
ehh
>>
Only Keepass because of the local database.

Cloudshit is a meme.
>>
>>56189662
This so much.
>>
File: 12228.jpg (55KB, 640x480px)
12228.jpg
55KB, 640x480px
>>56189649
Why would anyone own that and where can I get one?
>>
>>56189597
yes. I got several of my passwords cracked when some shitty websites got hacked over the years. It's funny to see the many "someone tried to login to your account from Nigeria" and stuff.
Each website a different pass = failproof.

Unless you used your lastpass acc on other websites, then you deserve anything that happens to you.
>>
>>56189597
Storing your account info in the cloud is like putting your life savings in the school locker.
>>
>>56190308
How so? If you store it in secure cloud services like Google Drive (Google doesn't fuck around about security) and secure your google account with 2 step verification and a strong pass you don't have to worry about it getting hacked.
>>
>>56189597
>Relying on software to remember all your passwords
>Not using your brain

The world is getting stupider every day. How the fuck can you not remember basic information?
>>
>>56190336
Not him, but trusting third parties is a risk.
>>
>>56190357
How do you remember dozens of randomly generated 20 character long passwords? Are you a robot?
>>
>>56190364
I'm not stupid.
>>
>>56189597
Yes, they're the best way by far to have secure passwords on every website

Just stay away from LastPass. KeePassX is fine if you're a shitty winbabby, otherwise use passwordstore.org
>>
>>56190368
so basically yeah, you are stupid.
>>
>>56190360
To add.

http://thehackernews.com/2016/07/lastpass-password-manager.html?m=1
>>
Keepassdroid

Local storage mobile password book convenient and secure as long as it's on you, and you can pair it with remote deletion software if you don't trust yourself to protect the phone
>>
>>56190414
OK dude, Mr "I cant remember basic information".

Have fun being stupid and poor.

You might as well write your passwords and bank details on a stickynote and leave it in public.
>>
>>56190416
Good thing I'm not using LasPass server :)
>>
>>56190427
butthurtus maximus

wow, you sure showed me! that big company full of security experts is no match to your intellect!

here, this is my main password with a single key missing. have fun with it!

spWC$pREMm%rx3S9uOvC8mk3Ypx^T7c%Q3whfG8G1TzIrzolp9j%y&6V*b3*Iw2NbVp*edFreg1WHoghGGn&hMQx%5HxtSV^oJyl
>>
File: laughingsluts.png (1MB, 960x792px) Image search: [Google]
laughingsluts.png
1MB, 960x792px
> he sends his passwords to the cloud
>>
>>56190449
>Having a password with that much autism
>>
>>56190451
Yeah and?
>>
>>56189597
No. Pen and paper > everything else
>>
>>56190449
So how do you remember you main password?
>>
>>56190461
Why should I care? I never have to type it or remember it.

my email account is [email protected]

surely you will be able to >l3 h4XX0r me now, right? with email and password just 1 char off?
>>
>>56190488
I don't need to. That is my google password, not my lastpass password
>>
>>56190357
>he doesn't use a randomly generated string of shit
>>
>>56190500
And how do you remember that password?
>>
>>56190500
Then what's your lastpass password?
>>
>>56190461
>having a generated 100 char password is autistic
>considering top-notch security software not safe enough for storing your sardinian pearl-diving fora passwords, thus having to memorize over 10 different 10 character passwords somehow is not

you insufferable cunt
>>
>>56190515
my password is H#j- waaait a minute, are you trying to trick me?
>>
>>56190416
reading the article:

>"look at all these bugs I found and that LastPass has immediatly fixed the same day!"

oh cool, a list of things LastPass is protected against, thanks for confirming how secure LastPass is!
>>
>>56190586
No, anon, I would never do that.

I just want to know what it is and how do you go about remembering it. So spit it out.
>>
>>56190344
Why not ask the NSA to store your data directly?
>>
>>56190357
>>56189597
I find it for some use cases to be extremely useful.
- Since I have brain, then I can memeorize good password for KeePass kdbx file.
- For any garbagesite which requires account for mega.nz links I can just create RANDOM account with RANDOM password.
>>
>>56190660
NSA won't empty out my bank account. A russian scriptkiddy might though.
>>
>>56189662
Doesn't LastPass also have a local database function?
>>
keepass lost my username and random password for a money account, so....fuck keepass? (or fuck me cause I never told it to save for some stupid reason)
>>
>not just keeping a book of your passwords
its 10x more convienient and 10x as safe. As long as you're not retarded and don't put
THIS IS MY EMAIL PASSWORD
THIS IS MY ONLINE BANKING PASSWORD
then you're also literally never going to have an account stolen
>>
File: 2016-08-14-00-51-05-1396721781.jpg (7KB, 231x218px) Image search: [Google]
2016-08-14-00-51-05-1396721781.jpg
7KB, 231x218px
>>56189597
Is this a meme?

I thought you were against the botnet?

Why do you want all your account info in one place? With all your passwords none the less.


What happens when they get hacked?
>>
>>56190364
>20 characters
you mean 40 (a lot of sites limit it to 40) and 100 characters.
>>
>>56190388
>just stay away from lastpass

Yeah, stay away from the most popular thus the most tested choice with computer security experts constantly looking around the code for bugs, but instead use a less popular one with less attention and people looking around trying to find bugs/hazards. Smart.
>>
>>56190774
It makes no difference unless there are blacks in your area breaking into homes and stealing notebooks. But it's also good storing it on an old phone, just disable/delete everything except a txt storing app, put it in airplane mode and back up your passwords on a memory card just in case the phone dies for some reason. It's much better to store passwords on devices with no Internet access than using meme programs and cloud services.
>>
>>56189597
It s a great tool, give it a try you d enjoy it.
>>
>>56190866
>manually typing 40 randomly generated passwords everytime he logs into a website

I prefer to just click "copy".
>>
>>56190836
I bet you also fully trust Windows and iOS because you think it's popular therefore it must be secure
>>
>not using 123456 as your password everywhere
>>
>>56190899
No, but it's surely more secure than something like "Obongo OS".
>>
>>56190898
>implying people use anything more than 16 characters
>implying anyone cares about the 5 seconds lost for typing the password
>>
Having a unique strong password for every service is a good idea.
A password manager is a way to do that while keeping the convenience that it is to not remember a lot of passwords.

But if you use an online service, you just have one new point of attack, should your account be breached, every account is breached.

A better solution would be to use fewer accounts.
combined with fewer computers where you access these accounts, you don't have to keep track of a lot of passwords.
>>
>>56190974
I think if someone is dumb enough to use lastpass, then he should only use it for throw away accounts and not for things like email.
>>
I have everything on a keypass database. I have several backups of the database on different computers and a copy on my USB on my keychain, pw is 9 random characters and symbols which I hope secure enough, I've memorised it off by heart

Works pretty good for me
>>
>>56190695
This. While I don't exactly trust the NSA, they are after all a government agency. Storing my passwords (for normie sites) directly with the NSA doesn't seem like a bad idea, they probably have good security.
>>56190308
No, it's client side encrypted. Beware of LastPass however, logmein aren't trustworthy (they still have metadata)
>>
I'm gonna propose an idea, someone tell me why it is bad.

We all know we should have a different password for each service or website, so why not make a system where the password you use is based upon the name of the service it is for.

This way, you can log into any website or service anywhere in the world, and you don't have to store the passwords anywhere. In fact, you should be able to derive the password from the name of the service. This way, you remember the process, rather than a thousand different passwords.

This way, for someone to have to figure it out, they would have to get a hold of 2 different passwords for 2 different services, and even then they would have to notice the system, which can be very hard if you're smart.

This kind of system along with 2 factor authentication means you're basically good, you don't have to store your password anywhere, you don't have to remember 100 passwords, you're pretty much as secure as anyone else as long as you never tell anyone how to derive the password.

Here's an example system off the top of my head:

1) Constant word is 'purple'
2) Intersperse this with the reverse of the name of the service.
3) At the end add the number of letters in the service, first letter the number, the last letter is capital.

You just have to remember these three steps.

Say you want to make a password for gmail

lpiuarmpgle5ivE

You need to know your password for youtube?

epbuurtpuloey7eveN


Even if somehow, an attacker got a hold of two of your passwords, they'd have to manually inspect it and make the connection and then figure out the process. In that case you have two factor authentication enabled because you're not an idiot and you just come up with a new process.

With this, you can go anywhere in the world, don't have to store your passwords in the cloud, etc.
>>
>>56192051
>I'm gonna propose an idea, someone tell me why it is bad.
First question you need to answer: You should assume that of your 100 accounts, an attacker can look at 10 of their passwords. Is your scheme secure under that circumstance?

Second question you need to answer: Is this scheme practical? Can you readily and quickly type your password without needing to basically remember it either way?
>>
>>56192143
What is the real life probability that an attacker is going to get even 2 or 3 of these passwords though? Surely it can't be very high if you're not being an idiot. Even when passwords do get leaked, they're usually dumps of hundreds of thousands of passwords. People rarely look at them manually and hard enough to see that there is a possibility they are linked in some way. I know security through obscurity isn't good, but practically, it doesn't seem like a huge risk.

Generally, you would stay logged in with sessions/store your password locally in the browser. The method would mainly only have to be used when you're away from your own computer, etc.
>>
>>56190695
>everyone here is American
Even I wouldn't trust NSA that much. They're a totalitarian agency.
>>
>>56190974
>should your account be breached, every account is breached.

It's important to do risk assessment here.

There are good ways to securely store information. The problem is that institutions that ought to know how (i.e. major banks) have shown us they don't. A good password manager has every generated password encrypted w/ your root password as a key. The root password is salted and encrypted. A brute-force attack against your account won't work because we're smart and we've setup two-factor authentication. If attackers compromised the password manager's infrastructure, we're still pretty OK since all the passwords are encrypted and we have a securely stored root password. Computational complexity buys us enough time to change these passwords without any problem.

I'd say it's riskier not to use a password manager than to use one.
>>
>>56190695
>>56191872
You honestly believe the government would tell people that their information was compromised by the Chinese or some Nigerians?

Unless your government gets caught with their pants down then they're going to just sweep it under the rug and hope for the best. The government isn't about to tell people they made a mistake no matter how inept or competent they are. There are people from all over the world attacking government databases so it's safe to assume some amount of data has been compromised.

You should just use something that has a local database and make regular backups. Do as much as you can to keep all essential information offline and anything like facebook or youtube information separate from important information like your money/purchase/bank history.
>>
>>56192233
The whole point of using different passwords for different services is to keep your other accounts secured if one is compromised.

If your password is essentially "MyPassword@[service]", it's just as secure as using the same password for everything.
>>
>>56192397
I use pass, gpg encrypts passwords. Also use it to generate and store usernames
pass -c <name> — copy password
pass generate -c <name> <characters> — generate n char password
>>
>>56190907
>tfw i actually use this for accounts i dont care about
>>
>>56190451
Your passwords are protecting something that is in the cloud, lol
>>
>>56190788
Read about how it works. They can't decrypt anything
>>
>>56189597

I'm surprised that no one here mentioned about enpass. I use enpass and it has pretty much every functionality that your favorite pass manager has got except that it is not as botnet as them.

Does everything locally and still supports the cloudsync meme.
>>
All of you need to learn how these password managers do security

Bunch of ignorance ITT
>>
>>56189597
>not using Excel
>>
>>56189662
You're a meme

Apple uses nCipher HSMs to store keys, this is better and more secure than any anon's home server setup.

Let me know when Linux or Microsoft start saving passwords using independently verified tamper proof crypto-processors.

Oh wait I forgot, this is the board where only fags buy apple. I guess only fags like the highest level of security too, must be a fag thing.
>>
>>56193415
http://blog.cryptographyengineering.com/2016/08/is-apples-cloud-key-vault-crypto.html

yup
>>
>>56193415
fucking lol, Apple basically has a private key Fort Knox setup here but the keepass local database is keeping him safe, for sure man.
>>
>>56193384
>not using excel with temps and autosave
>>
>>56193415
>not storing your shit offline
You're a meme
Thread posts: 73
Thread images: 5


[Boards: 3 / a / aco / adv / an / asp / b / bant / biz / c / can / cgl / ck / cm / co / cock / d / diy / e / fa / fap / fit / fitlit / g / gd / gif / h / hc / his / hm / hr / i / ic / int / jp / k / lgbt / lit / m / mlp / mlpol / mo / mtv / mu / n / news / o / out / outsoc / p / po / pol / qa / qst / r / r9k / s / s4s / sci / soc / sp / spa / t / tg / toy / trash / trv / tv / u / v / vg / vint / vip / vp / vr / w / wg / wsg / wsr / x / y] [Search | Top | Home]

I'm aware that Imgur.com will stop allowing adult images since 15th of May. I'm taking actions to backup as much data as possible.
Read more on this topic here - https://archived.moe/talk/thread/1694/


If you need a post removed click on it's [Report] button and follow the instruction.
DMCA Content Takedown via dmca.com
All images are hosted on imgur.com.
If you like this website please support us by donating with Bitcoins at 16mKtbZiwW52BLkibtCr8jUg2KVUMTxVQ5
All trademarks and copyrights on this page are owned by their respective parties.
Images uploaded are the responsibility of the Poster. Comments are owned by the Poster.
This is a 4chan archive - all of the content originated from that site.
This means that RandomArchive shows their content, archived.
If you need information for a Poster - contact them.