PDA

View Full Version : Password protectors - a suit of armour, or a Trojan horse?



anfearchiuin
03-22-2014, 12:09 PM
Recently I looked on line at reviews for the top password protectors. After reading, I chose to use LastPass and paid up for the professional option to allow my mobile phone and tablet to be included.

My suit of armour: every one of my services is now protected by a *different* complex password

My trojan horse: LastPass know all my secrets

Do you think that now I am more or less secure?

the_nephrops
03-23-2014, 01:24 AM
I use, for a long time, KeePass to store my passwords after I had an brute force attack on my primary email account. After that I changed for a more complex one, created by KeePass, and I didnīt had any kind of attack until now.
Be sure to protect your master file (the one with all passwords) with a password that you remember and keep a secure (an updated) copy.

Regarding security, in my humble opinion, yes you're a little more secure.

anfearchiuin
03-23-2014, 09:31 AM
Thankyou for sharing yor experience.

MysticRiffs
05-02-2014, 02:40 AM
Secondly, consider this. You master password isn't kept by them, which has two immediate ramifications. 1. It's about as secure as it can be. Even if they get thoroughly raped by hackers, no one gets access to the master password. 2. If you lose your password, that's effectively game over for everyone of those uniquely passworded sites.

A lot of techs recommend using a pnemonic (spelling). Take this site, for example. FileSharingTalk. Create a simple passphrase that you'll remember. I think filesharingtalk is one of the biggest nzb sites I've ever used, but I wish they had a shout box! is a good enough example. The passphrased for it can be ItFSTiootBNSIeu,bIwthaSB! Crack that, bitches. :D

piercerseth
05-02-2014, 11:50 AM
Another vote for KeePass (along w/ KeeFox plugin). Went back and reset all my passwords after the heartbleed nonsense with http://strongpasswordgenerator.com/ Keep the pwd db in a few different places on assorted media.

megabyteme
05-02-2014, 12:32 PM
Another vote for KeePass (along w/ KeeFox plugin). Went back and reset all my passwords after the heartbleed nonsense with http://strongpasswordgenerator.com/ Keep the pwd db in a few different places on assorted media.


Sure, that'll kinda work. However, if you are serious, you'll assign double blind, handwritten passwords (created by someone else, but neither of you know what the sequence is, the writer does not know what it it for), random strangers are each selected (at gunpoint), blindfolded, and taken to an unknown location. There, they are each "asked" to enter a single line of user info- they do not know any other line. Upon completion of their task, they are forced to consume 4 Ambien per hour until they can no longer remember their name. Implant in them that they have a new name. Torture them until they believe this.

Burn all notebooks, along with "volunteers' " clothes and personal effects, and release them (still blindfolded, beaten, and believing their new identity) at random gravel pits.

Never log into these accounts as the NSA is watching your every move, and your whole operation has been compromised. Do not even log back into this site for further instructions.

piercerseth
05-06-2014, 11:08 PM
Another vote for KeePass (along w/ KeeFox plugin). Went back and reset all my passwords after the heartbleed nonsense with http://strongpasswordgenerator.com/ Keep the pwd db in a few different places on assorted media.


Sure, that'll kinda work. However, if you are serious, you'll assign double blind, handwritten passwords (created by someone else, but neither of you know what the sequence is, the writer does not know what it it for), random strangers are each selected (at gunpoint), blindfolded, and taken to an unknown location. There, they are each "asked" to enter a single line of user info- they do not know any other line. Upon completion of their task, they are forced to consume 4 Ambien per hour until they can no longer remember their name. Implant in them that they have a new name. Torture them until they believe this.

Burn all notebooks, along with "volunteers' " clothes and personal effects, and release them (still blindfolded, beaten, and believing their new identity) at random gravel pits.

Never log into these accounts as the NSA is watching your every move, and your whole operation has been compromised. Do not even log back into this site for further instructions.

Had a crypto nerd try to explain one-time pads. Turns out they aren't the same thing my gf sends me to the store to buy, but equally indecipherable.
Oblig xkcd:
142946

megabyteme
05-07-2014, 12:54 AM
Never underestimate the value of violence upon the nerd population. :devil: