WoodCentral Forums

Est. 1998 — 27 years of woodworking knowledge

O.T. Password Managers

Posts

O.T. Password Managers

#1

O.T. Password Managers

Stuart Johnson

If you subscribe to a a password manager like LastPass or 1 Password how do you fix or update all the current accounts used daily. Plus, what about user names are they input automatically? The sites seem a little vague on the mechanics other than try it and see. I sure don't want to try one and have my current accounts messed up.

Re: O.T. Password Managers

#2

Re: O.T. Password Managers

John McGaw

I can only reply with reference to RoboForm, the password manager I've been using for years. I'll try to keep this non-technical.

The main answer is that the manager does not tamper with whatever you have set up for user names and passwords or whatever you have to recall and repeat to log in -- you go to the site's login page and enter the correct information and then tell the manager to remember that information. Up until that time it knows nothing about what is going on. From then on when you tell the manager to log into the same site it will go to the proper URL and fill in the login form with whatever it remembered before and then trigger the login.

The manager also as the ability to remember the contents of other forms you may sometimes fill out, save secure notes, generate 'good' passwords, check all of the memorized passwords for their quality and to see if you have used the same on on multiple sites. RoboForm saves your passwords and other data in an encrypted file on your computer and on their own servers as a backup. If you run the manager on multiple computers the data on the external server serves to synchronize.

Re: O.T. Password Managers

#3

Call me old fashioned...

Denis Chenard in Ottawa

But I would NEVER use a password manager. Two reasons: first, computers can be hacked and password info retrieved (even if I use Linux I won't leave passwords on my machine). Second, not using a manager forces you to remember your passwords so that you can log in into accounts/access specific sites that require passwords while using somebody else's machine (same reason why I don't use speed dial on phones).

Better safe than sorry...

DC

Re: O.T. Password Managers

#4

Re: Call me old fashioned...

Don Evans

Hey Dennis

Your advise is the safest way but can you remember 180+ log in?

That how many I have.

I use Norton Internet Security and it has never failed me. Internet Security saves and protects my password and unless something changes I'll trust it to continue.

Norton just warned me about the new problem of WiFi hacking so if you use cell phones Ipads Kindles etc via you wifi then they can be hacked. Latest virus is called Krack.

You gotta protect yourself.

Friend of mine just got hacked and he was using McAfee the free one, you get what you pay for, right!

Don

Re: O.T. Password Managers

#5

Re: Call me old fashioned...

John McGaw

Funny, I just got done counting the logins stored in my manager and came out with thae same 180+ estimate (not being up to detailed counting before the coffee has had full effect). If one is using good passwords I don't see anyone remembering that number of long random gibberish strings.

Re: O.T. Password Managers

#6

Re: Call me old fashioned...

Bill Howatt

I use KeyPass2 but it only gets used as a secure storage vault - it does not link to sites and I have to open it manually to retrieve a forgotten password. I have an aversion to any remembered auto-complete or similar.

I do not use complicated passwords for things like forums so I am usually only retrieving infrequently used, complex passwords.

In my KeyPass2 program I keep other login information such as "Security Q&A", software serial numbers, or other relevant information to the site or program.

Re: O.T. Password Managers

#7

I'm in the "old fashioned" camp too.

Mike Circo

But some technology.

I use a free application called "Password Gorilla". I got it initially because it had both Windows and Linux applications so I could use a common database from all three of my systems.

The database is encrypted and passkey protected. The program allows you to cut and past the site url, ID, and password as you need. you can link it to a browser and it will bring up the site.

Yes it is a manual password manager. YOu have to create a record with the name of the site, the ID and password. But since you can just cut and paste all the info, you can make complex (safer) passwords because you don't have to remember them.

Works great for me. But everyone is different.

Re: O.T. Password Managers

#8

Same here...

John in NM

I can't imagine a world in which I would actually need 180, or even 30, complicated, individual passwords.

Re: O.T. Password Managers

#9

Re: O.T. Password Managers

Jim Dillon

Stuart, I use LastPass. If I understand your question, once you have LastPass activated in your browser it monitors your login activity and will ask after you have entered the site if you want to store that site for its password "vault" thus permitting you to log into that site (either manually or automatically) in the future. Regarding user names, they are entered automatically depending on what you use at the login site. I started out slowly at an unimportant web site to get a feeling for how the software operates etc. Then moved on to more important sites. The only glitch I've encountered is somehow the software "disappeared" from my browser (Chrome) window. I reinstalled the software, retyped my master password and everything was good again. I breathed a sigh of relief! As I understand it, the "vault" containing your passwords is not actually stored on your computer but in the cloud somewhere - all encrypted. I use LastPass to generate very secure passwords all the time - passwords that I could never possibly remember. I believe you can also print out a list of your sites, user names and passwords.

Hope this helps. Jim

Re: O.T. Password Managers

#10

Re: Same here...

John McGaw

I guess the question comes down to "how many random 12-character alphanumeric (upper-lower-case with interspersed punctuation) strings" can you memorize without error? Whether it is 3 or 30 or 300, failing the test at a critical time could be troublesome and possibly very expensive. I can perfectly remember my 8-digit USAF serial number from 1965 but if I had to remember z%Z7yw5yBgF8 and Y73J@Jj6ce$R and @fdCj9AY!hG4 I'd be in deep do-do.

Re: O.T. Password Managers

#11

The difference....

John in NM

My computer use appears to be uninteresting enough to not need fully random passwords, with just a couple exceptions. The best security is often being too boring to bother with.

Ironically, my employer just implemented a password policy that requires only alpha numeric - no special characters at all. Not sure what the advantage of that could be.

Re: O.T. Password Managers

#12

what am I missing?

Bill Tindall, E.Tn.

why does anyone need 180 passwords? What is risky about having one password for stuff like wood central and a very few secure ones for everything secure? NSA gets hacked. Everything gets hacked. I don't see that having a manageable number of passwords is more risky than having them all in one tidy location that must be a target for every budding hacker.

Re: O.T. Password Managers

#13

Re: The difference....

John McGaw

The major security problem presented there is that, if one re-uses passwords, the fact that nearly all of the URLs are nothing important is no protection if even one important site is one of those re-using and it gets noticed. If there is no re-use then safety, while not assured, is not compromised by convenience.

I had never realized how shoddy my practices had become until RoboForm added an analysis function then scores of sites using the same (pretty decemt) password showed up.

Re: O.T. Password Managers

#14

Re: The difference....

jesse cloud

Don't know if this is the case with your organization, but many intentionally 'dumb down' passwords so that they can easily break them if needed.

Additionally, from day one the government has dumbed down allowable encryption formats as a 'matter of national security'. Not as bad as it used to be, but there are still some constraints on what commercial products can do in terms of security, even more so if they want to export.

Re: O.T. Password Managers

#15

Re: The difference....

John in NM

And where did I say anything about reusing passwords?

Non-random does not equal repeated.

Re: O.T. Password Managers

#16

Re: what am I missing?

AZ in Colorado Springs

The danger of repeating the same password is that if someone cracks the code on tour savings account then they can get into all the others quite easily.

Re: O.T. Password Managers

#17

Re: what am I missing?

Bill Howatt

I don't think Bill said he was using non-secure, repeated passwords for his "critical" accounts - only for things like forums. That's pretty well the way I operate as well.

Most sites like forums don't ask for answers to security questions and other measures if you forget your passwords - you don't want to have a weak password on any account that seeks that type of info since it might be the same answer on an important account, eg, mother's maiden name.

Bill

👍 This page answered my questions

Your vote helps other woodworkers quickly find the answers and techniques that actually work in the shop.