check out the new remote control Jockey Wheel SmartBar rearview170 Beam Communications SatPhone Shop Topargee products
Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: pass word managers......


Senior Member

Status: Offline
Posts: 158
Date:
pass word managers......


Does anyone use one??

I "googled" how they work but could not find an answer that I could understand!!

How do they "communicate" your P/W if you have forgotten it?

cheers Bilbo

 



__________________


Guru

Status: Offline
Posts: 541
Date:

bilbo wrote:

Does anyone use one??

I "googled" how they work but could not find an answer that I could understand!!

How do they "communicate" your P/W if you have forgotten it?

cheers Bilbo

 


 Just ask Optus!    lol



__________________

Age does not weary us, makes us go travelling more



Guru

Status: Offline
Posts: 964
Date:

Password Managers come in a variety of flavours. Some store passwords you enter, others generate complex passwords for you, some are restricted to one device while others span multiple devices, some will even store ancillary information attached to the user account accessed by the credentials you have added (like account numbers or app preferences).

Essentially they are an encrypted database of the credentials you are using and that database is more secured than a simple text file or piece of paper. They typically auto fill the username and password for you to submit, they don't look up your credentials and expect you to enter them although most have a look up function that let you view your passwords. Not all apps and websites will interact with password manager (government, banking and finance apps may not for instance).

Password Managers don't make your information held by others any more secure or safe, they are a means to safely secure and manage your own credentials.

Everyone should be using a password manager with a secure complex password and that password should a secure means to recover the master password. They take over the day to day "remembering"

__________________


Guru

Status: Offline
Posts: 877
Date:

That was a good explanation dabbler. Thank you.

Can anyone on here suggest a good password manager App to use for a retired old fella like me with a poor memory.

__________________

Welcome to Biggs Country many may know it as Australia

This members posts may contain;

The actual truth

If offended, scroll on by.



Guru

Status: Offline
Posts: 4132
Date:

Look at the security incidents for LastPass:

https://en.wikipedia.org/wiki/LastPass#Security_issues

I can't bring myself to trust a web based password management service. I would much rather an open source password manager residing on my own machine, perhaps on a USB stick.



__________________

"No friend ever served me, and no enemy ever wronged me, whom I have not repaid in full."

Lucius Cornelius Sulla - died 78 BC 

 



Senior Member

Status: Offline
Posts: 158
Date:

I am with Dorian here.....I dont trust "anyone".

To be able to put the P/W on a USB stick.......dont you have to do that "electronically"....is that not a prob in itself in that the P/W is available to a hacker at a later date?? 

How about keeping P/W in a diary?? ( I have a very very safe hiding place )

cheers Bilbo



__________________


Guru

Status: Offline
Posts: 4706
Date:

A cloud based password manager is somewhat like "Trust me, I'm a gynaecologist." If it's on the net it's available to a hacker 24/7 if it's on a USB stick it isn't. But don't loose your USB stick without an up to date backup and a certain memory of the master password. You could email the (encrypted?) master password to your Gmail account but don't make the subject line "Master password" :)

I don't use a password manager but maybe should, I keep my passwords in an encrypted file on my local hard drive but, for things such as banking, I simply have strong passwords which I can remember.

It is a problem.



__________________

 

"I beseech you in the bowels of Christ think it possible you may be mistaken"

Oliver Cromwell, 3rd August 1650 - in a letter to the General Assembly of the Kirk of Scotland



Guru

Status: Offline
Posts: 4706
Date:

bilbo wrote:

How about keeping P/W in a diary??


There is much to be said for this.

But be a little cryptic: eg. Commonwealth Bank becomes "ComB" and the like.



__________________

 

"I beseech you in the bowels of Christ think it possible you may be mistaken"

Oliver Cromwell, 3rd August 1650 - in a letter to the General Assembly of the Kirk of Scotland



Guru

Status: Offline
Posts: 532
Date:

Agree re available programmes. If they have been written by MS, Apple or whomever, they can be hacked more easily.

Did my own with an open-source word processor which required one password to open, another to edit.

All entries were in "coded" titles with related passwords. 

Must say thanks for the USB stick storage clue - must do that.



__________________

Cheers - Ian

I slowly realise as I get older that I am definitely NOT the fastest rat in the race.

Also the older I get the more I realise I do not know.



Guru

Status: Offline
Posts: 1197
Date:

I use Keepass. It is cross platform with versions for various operating systems. I use it on Windows and Android phone and the same file can be copied between platforms. No cloud storage used. There is also a portable version that works entirely on a USB stick. It generates passwords by default but I prefer to save my own.

It is free but more importantly is open source, which means the code that is used to build the app is available for anyone to see. So you can have confidence there is no hidden section that secretly does things you would not want.

Keepass features



__________________


Senior Member

Status: Offline
Posts: 339
Date:

Try three spreadsheets which have very different names. e.g. "HoldenCars.xlsx", "TestInfo.xlsx", "Furniture.xlsx" and each have a different password to open them.

The first column in each spreadsheet holds the key to join the data together.

The first spreadsheet has the name of the entity you are interested in.  e.g. "rtnsk74%s9", "The Grey Nomads Forum"

The second spreadsheet has the login name of the entity you are interested in.  e.g. "rtnsk74%s9", "myLogin"

The third spreadsheet has the password of the entity you are interested in.  e.g. "rtnsk74%s9", "myPassword"

Without all three spreadsheets, the data is useless and it's not as complicated as it looks.

If you want to be even more clever, you can create a fourth spreadsheet with a simple macro in it which opens the other three spreadsheets and then if you enter the entity you are interested in, it shows all three pieces of info next to each other.

Alternate to the spreadsheets, you can do the same with three small notebooks and then hide them around the house or caravan.

 



__________________


Guru

Status: Offline
Posts: 4132
Date:

I thought I would look for KeePass in the Microsoft Store.

Then I saw this thread:

https://sourceforge.net/p/keepass/discussion/329220/thread/a9d2de0f/

"Someone decided to trade KeePass for $11 in Microsoft Store. I wonder how did it become approved"

 



__________________

"No friend ever served me, and no enemy ever wronged me, whom I have not repaid in full."

Lucius Cornelius Sulla - died 78 BC 

 



Guru

Status: Offline
Posts: 1197
Date:

Now almost 5 years later and no updates to that thread. One of the comments pointed out the size of the file was larger, so who knows what else it had. Presumably the scam has been removed from Microsoft Store. Shame on you Microsoft.

Get it direct from the developers from the link I provided.

__________________


Senior Member

Status: Offline
Posts: 158
Date:

Thanks everyone for your responses.......but for me most are out of my "IT"  league ........I will just have "difficult" P/W's for banks/govt agencies and keep them safe "somewhere on 40 acres"......cheers Bilbo

 



__________________


Senior Member

Status: Offline
Posts: 291
Date:

I use KeePassXC and restrict it purely to my computer; do not store it in the 'Cloud'. The main thing to remember with passwords is that the longer it is, the harder the job of a hacker to break in. I use a 20+ character master password. However, a good thing that many companies are doing now is offering/enforcing the use of multi factor authorisation (MFA) also known as two step verification. Where an SMS or email or 'Authenticator' is used to send a code to you when you try to login to email or bank, etc. This MFA reduces the value of the password (to a hacker), but increases the value of (typically) your phone, if that is the MFA facilitator. Don't lose your phone!

__________________


Senior Member

Status: Offline
Posts: 215
Date:

Like Bilbo I write mine down and keep somewhere safe.

Instead of trying to remember a heap of letters and numbers mixed together I use a sentence I make up with upper and lower case letters, eg --IwWmdT# I will Wash my dog Tomorrow hash.

Barry

__________________
100 Series Turbo Cruiser & 21ft Lotus Trackvan


Guru

Status: Offline
Posts: 877
Date:

Thanks for the warnings about the Apps.

It stands to reason that they may only be a secure as the trust you put in them.

I am not that tech savvy when it comes to computers generally so I think I will stick to the old reliable note pad.
Having said that, you guys have given me some great ideas when it comes to making up a password so what I might do is change any of my simple passwords with ones that might be a little more difficult to guess or hack.

__________________

Welcome to Biggs Country many may know it as Australia

This members posts may contain;

The actual truth

If offended, scroll on by.



Guru

Status: Offline
Posts: 1192
Date:

I use a password protected page in OneNote for all of mine. Easy to update if you change things & only one password to get in :)

__________________

'Once you are infected with the travel bug you have it for the rest of your life - there is NO cure'

http://hukaroa.blogspot.com.au

 



Guru

Status: Offline
Posts: 4706
Date:

spida wrote:

I use a password protected page in OneNote for all of mine. Easy to update if you change things & only one password to get in :)


And that's uploaded to "The Cloud" is it?

Good luck.



__________________

 

"I beseech you in the bowels of Christ think it possible you may be mistaken"

Oliver Cromwell, 3rd August 1650 - in a letter to the General Assembly of the Kirk of Scotland



Senior Member

Status: Offline
Posts: 431
Date:

type in, Have I been pwnd, or pwnd passwords, in your browser. you may all get a shock. well worth a try.

__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us
Purchase Grey Nomad bumper stickers Read our daily column, the Nomad News The Grey Nomad's Guidebook