▲ 353 ▼ Was it hunter2 or hunter3 (files.catbox.moe) submitted 2 years ago by Gork@lemm.ee to c/memes@sopuli.xyz 32 comments fedilink hide all child comments
[–] Rikj000@discuss.tchncs.de 52 points 2 years ago* (4 children) 2 words for you: Password Manager Get around to using one :P I only remember my password to my PW manager, which additionally is encrypted with a key file to increase security. The rest of my PWs are 128 character long random generated PWs, with capitals, numbers, special characters etc.. permalink fedilink source hideshow 8 child comments replies: [–] Badeendje@lemmy.world 12 points 2 years ago Yep. Several years ago I switched and it took a little getting used to. But now I would not want it any other way. The plugins in the browsers make it convenient and also a proper app on your mobile and you are set to go. Click on a password field and then you can click on the plugin to fill the fields. permalink fedilink source parent [–] AbsurdityAccelerator@lemmy.world 6 points 2 years ago I wish all my passwords were 128 characters. Most sites won't allow anything that complex. Because apperantly making the password hash field longer is hard /s permalink fedilink source parent [–] mormund@feddit.de 3 points 2 years ago (4 children) Where do you keep the key file and the PW managers DB? I feel like they would be too much side-by-side to really increase security in my case permalink fedilink source parent hideshow 8 child comments replies: [–] pipe01@programming.dev 4 points 2 years ago Can always use a service like bitwarden, even their free tier is very good permalink fedilink source parent [–] Rikj000@discuss.tchncs.de 4 points 2 years ago I won't disclose where I store mine. But I'd recommend to: Not backup your PW manager's database + key file in the same location (That would decrease security, x1 data breach would allow them to easily brute force your PW DB since they'll have the key) Not go with a PW manager that does not allow you to choose a location where you desire to backup to (Seen plenty of mainstream PW managers getting data breached by now, so going with a cloud, which is not solely used for PW managers, has an advantage imo, since they tend to be less targeted by hackers) I've been happily using KeeWeb + Keepass2Android for years now: https://github.com/keeweb/keeweb https://github.com/PhilippC/keepass2android permalink fedilink source parent [–] tkk13909@sopuli.xyz 3 points 2 years ago (2 children) You could use a USB drive that you only ever plug in to open the password manager. It's not the most secure option but it's a bit better than no key file at all. permalink fedilink source parent hideshow 4 child comments replies: [–] mormund@feddit.de 3 points 2 years ago (1 child) Can't use it with a phone though. To be honest, I think just having a password manager gives you protection against 99% of the attack surface. And if someone is really determined, I'm not sure the key file will be hard to obtain for them no matter what. But I was curious what setup others have permalink fedilink source parent hideshow 2 child comments replies: [+] lud@lemm.ee 3 points 2 years ago* (last edited 1 year ago) [deleted] permalink fedilink source parent [–] vox@sopuli.xyz 0 points 2 years ago* or store the key in a tpm chip protected by password +biometric auth? that's what kost OSs do for storing passkeys and encryption keys permalink fedilink source parent [–] petrescatraian@libranet.de 3 points 2 years ago* (last edited 2 years ago) @mormund I used to store them in a paper notebook, away from the prying eyes of malware and other shenanigans. Now I also have them in a password manager for easy access in case I need them, if the account supports 2FA TOTP. @Rikj000 permalink fedilink source parent [–] I_Has_A_Hat@lemmy.world 1 point 2 years ago I have tried to use a password manager like 3 separate times now and can never seem to get the hang of it permalink fedilink source parent
[–] Badeendje@lemmy.world 12 points 2 years ago Yep. Several years ago I switched and it took a little getting used to. But now I would not want it any other way. The plugins in the browsers make it convenient and also a proper app on your mobile and you are set to go. Click on a password field and then you can click on the plugin to fill the fields. permalink fedilink source parent
[–] AbsurdityAccelerator@lemmy.world 6 points 2 years ago I wish all my passwords were 128 characters. Most sites won't allow anything that complex. Because apperantly making the password hash field longer is hard /s permalink fedilink source parent
[–] mormund@feddit.de 3 points 2 years ago (4 children) Where do you keep the key file and the PW managers DB? I feel like they would be too much side-by-side to really increase security in my case permalink fedilink source parent hideshow 8 child comments replies: [–] pipe01@programming.dev 4 points 2 years ago Can always use a service like bitwarden, even their free tier is very good permalink fedilink source parent [–] Rikj000@discuss.tchncs.de 4 points 2 years ago I won't disclose where I store mine. But I'd recommend to: Not backup your PW manager's database + key file in the same location (That would decrease security, x1 data breach would allow them to easily brute force your PW DB since they'll have the key) Not go with a PW manager that does not allow you to choose a location where you desire to backup to (Seen plenty of mainstream PW managers getting data breached by now, so going with a cloud, which is not solely used for PW managers, has an advantage imo, since they tend to be less targeted by hackers) I've been happily using KeeWeb + Keepass2Android for years now: https://github.com/keeweb/keeweb https://github.com/PhilippC/keepass2android permalink fedilink source parent [–] tkk13909@sopuli.xyz 3 points 2 years ago (2 children) You could use a USB drive that you only ever plug in to open the password manager. It's not the most secure option but it's a bit better than no key file at all. permalink fedilink source parent hideshow 4 child comments replies: [–] mormund@feddit.de 3 points 2 years ago (1 child) Can't use it with a phone though. To be honest, I think just having a password manager gives you protection against 99% of the attack surface. And if someone is really determined, I'm not sure the key file will be hard to obtain for them no matter what. But I was curious what setup others have permalink fedilink source parent hideshow 2 child comments replies: [+] lud@lemm.ee 3 points 2 years ago* (last edited 1 year ago) [deleted] permalink fedilink source parent [–] vox@sopuli.xyz 0 points 2 years ago* or store the key in a tpm chip protected by password +biometric auth? that's what kost OSs do for storing passkeys and encryption keys permalink fedilink source parent [–] petrescatraian@libranet.de 3 points 2 years ago* (last edited 2 years ago) @mormund I used to store them in a paper notebook, away from the prying eyes of malware and other shenanigans. Now I also have them in a password manager for easy access in case I need them, if the account supports 2FA TOTP. @Rikj000 permalink fedilink source parent
[–] pipe01@programming.dev 4 points 2 years ago Can always use a service like bitwarden, even their free tier is very good permalink fedilink source parent
[–] Rikj000@discuss.tchncs.de 4 points 2 years ago I won't disclose where I store mine. But I'd recommend to: Not backup your PW manager's database + key file in the same location (That would decrease security, x1 data breach would allow them to easily brute force your PW DB since they'll have the key) Not go with a PW manager that does not allow you to choose a location where you desire to backup to (Seen plenty of mainstream PW managers getting data breached by now, so going with a cloud, which is not solely used for PW managers, has an advantage imo, since they tend to be less targeted by hackers) I've been happily using KeeWeb + Keepass2Android for years now: https://github.com/keeweb/keeweb https://github.com/PhilippC/keepass2android permalink fedilink source parent
[–] tkk13909@sopuli.xyz 3 points 2 years ago (2 children) You could use a USB drive that you only ever plug in to open the password manager. It's not the most secure option but it's a bit better than no key file at all. permalink fedilink source parent hideshow 4 child comments replies: [–] mormund@feddit.de 3 points 2 years ago (1 child) Can't use it with a phone though. To be honest, I think just having a password manager gives you protection against 99% of the attack surface. And if someone is really determined, I'm not sure the key file will be hard to obtain for them no matter what. But I was curious what setup others have permalink fedilink source parent hideshow 2 child comments replies: [+] lud@lemm.ee 3 points 2 years ago* (last edited 1 year ago) [deleted] permalink fedilink source parent [–] vox@sopuli.xyz 0 points 2 years ago* or store the key in a tpm chip protected by password +biometric auth? that's what kost OSs do for storing passkeys and encryption keys permalink fedilink source parent
[–] mormund@feddit.de 3 points 2 years ago (1 child) Can't use it with a phone though. To be honest, I think just having a password manager gives you protection against 99% of the attack surface. And if someone is really determined, I'm not sure the key file will be hard to obtain for them no matter what. But I was curious what setup others have permalink fedilink source parent hideshow 2 child comments replies: [+] lud@lemm.ee 3 points 2 years ago* (last edited 1 year ago) [deleted] permalink fedilink source parent
[+] lud@lemm.ee 3 points 2 years ago* (last edited 1 year ago) [deleted] permalink fedilink source parent
[–] vox@sopuli.xyz 0 points 2 years ago* or store the key in a tpm chip protected by password +biometric auth? that's what kost OSs do for storing passkeys and encryption keys permalink fedilink source parent
[–] petrescatraian@libranet.de 3 points 2 years ago* (last edited 2 years ago) @mormund I used to store them in a paper notebook, away from the prying eyes of malware and other shenanigans. Now I also have them in a password manager for easy access in case I need them, if the account supports 2FA TOTP. @Rikj000 permalink fedilink source parent
[–] I_Has_A_Hat@lemmy.world 1 point 2 years ago I have tried to use a password manager like 3 separate times now and can never seem to get the hang of it permalink fedilink source parent