What is 'best practice' for password management?

ship691

New member
Member
VIP
Local time
10:10 AM
Messages
136
Hi

What is the 'best practice' for managing one's passwords?

A) HOW SHOULD I STORE PASSWORDS?
Problems:
1. I need to manage a fairly large number (i.e. 50+). So there are too many to remember.

2. Obviously I don't want to keep them inside a simple unencrypted text file, in case my data gets hacked.

3. If I download dedicated password application how can I trust it?(!)

4. I don't trust 'The Cloud' nor any of the big data owners: google, apple, amazon, drop-box et al.

5. I don't want to be tied to anything that I cant migrate with me onto my next hardware, when I come to upgrade my PC(s).

Either way I dont really want to pay anything (certainly not more than a few dollars) for this security.

I was thinking of using something like TrueCrypt to create a virtual drive (that I encrypt robustly) and then storing my passwords in an ordinary text file.
That way I would have a single master password (for TrueCrypt) which would give access to all the other passwords.
[Aside: Obviously if I forget my master password I'm screwed!]


B) PASSWORD CONVENTIONS
As you know many sites require passwords that meet specific rules e.g.
- At least one upper AND one lower case letter
- At least one digit
- No tripplets (three characters the same next to each other) (iTunes!)
- No more than 16 characters

Double-click problems
Some sites allow extended ASCII characters (e.g. £$%^&*) , which give VASTLY better security of course. BUT they are a mighty pain to use regularly because if you double-click using Windows (XP /7 /8), windows doesn't accept extended as being part of 'a word' and ignores the extended ASCII characters in your password. And if you TRIPLE-click, it then selects the entire line! This is a nightmare if you are in and out of passwords all day.

SUMMARY
a) I want passwords that are pretty much secure.
e.g. say 1 trillion years from my desktop to crack according to this site:
https://howsecureismypassword.net
(Not that I trust it not to harvest whatever I put in and use against me!)
This is extremely hard (perhaps impossible) to achieve within 16 characters unless one uses extended ASCII.

b) For day-to-day convenience, I want to absolutely minimize the number of clicks and keystrokes.

c) For low security sites that I dont give a damn about, I just want something easy to type in.


- Any suggestions?

With thanks

J


P.S. For reasons of security I also quite often clear out all cookies.
 

My Computer My Computer

At a glance

Windows 7 x64 Professional (SP1)Intel Core i5 CPU 750 @2.67GHz8GBATI Radeon HD 5700 series
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Professional (SP1)
CPU
Intel Core i5 CPU 750 @2.67GHz
Motherboard
Intel
Memory
8GB
Graphics Card(s)
ATI Radeon HD 5700 series
Hard Drives
INTEL SSD ATA 256GB
I have gone through the same thing. Most of mine I don't worry too much about, like this site. If anyone discovered my password here, what harm could come to me, except someone typing messages under my name, no big deal. The only ones I really worry about are my bank, paypal and ones like that where money is involved. I have a word document with Passwords that is buried in a file and is doubtful anyone could find it.
 

My Computer My Computer

At a glance

Windows 7 Home Premium 32-Bit - Build 7600 SP1Intel Core i3-2120 3.30GhzKingston 4 GB DDR3 1333 mhzAMD Radeon HD6670
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
This post shames me to a certain extent and prods me in others. I'm one of those dummies that only use a limited number of passwords for all my sites. Been meaning to diversify and will very soon. I am the only person with access to my machine and the passwords I use are fairly secure so I'm comfortable with mine until the end of my season.

Now as to your query and comments ........ I think the TrueCrypt solution you mentioned would be the best. I've used it before in the way you describe and it worked perfectly. Thumb drive for me. Lastpass is a pretty good manager also and I'm sure you'll get other recommendations to it.
 

My Computer My Computer

At a glance

Windows 10x64 Build 1709Intel i7 7700HQ Kaby Lake16 GB DDR4 @2400Nvidia Geforce GTX 1060
Computer type
Laptop
Computer Manufacturer/Model Number
MSI GE72VR Apache Pro-416
OS
Windows 10x64 Build 1709
CPU
Intel i7 7700HQ Kaby Lake
Motherboard
Micro-Star Intl. MS-179B (U3C1)
Memory
16 GB DDR4 @2400
Graphics Card(s)
Nvidia Geforce GTX 1060
Screen Resolution
1920x1080 120Hz
Hard Drives
256 GB Nvme M.2 SSD

1TB HDD@7200
Cooling
Cooler Blast 4
Keyboard
Steel Series
Antivirus
Bit Defender Free
Browser
Edge
Double-click selection
After extensive googling I cant find any solution to the double-click not selecting extended ASCII problem. Bl**dy Microsoft :^[

However my partial solution to this double-click selection problem is to store my passwords in an (Excel) spreadsheet, rather then in a text file. A single click on a cell selects it's entire contents, which can then be pasted in to a web page, weird characters and all !

Lastpass
A) it has had security breaches
B) the passwords are stored somewhere in the cloud where they with enough processing power get decrypted.
C) how sure can we be that they haven't coded a backdoor into their system, either deliberately or accidentally.
D) what happens in the event of a war and the state nationalises them?
E) what happens if a trojan/virus installs itself into my system and starts harvesting data e.g. keystrokes
Nice try, but again we cant completely trust it.

Nope - call me old-fashioned by I'd rather store my own passwords thank you.

PW Conventions
Fwiw, some people use a convention that uses the name of the site in question as part of their password. e.g. You might incorporate the first 3 letters of the site in question into the start or the end of your PW. Personally I find that cumbersome and would rather to a control/F to find the PW and copy and paste. Also I have more than one email address which adds to the complication of what needs to be stored...(!)
 

My Computer My Computer

At a glance

Windows 7 x64 Professional (SP1)Intel Core i5 CPU 750 @2.67GHz8GBATI Radeon HD 5700 series
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Professional (SP1)
CPU
Intel Core i5 CPU 750 @2.67GHz
Motherboard
Intel
Memory
8GB
Graphics Card(s)
ATI Radeon HD 5700 series
Hard Drives
INTEL SSD ATA 256GB
I use a passworded Excel file that opens with the touch of Macro key. I just hope I never forget the password to that!
 

My Computer My Computer

At a glance

W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x6...i7-4790k @ 4GHz (4.4GHz Boost)16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9...EVGA GTX 980 Classified
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x64 VM | Linux Mint VM
CPU
i7-4790k @ 4GHz (4.4GHz Boost)
Motherboard
ASUS Sabertooth Z87 (BIOS Rev 2004)
Memory
16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9-9-9-27
Graphics Card(s)
EVGA GTX 980 Classified
Sound Card
Realtek Onboard
Monitor(s) Displays
Samsung S27D390
Screen Resolution
1920 x 1080
Hard Drives
240GB Intel 520 Series SSD |
Samsung 850 EVO 120GB SSD |
2TB WD Caviar Black |
2TB WD Caviar Black |
2TB WD Caviar Green
PSU
Corsair HX850-80 Gold Modular
Case
Cooler Master Silencio 650
Cooling
Corsair H80i w/2 x Corsair SP120 | 2 x 120mm Noctua NF-S12B
Keyboard
Microsoft Sidewinder X4
Mouse
Gigabyte M6900 optical
Internet Speed
152mb
Antivirus
F-Secure
Browser
Firefox 38.0
Other Info
Backup Rig: Win 7 Pro 64-bit | AMD A10-5800k | ASUS F2A85-V Pro | 8GB Samsung DDR3 @1600MHz | 120GB Toshiba SDD | 2TB Seagate HDD | Cooler Master Silencio 550
Just a passworded Excel file, on it's own.... It's a start but, suppose you lost your data on a train would you be happy with that level of security? Really...?
 

My Computer My Computer

At a glance

Windows 7 x64 Professional (SP1)Intel Core i5 CPU 750 @2.67GHz8GBATI Radeon HD 5700 series
Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom
OS
Windows 7 x64 Professional (SP1)
CPU
Intel Core i5 CPU 750 @2.67GHz
Motherboard
Intel
Memory
8GB
Graphics Card(s)
ATI Radeon HD 5700 series
Hard Drives
INTEL SSD ATA 256GB
I would also suggest you use a TruCrypt file for that. Store a Excel File in it and if you are the only user on your machine or nobody else uses your user account your can create a batch file for Autorun to mount your drive at your login.

However this batch file will be visible when executed and show your master password. To fix that there is a way by using a VBScript to hide the CMD window. Forgot where I read that.

This will make it quite comfortable to use. I think you can also have the batch file prompt you for the password in case you find it unsafe in autoruns.

About Password length I'd choose at least 16 characters of all kinds with numbers and digits and make shure to hit the spacebar 1-2 times in the password aswell. That is not very common but helpful and more secure.
 

My Computer My Computer

At a glance

Windows 7/8 Pro 64biti5-4670Corsair 16GBGigabyte GeForce 760
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7/8 Pro 64bit
CPU
i5-4670
Motherboard
Asus Gryphon
Memory
Corsair 16GB
Graphics Card(s)
Gigabyte GeForce 760
Hard Drives
Intel SSD - 180Gb
Are you speaking of very important sites that you are protecting such as your bank or is this just everyday sites that you visit?
 

My Computer My Computer

At a glance

Windows 7 Home Premium 32-Bit - Build 7600 SP1Intel Core i3-2120 3.30GhzKingston 4 GB DDR3 1333 mhzAMD Radeon HD6670
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
Just a passworded Excel file, on it's own.... It's a start but, suppose you lost your data on a train would you be happy with that level of security? Really...?

If I lost my data on a train I'd be wondering why I had a 30lb+ mid tower rig with me on a train.
 

My Computer My Computer

At a glance

W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x6...i7-4790k @ 4GHz (4.4GHz Boost)16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9...EVGA GTX 980 Classified
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
W7 Pro x64 SP1 | W10 Pro IP x64 | W8.1 Pro x64 VM | Linux Mint VM
CPU
i7-4790k @ 4GHz (4.4GHz Boost)
Motherboard
ASUS Sabertooth Z87 (BIOS Rev 2004)
Memory
16GB DDR3 Kingston HyperX Fury @ 1600MHz CL 9-9-9-27
Graphics Card(s)
EVGA GTX 980 Classified
Sound Card
Realtek Onboard
Monitor(s) Displays
Samsung S27D390
Screen Resolution
1920 x 1080
Hard Drives
240GB Intel 520 Series SSD |
Samsung 850 EVO 120GB SSD |
2TB WD Caviar Black |
2TB WD Caviar Black |
2TB WD Caviar Green
PSU
Corsair HX850-80 Gold Modular
Case
Cooler Master Silencio 650
Cooling
Corsair H80i w/2 x Corsair SP120 | 2 x 120mm Noctua NF-S12B
Keyboard
Microsoft Sidewinder X4
Mouse
Gigabyte M6900 optical
Internet Speed
152mb
Antivirus
F-Secure
Browser
Firefox 38.0
Other Info
Backup Rig: Win 7 Pro 64-bit | AMD A10-5800k | ASUS F2A85-V Pro | 8GB Samsung DDR3 @1600MHz | 120GB Toshiba SDD | 2TB Seagate HDD | Cooler Master Silencio 550
Just a passworded Excel file, on it's own.... It's a start but, suppose you lost your data on a train would you be happy with that level of security? Really...?

If I lost my data on a train I'd be wondering why I had a 30lb+ mid tower rig with me on a train.

I once lost my laptop on a train, but there were some nice folks who helped me find it.
 

Attachments

  • 3XZRfFe.jpg
    3XZRfFe.jpg
    98 KB · Views: 0

My Computer My Computer

At a glance

Windows 7 Home Premium 32-Bit - Build 7600 SP1Intel Core i3-2120 3.30GhzKingston 4 GB DDR3 1333 mhzAMD Radeon HD6670
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom Build
OS
Windows 7 Home Premium 32-Bit - Build 7600 SP1
CPU
Intel Core i3-2120 3.30Ghz
Motherboard
Asus P8Z68-V LX Intel Z68 Socket H2 ATX
Memory
Kingston 4 GB DDR3 1333 mhz
Graphics Card(s)
AMD Radeon HD6670
Sound Card
Sound Blaster Audigy SE 24-Bit
Monitor(s) Displays
Asus VE228
Screen Resolution
1440 X 900
Hard Drives
OCZ Vertex 3 120 GB Sata 3 SSD ==
Kingston SH103/S3 120 G Hyper X 120 GB SSD ==
Western Digital 500 GB Caviar Green 7200 RPM ==
PSU
Corsair CX600M == 600 Watt
Case
NZXT Apollo - Silver with Clear Side Panel
Cooling
Three 120 mm Fans
Keyboard
Microsoft Natural 4000
Mouse
Microsoft Custom Optical 3000
Internet Speed
AT&T Fiber Optic Wireless Network
Antivirus
Microsoft Security Essentials
Browser
Chrome
Other Info
120 mm Blue LED Fan -- Three Blue LED Lazer Light Sticks
I use LastPass for every day type passwords like forums, email and the like. I feel that LastPass is safe enough for these.

Financial type are kept in my head and changed often.
 

My Computer My Computer

At a glance

1. Windows 7 Home Premium sp1 - 64bit 2. Wind...1. AMD Phenom II x2 511 3.4GHz 2. Intel i7-47...1. 5 GB - DDR3 2. 8GB DDR3-1600MHzIntegrated 1. ATI Radeon 4200 2. Intel HD Gra...
Computer type
PC/Desktop
Computer Manufacturer/Model Number
1. HP p6733w Desktop 2. HP Envy 700-515xt Desktop
OS
1. Windows 7 Home Premium sp1 - 64bit 2. Windows 7 Pro sp1 - 64bit
CPU
1. AMD Phenom II x2 511 3.4GHz 2. Intel i7-4790 Quad 4.0GHz
Motherboard
1. N-Alvorix-RS880-uATX 2. Kaili2
Memory
1. 5 GB - DDR3 2. 8GB DDR3-1600MHz
Graphics Card(s)
Integrated 1. ATI Radeon 4200 2. Intel HD Graphics 4600
Sound Card
1. Realtek High Definition Audio 2. Realtek (Neutered Beats)
Monitor(s) Displays
1. Acer V193L 2. HP 2311 Series Wide LCD
Screen Resolution
1. 1280 x 1024 2. 1920 x 1080
Hard Drives
1. 750 GB - 7200 RPM SATA 2. 1TB 7200 RPM SATA
PSU
1. 250w 2. 300w
Cooling
Stock
Keyboard
Logitech USB keyboard
Mouse
Logitech USB optical mouse
Internet Speed
1.0 - 2.0 mbps
Antivirus
Eset Smart Security v9.0.349.0
Browser
Pale Moon
Back
Top