Help for save password securely

killer bee

New member
Power User
VIP
Local time
6:11 AM
Messages
406
Recently someone in USA hacked my gmail account, I normally use "Lastpass" for save password, but now i think its not secure. Is it OK if i put my passwords into text files (encrypted) and save it my PC. Because if i forget them i can't use my emails ad FB accounts.
Is it ok if i save passwords using web browser password manager? But i have Xmarks and Firefox sync.
Actually i have 6 email address (4 personal use and other 2 for my blog)

How do you save your password securely?
 

My Computer

Computer Manufacturer/Model Number
Intel DG31PR (Intel Dual core 2.5 E5200 @ 2.5GHz)
OS
windows7 Ultimate SP1 x32bit
CPU
Intel
Motherboard
Intel DG31PR
Memory
Kinsgton 1GB an Transcend 2GB
Graphics Card(s)
Intel- onboard
Sound Card
Intel- onboard
Monitor(s) Displays
ViewSonic LCD Widescreen 19
Screen Resolution
1400x900
Hard Drives
Samsung 256GB
PSU
Legend
Case
Legend
Cooling
Intel
Keyboard
Seemo
Mouse
Prolink
Internet Speed
Download Speed-512Kbps, Upload Speed-128Kbps (ADSL wired)
Other Info
UPS- Prolink Pro650s
Router Prolink H5201
Sub Woofer - Creative 2.1
Roboform Desktop Pro (there's also a free version).

keep your password somewhere else - not on your pc.
 

My Computer

Computer Manufacturer/Model Number
Toshiba Satellite L500
OS
Windows 7 Home Premium x64 OEM --> RTM clean install
CPU
Intel T4400
Motherboard
? - laptop inbuilt ?
Memory
4Gb
Graphics Card(s)
? - Mobile Intel(R) 4 Series Express Chipset Family ?
Sound Card
Realtek
Monitor(s) Displays
? + extended to a 42" LG55PC plasma tele!
Screen Resolution
1366 * 768
Hard Drives
320Gb 5500rpm
PSU
?
Case
?
Cooling
?
Internet Speed
3Meg, when it works.
Other Info
A LOWLY LAPTOP!
Hi, killer bee. I use a piece of software called KeePass to store some of my important passwords that are hard to remember. I have found it very useful, and I highly suggest it.

KeePass Password Safe
 

My Computer

Computer Manufacturer/Model Number
Lenovo ThinkPad W520 (4270CT)
OS
Windows 7 Professional x64
CPU
Intel Core i7-2720QM
Memory
4GB (2 x 2GB)
Graphics Card(s)
NVIDIA Quadro 2000M (with Optimus)
Hard Drives
500 GB @ 7200 RPM
I agree with BriceH, KeePass is great and it even offers to generate passwords for you. I have used it for years and and it highly customizable and easy to use. One nice feature is that you can set a password to access your KeePass passwords but you can also have KeePass require a key file in conjunction with your password. This mean you could save your password on one source and then save your "key file" on say a usb thumb drive or even just on your desktop.
 
Last edited:

My Computer

Computer Manufacturer/Model Number
Sager NP2096
OS
7 Ultimate 64 bit Service Pack 1
CPU
Intel Core 2 Duo P9500 @ 2.53GHz (lower wattage chip)
Motherboard
JHL 90 (U2E1)
Memory
4.0GB Dual-Channel DDR 2 @ 398MHz (5-5-5-18)
Graphics Card(s)
512MB GeForce 9600M GT
Sound Card
Realtek High Definition Audio
Monitor(s) Displays
Generic PnP Monitor
Screen Resolution
1680x1050
Hard Drives
Hitachi 244GB @ 7200rpm (IDE)
Cooling
nature
Keyboard
generic
Mouse
Microsoft Wireless Mobile Mouse 3500
Internet Speed
30 megabits down, 5 megabits up
Other Info
1.)Staples 4-Port USB 2.0 Mobile Hub
2.)WNDR3700 - NETGEAR RangeMax Dual Band Wireless-N Gigabit Router
3.)Logitech Webcam C250
4.)Logitech M570
The problem is not Lastpass never was. No point in moving an insecure password to another system it is still an insecure password. What you should be doing is change all your passwords by using the "Generate Password" Lastpass provides, make it long and complicated. But it doesn't matter what you use an insecure password is still insecure.

Just for the record, Lastpass is secure. As long as the passwords it stores are secure and the master password is secure. The same applies to every password manager.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
I think "Roboform", "KeePass Password Safe" and "last pass" also use same thing. They sync passwords with the server? Am i right?
 

My Computer

Computer Manufacturer/Model Number
Intel DG31PR (Intel Dual core 2.5 E5200 @ 2.5GHz)
OS
windows7 Ultimate SP1 x32bit
CPU
Intel
Motherboard
Intel DG31PR
Memory
Kinsgton 1GB an Transcend 2GB
Graphics Card(s)
Intel- onboard
Sound Card
Intel- onboard
Monitor(s) Displays
ViewSonic LCD Widescreen 19
Screen Resolution
1400x900
Hard Drives
Samsung 256GB
PSU
Legend
Case
Legend
Cooling
Intel
Keyboard
Seemo
Mouse
Prolink
Internet Speed
Download Speed-512Kbps, Upload Speed-128Kbps (ADSL wired)
Other Info
UPS- Prolink Pro650s
Router Prolink H5201
Sub Woofer - Creative 2.1
I think "Roboform", "KeePass Password Safe" and "last pass" also use same thing. They sync passwords with the server? Am i right?

Wouldn't matter, the software is not the problem.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2

My Computer

Computer Manufacturer/Model Number
Intel DG31PR (Intel Dual core 2.5 E5200 @ 2.5GHz)
OS
windows7 Ultimate SP1 x32bit
CPU
Intel
Motherboard
Intel DG31PR
Memory
Kinsgton 1GB an Transcend 2GB
Graphics Card(s)
Intel- onboard
Sound Card
Intel- onboard
Monitor(s) Displays
ViewSonic LCD Widescreen 19
Screen Resolution
1400x900
Hard Drives
Samsung 256GB
PSU
Legend
Case
Legend
Cooling
Intel
Keyboard
Seemo
Mouse
Prolink
Internet Speed
Download Speed-512Kbps, Upload Speed-128Kbps (ADSL wired)
Other Info
UPS- Prolink Pro650s
Router Prolink H5201
Sub Woofer - Creative 2.1
keepass stores its files locally, using an encryted database .db file.

if you use multiple computers (including smartphones), you can do special tricks with syncing software such as sugarsync (or dropbox), but that kind of defeats the benefits of keeping it local.
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
keepass stores its files locally, using an encryted database .db file.

if you use multiple computers (including smartphones), you can do special tricks with syncing software such as sugarsync (or dropbox), but that kind of defeats the benefits of keeping it local.

Don't these services like sugarsync and dropbox store your files encrypted too? So there is basically no chance that the KeePass .kb file could be related to your system?
 

My Computer

OS
Windows 7 Professional x64 (SP1)
Screen Resolution
7680x1600
If not then what is the problem.

Well not to be rude, but you are. PICNIC, problem in chair not in computer. As long as your passwords are insecure (apple) then they can be bruteforced or if you fall for a phishing attack. It doesn't matter what software you use they cannot protect from PICNIC issues.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
keepass stores its files locally, using an encryted database .db file.

if you use multiple computers (including smartphones), you can do special tricks with syncing software such as sugarsync (or dropbox), but that kind of defeats the benefits of keeping it local.

Don't these services like sugarsync and dropbox store your files encrypted too? So there is basically no chance that the KeePass .kb file could be related to your system?

i'm not sure if synced data are encrypted before or after being sent from your pc to their servers.

maybe i didn't make myself clear - i was just pointing out that if you keep your files local, then you're not exposed to security vulnerabilities BUT if you have multiple machines and want access to your keepass database from them all, then there's a slight exposure risk.

it's something i've been thinking a lot about lately, and it seems there is no perfect solution. if your data is out there in the cloud, then there's possible dangers that somebody else can get at it.

saying that, i don't have any vitally important top-secret data, but i still wouldn't want people logging into all my stuff.
 

My Computer

Computer Manufacturer/Model Number
mickey megabyte 1234
OS
ultimate 64 sp1
CPU
i5 2500K [email protected]
Motherboard
MSI P67A-GD53
Memory
8 gigs GSkill Ripjaws 1600
Graphics Card(s)
amd hd6950
Sound Card
creative x-fi gamer
Monitor(s) Displays
samsung 24"
Screen Resolution
1920x1080
Hard Drives
ocz vertex 2e 60 gig, samsung f3 1tb, buffalo 2tb ext
PSU
antec 550
Case
antec three hundred
Cooling
i'm a cooling fan
Keyboard
saitek eclipse ii
Mouse
logitech g3
Internet Speed
about 4 Mbps
Other Info
i love win7
it's something i've been thinking a lot about lately, and it seems there is no perfect solution. if your data is out there in the cloud, then there's possible dangers that somebody else can get at it.

As long as it is encrypted and you use a secret private key that never is shared then you don't have much to worry about. For example, Lastpass only ever stores the encrypted data on their servers. Your computer does the encryption and decryption locally only. Your master password never leaves your computer, Lastpass does not even have it stored in their database.

Now if you find a way to decrypt secured-keyed AES without the key the NSA would like to talk to you.

But again if your passwords are insecure it won't matter.
I suppose you could look here: https://www.grc.com/haystack.htm
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Alienware Aurora ALX R4
OS
Windows 10 Pro (x64)
CPU
Intel Core i7-3930K (3.2GHz - 4.5GHz)
Motherboard
Alienware Aurora-R4 x79
Memory
4x Samsung 4GB PC3-12800 DDR3 (16GB 1600MHz)
Graphics Card(s)
Nvidia Geforce GTX 690
Sound Card
SteelSeries Siberia Elite
Monitor(s) Displays
Dell UltraSharp U3011
Screen Resolution
2560x1600
Hard Drives
Samsung 850 Pro 256 GB, Seagate 1TB Desktop Hybrid HDD, 2x Western Digital 4TB Green HDD
PSU
875W Some Dell PSU <.<
Case
Alienware Aurora ALX
Cooling
Custom Liquid Cooling (EK CPU & GPU blocks) dual EK 480RAD
Keyboard
Logitech G710+ Mechanical
Mouse
Logitech G700s
Internet Speed
Verizon Fios (50 mbps average)
Other Info
Server: Intel NUC D54250WYK: i5-4250U, 16GB, 256 GB mSATA, Windows Server 2012 R2
Back
Top