Minichan

Topic: Is my new password secure?

Anonymous A started this discussion 12 years ago #38,115

I decided to make a long, random password. Is it secure? Here it is: R!ZMBS#%EK2m8tw&ED*Uc728Gj2J9K%Hcj#V#RpgwDf_p

Anonymous B joined in and replied with this 12 years ago, 3 minutes later[^] [v] #510,399

Not to mention that this thread is retarded and a shitpost by MAtt as he posted two similar threads before: http://minichan.org/topic/37638 & http://minichan.org/topic/37915

This password is ridiculous, and if you were to actually use something like that I genuinely pity you. It scores about 0/10 on being easly memorable, which means it would have to be written down or stored somewhere. If you store it, for god's sake use a password manager and let that generate the password for you and never worry again.

Anonymous A (OP) replied with this 12 years ago, 1 minute later, 4 minutes after the original post[^] [v] #510,400

@previous (B)
But purely in terms of security, is it a good one?

Anonymous B replied with this 12 years ago, 2 minutes later, 6 minutes after the original post[^] [v] #510,401

@previous (A)
No, because of the reasons I stated. You will have written it down (this kills all the security), or are storing it in a password manager. If it's the latter, this question is retarded and so are you. Additionally, it's overly complex. Sure, a brute force would take forever, but in your case it's a lot more likely that you have security questions asking one what 1+1 is in french. Or, you know, have this shit written down on a post-it note.

But alas, I assume you are trolling. So basically, get fucked.

Anonymous A (OP) replied with this 12 years ago, 1 minute later, 8 minutes after the original post[^] [v] #510,402

@previous (B)
What is wrong with physically writing it down, and keeping it in a secure place in my home?

Anonymous A (OP) double-posted this 12 years ago, 17 seconds later, 9 minutes after the original post[^] [v] #510,403

@510,401 (B)
And no, I am not trolling.

Anonymous B replied with this 12 years ago, 8 minutes later, 17 minutes after the original post[^] [v] #510,404

@510,402 (A)
This makes the password useless outside of your home, and accessible to anyone who can gain access to your home. If you carry it with you, then that is even worse as you will have to take it out in public where others could oversee it or, you know, punch you in the face and take it.

Anonymous B double-posted this 12 years ago, 1 minute later, 19 minutes after the original post[^] [v] #510,405

@510,403 (A)
Then just use a password manager like KeePass or LastPass or something. Have a nice and secure master password that consists of a memorizable sentence (Think: https://xkcd.com/936/) and generate a new password for every service you use. The only exception might be financial services, which have their own "master password" that exists only within your head.

(Edited 19 seconds later.)

Anonymous A (OP) replied with this 12 years ago, 35 seconds later, 20 minutes after the original post[^] [v] #510,406

@previous (B)
Is that more secure than a ridiculously long and random password that I physically write down in my house?

Anonymous B replied with this 12 years ago, 1 minute later, 22 minutes after the original post[^] [v] #510,407

@previous (A)
Yes. You would still be using a master password that should only exist in your head. This password protects access to the password database. If someone has compromised your computer, they already have a keylogger so nothing much matters there. Additionally I am assuming you use this written down password for multiple services, which is a Bad Idea(tm).

It would also be infinitely more convient. If you truly want a physical security token invest in a smartcard and only use services that support it, YubiKey has been innovating in that area recently in cooperation with Google (Chrome).

fwiw, I still think you're trolling but I'm bored so whatever.

(Edited 37 seconds later.)

Anonymous A (OP) replied with this 12 years ago, 4 minutes later, 26 minutes after the original post[^] [v] #510,408

@previous (B)
Fuck, I am not trolling. Jesus.

Now, I downloaded KeePass. But, now my entire life is dependent on that particular software (1) working, and (2) not going out of business. How to get around that?

Anonymous B replied with this 12 years ago, 3 minutes later, 30 minutes after the original post[^] [v] #510,410

@previous (A)
KeePass is open source software that does not require a connection to the internet. There is no business model. You can download the source code and compile it yourself, but a saner action is to burn the installer to a cdrom. But you can bet your ass that the moment the keepass website goes down another one will spring up where people are rehosting the binaries.

You should of course back up your password database, this could also be burned to cdrom occasionally, kept on an usb stick, or simply by using some service such as google drive or dropbox. The latter are fine as the password database is encrypted with your master password.

edit: Additionally there are projects such as http://sourceforge.net/projects/kpcli/ which contain a slimmed down implementation of the KeePass database format. I would not recommend these for writing towards your database, but for reading from it (which is what you would want if the primary project stops working for whatever reason) will be fine. There are dozens of these readers, and the file format is relatively well documented.

edit2: And most services offer ways to reset your password. This may be a bit of a hassle, but saying your life depends on it is a bit melodramatic.

(Edited 4 minutes later.)

Anonymous A (OP) replied with this 12 years ago, 5 minutes later, 36 minutes after the original post[^] [v] #510,411

@previous (B)
Ok, thank you very much for the helpful information.

Metæ joined in and replied with this 12 years ago, 20 minutes later, 56 minutes after the original post[^] [v] #510,412

We've talked about keeping things in one thread before, haven't we? We're not going to have password shtick. Thanks.
:

Please familiarise yourself with the rules and markup syntax before posting.