Showing posts with label master password. Show all posts
Showing posts with label master password. Show all posts

Wednesday, March 9, 2016

How To Vault (part 2)

   A few posts ago I wrote an overview of why you may want to use a password vault.  This was in answer to reader question to provide more specifics about vaults.

   We've talked about passwords and password vaults a number of times in the past including here, here and here.

   If you haven't read part 1 of this discussion, it's here.

   Hopefully you are now convinced that you should be using a password vault, also called a password manager.  Now what...?

Products & Costs.
   A few years ago there were just a few key players in this field, but the list of products has grown and there are a number of good choices.  I'll briefly mention four of the best known and provide some links where you can get more info.
  • LastPass - the basic product is free.  It has most of the features you'd want, but the free version only supports use in a web browser.  If you want a mobile app and to support password fills in mobile apps then you need to get LastPass Premium, $1/month or $12/year.
  • DashLane - this is another very popular product.  It's free to download and use on any device.  However to have your passwords synced across devices, a very important feature, you need to use the Premium product which costs $40/year.
  • KeePass - this is well known and solid product.  It always has been free and is open source.  It was designed to support an exportable vault.  That means the primary way to use this tool is to keep it on a thumb drive and plug it in to the computer you use it on.  That can be either handy or inconvenient depending upon how many computers you have and how you do your work.  With KeePassX you can store the vault in free cloud storage like GoogleDrive, OneDrive, Dropbox, etc. and can connect with apps on mobile devices.
  • 1Password - many people like this product and consider it easy to use.  It's design is similar to KeePass in that it's basic use is on a single system and you can share your vault using free online cloud storage services.  It's free to download and there is a one-time license fee.  There is also mobile support and that requires a valid license.
   Here are a few review articles that go into more detail about the features of these, and some other, products.

Tuesday, June 23, 2015

Say It Ain't So LastPass!

   There are so many data breaches happening each week that it's easy to become numb to all the announcements.  Sometimes one or two dominate the news because of the size or importance of the breach.  Sometimes there is confusion in the media about the breach or the significance.  Sometimes the experts don't agree.

   I think most people have heard about the OPM - Federal (US) Office of Personnel Management - breach in which personal information on over 4 million people, including security clearance information, possibly dating back to 1985 was stolen in attack on federal computers.  Everyone agrees that this one was big and bad.  But also in the news was the breach of information at LastPass, and there is far less consensus on the impact.

   LastPass is a password vault - a program that lets you store all your passwords in an encrypted "safe".  I've talked about password vaults many times in the past.  I have always recommended the use of a password vault and I still do.

   First, let's discuss what happened.

Tuesday, January 6, 2015

The Secret Life of Passwords

   I've written about passwords plenty of times in the past.  Passwords are one of the main security touch-points for people, and it's often not a pleasant experience.

   As we've discussed, it's hard for people to pick good passwords and remember them.  So users need "tricks" to help the memory.  One way I've told people to construct a password is to base the password on an embarrassing moment in your life - that way you won't forget the password and you also won't tell it to anyone else.

   Apparently people have been using that, and similar, methods.  NY Times reporter Ian Urbana wrote a great piece on this called "The Secret Life of Passwords".  He asked people to tell him their passwords - yes, you shouldn't do that - but also the story behind the passwords.  There are some very interesting stories.  People seem to memorialize a part of their life in their passwords!  You can read the full story hereLeo Laporte did a great interview with Ian in the Triangulation podcast.  You can hear that here.

   I'd like to focus to two aspects of this story that jumped out at me.

   First is the story of Cantor Fitzgerald.  They are a large financial firm who were headquartered at the World Trade Center in 2001.  When the terrorist attacks hit the towers, Cantor Fitzgerald over two-thirds of their employees were killed.  That was tragic.

Tuesday, May 13, 2014

The Best (First Good) Password Policy Ever!



In the past I've discussed a number of aspects of the password dilemma.  Among the key issues are
  • good passwords are hard to remember, and;
  • passwords you can remember are easy for attackers to guess.
   But, maybe one of the key issues is that password policies are universally so bad that consumers can't do the right thing because they can't figure out what that is!  We've been living with that old dogma of.... say it with me...
  • 8 characters;
  • upper/lower case;
  • numbers;
  • special characters.
   That's been around since the 60's.  Perhaps it worked in a world when people had only one password, when systems weren't all networked together, and attacking systems wasn't the lucrative business it is now.

Tuesday, August 13, 2013

More Problems with Passwords???

   While I like to write about a variety of security-related topics, it seems that issues with passwords
keep coming up again and again.

   Passwords, and in particular their use for online authentication, is a mess.  I've written about this a number of times including here, here and here.  My advice for online use of passwords has been the same all along.  I've always said:
  1. choose good long passwords (long sentences are just fine)
  2. use a password vault, and
  3. use a unique password at each online site.
  4. (bonus) use 2-factor authentication for online sites when available (and complain if it isn't available yet!) 
   But... I had missed something!  There is another key thing that everyone needs to do to protect their online passwords... Don't Store Passwords in Your Browser!