• WANTED: Happy members who like to discuss audio and other topics related to our interest. Desire to learn and share knowledge of science required. There are many reviews of audio hardware and expert members to help answer your questions. Click here to have your audio equipment measured for free!

Warning: change your password please!

tomtoo

Major Contributor
Joined
Nov 20, 2019
Messages
3,720
Likes
4,814
Location
Germany
Ok, but what is the algorithm to keep corresponding PW and sites/logins together?

Here we have a few encrypted PW lists daily backed up on the home server (NAS) for the family members. All with the same PW which is an easy to remember modified fairytale fantasy name for all of them. So the brains of the members are a nice PW back-up for each other in case of emergency.

You could use lets say first x letters of site name as prefix or postfix.Or 1,2,5 letter. Not perfect. But much better than use the same everywhere.
 

DuncanDirkDick

Member
Forum Donor
Joined
Mar 8, 2021
Messages
54
Likes
40
I'd stick to the common attack vectors, not to personalized ones. And in 99% of the cases it's a compromised database with people using the same username/password combination everywhere.
 

somebodyelse

Major Contributor
Joined
Dec 5, 2018
Messages
3,754
Likes
3,053
It is open source, so more eyeballs are on the code looking for vulnerabilities. And, there is currently no hacked version of it available on the dark web, unlike KeePass.
They're both open source. Patching in some code for exfiltration and compiling doesn't need the dark web. If someone's got sufficient privs to replace the binary you're already compromised, and it probably doesn't matter which password manager you're using. I'd be interested in what BitWarden is doing differently to KeePass and its derivatives that makes it any more secure. Some of this may be OS specific.
 

beefkabob

Major Contributor
Forum Donor
Joined
Apr 18, 2019
Messages
1,658
Likes
2,114
So they have been hacked, twice, and you still stick with them? I'm am not sure I understand that thinking.
Who hasn't been hacked?
Since my passwords are encrypted with an obscenely long password, it doesn't really matter.
The convenience of cloud-based passwords means that I can use strong passwords. If I had to go to a file or use something not cloud-based, it'd be a pain in the ass, so I'd have less incentive to have good passwords.
 

Andreas007

Active Member
Joined
Mar 11, 2019
Messages
144
Likes
377
Location
Germany, Bavaria
I recently engaged a white hat security consultant to pen test our network at work. He hacked into our security manager's laptop, replaced his KeePass executable with a hacked version, and gained access to the admin passwords for nearly everything on our network. He left his report on the desktop of my laptop instead of emailing it to me. Needless to say, we no longer allow KeePass. He recommends BitWarden.
I don't get it why BitWarden should be better than KeePass in such a case. What does it help to change a program when your system got hacked?
If your system gets hacked no program can be trusted anymore and it's easy to eavesdrop on any data.

Switching form KeePass to BitWarden was useless if nothing else was done to secure your network instead.
 

sofrep811

Active Member
Joined
Jun 4, 2016
Messages
253
Likes
319
The main use these days is to link to a site which as a result, causes Google to rank them higher in search results. But they also try to sell stuff.
OK. That makes total sense. I knew a guy in the early days of Google and that was his gig--he'd get a person's business to show up on top with certain searches. This was 2003, I think? But it's more sophisticated now.
 

Mulder

Addicted to Fun and Learning
Forum Donor
Joined
Sep 2, 2020
Messages
640
Likes
887
Location
Gothenburg, Sweden
I recently engaged a white hat security consultant to pen test our network at work. He hacked into our security manager's laptop, replaced his KeePass executable with a hacked version, and gained access to the admin passwords for nearly everything on our network. He left his report on the desktop of my laptop instead of emailing it to me. Needless to say, we no longer allow KeePass. He recommends BitWarden.
You should of cource keep both KeePass and the key on a USB stick and only use it when needed.
 

Steve Dallas

Major Contributor
Joined
May 28, 2020
Messages
1,217
Likes
2,921
Location
A Whole Other Country
I don't get it why BitWarden should be better than KeePass in such a case. What does it help to change a program when your system got hacked?
If your system gets hacked no program can be trusted anymore and it's easy to eavesdrop on any data.

Switching form KeePass to BitWarden was useless if nothing else was done to secure your network instead.
Why would you assume we did nothing else to secure the network? We implemented about a dozen recommendations not germane to this thread.
 

sweetchaos

Major Contributor
The Curator
Joined
Nov 29, 2019
Messages
3,917
Likes
12,117
Location
BC, Canada
I recommend Bitwarden over most of the other password managers due to it being self host able
Cool, but not everyone is inclined to self-host their own password manager.

Bitwarden (cloud-hosted, not self-hosted) or 1password (already cloud-hosted) are an easy recommendation for anyone who's not technically inclined.

If I tell any of my non-technical friends to self-host their own password manager, they'll look at me like I'm from another planet.
 

Labjr

Major Contributor
Joined
Dec 14, 2018
Messages
1,069
Likes
985
Google reminds me to change my passwords all the time. You almost need a separate computer with it's own operating system designed to keep track of passwords.
 

Blumlein 88

Grand Contributor
Forum Donor
Joined
Feb 23, 2016
Messages
20,754
Likes
37,597
Google reminds me to change my passwords all the time. You almost need a separate computer with it's own operating system designed to keep track of passwords.
Yes, on my phone google will tell me one of my passwords has been found on the dark web during their security updates process. It does not show up on https://haveibeenpwned.com/ or similar sites. I don't reuse it and in fact have changed it. I never saw any evidence of anything wrong. Of course someone else may have used the same password which is not otherwise related to me.

In any case, I do hope passkeys catch on and become the norm. For many people passwords are reaching or have reached the point where it is far too much trouble to keep them safe and they aren't proving fully safe anyway. Passkeys will be overall more convenient and much safer in several ways than passwords.
 

Labjr

Major Contributor
Joined
Dec 14, 2018
Messages
1,069
Likes
985
Yes, on my phone google will tell me one of my passwords has been found on the dark web during their security updates process. It does not show up on https://haveibeenpwned.com/ or similar sites. I don't reuse it and in fact have changed it. I never saw any evidence of anything wrong. Of course someone else may have used the same password which is not otherwise related to me.

In any case, I do hope passkeys catch on and become the norm. For many people passwords are reaching or have reached the point where it is far too much trouble to keep them safe and they aren't proving fully safe anyway. Passkeys will be overall more convenient and much safer in several ways than passwords.
From what I've read Passkeys isn't going to work with Windows 10 which most people are still using. However, I'm already using it on Windwows 10 with Ebay and Best Buy. Perhaps it won't work cross-platform. I hope Google Passwords will store the Passkeys so I don't have to create new Passkeys for every device I use. It's not supposed to work with IOS 15 either. I hope they'll change these requirements so everyone doesn't need to upgrade equipment to have better password security.
 
Last edited:

Blumlein 88

Grand Contributor
Forum Donor
Joined
Feb 23, 2016
Messages
20,754
Likes
37,597
From what I've read Passkeys isn't going to work with Windows 10 which most people are still using. However, I'm already using it on Windwows 10 with Ebay and Best Buy. Perhaps it won't work cross-platform. I hope Google Passwords will store the Passkeys so I don't want to have to create new Passkeys for every device I use. It's not supposed to work with IOS 15 either. I hope they'll change these requirements so everyone doesn't need to upgrade equipment to have better password security.
Should work on Android, IOS, MacOS, and Windows 11. Also they have provisions to use them cross platform. Slightly less convenient, but equally secure. You can use MacOS or IOS on Windows 10, but not in the other direction though it is promised soon.
 

kchap

Addicted to Fun and Learning
Forum Donor
Joined
Jun 10, 2021
Messages
586
Likes
572
Location
Melbourne, Oz
Cool, but not everyone is inclined to self-host their own password manager.

Bitwarden (cloud-hosted, not self-hosted) or 1password (already cloud-hosted) are an easy recommendation for anyone who's not technically inclined.

If I tell any of my non-technical friends to self-host their own password manager, they'll look at me like I'm from another planet.
I can recommend Bitwarden. I do not not have any experience 1password so I cannot comment. Bitwarden is open source and they have been independently audited. It works well on Windows, Android and Linux. There is an iOS version, again I have no experience with it.

However you have to be prepared for the day some hackers download the entire cloud based database. The only thing that will save you then is long, unique but memorable pass phrase. I don't suggest using Luke, I am your father.
 

antcollinet

Master Contributor
Forum Donor
Joined
Sep 4, 2021
Messages
7,698
Likes
12,991
Location
UK/Cheshire
I love me some Lastpass. Just have a seriously long master password and you'll be fine no matter what. Using a different email address or login for most websites is pretty helpful too. I have a bajillion attempts to hack my business wordpress, and they're all the wrong logins attempted by scripts. I have gotten hacked before, but only because of flaws in wordpress itself, which no password program can stop.
Install wordfence (or similar) on your sites, and set it to block an IP after 5 login attempts. Kills brute force attacks. And turn off the account named admin.
 

JPA

Active Member
Forum Donor
Joined
Mar 21, 2021
Messages
157
Likes
266
Location
Burque
I suppose the problem then is that you have to ALWAYS be able to remember the encryption pass. Back to a piece of paper in a drawer again? :p
No, NTFS file system encryption doesn't require an additional password beyond your login password.
 
Top Bottom