• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Changing Passwords Is Bad For Security

still don't get why passwords are still a thing...

society has had the ability to achieve multifactor authentication for decades, and yet here we are, at 2016/08/11 16:30 EDT, stuck with most things relying simply on passwords. can't sites/companies just invest in transitioning people to use soft-tokens (RSA software based tokens, for example) coupled with biometrics (voice/facial/finger print reco)

soft-tokens cover "something you have"
biometrics cover "something you are"
Yeah like your finger and your badge, imagine that.
I mean it might be a problem if they ask you to change for another finger after 10.. but when we get there, when we get there.
 
I mean it might be a problem if they ask you to change for another finger after 10.. but when we get there, when we get there.
uh, what? when it comes to biometrics you're not really meant to constantly have to update it on a regular basis.
 
I did this for internal websites. For everything else, I literally synced my PW to whatever it was on Windows. If I have to change windows, I change the PW on every single app to that password. For servers, however, I just save the passwords in the term program.

Now I do have some places where passwords aren't strong, but those are always sites that I don't care about. I've got junk email accounts that I couldn't care less if someone hijacks. I use them to sign up for sites I don't care about and don't want them to ahve any of my real accounts.

I definitely think a PW manager is much better. If you've got a strong password, nobodies going to break it other than the feds and if they want it, then they're going to get it one way or another.

Yep - I oversee IT, but am not an IT professional by any means. I have more knowledge than 99% of people, but not like a lot of you guys. I work in financial services and there is a major fear of the weakest link... I feel like I should say "you'd be surprised at how ignorant people are from management to the frontline", but you all know that. My CEO had a website misdirection from typing a bad URL the other day and it "took over her computer". Suddenly I have pressure to invest in "24/7 vulnerability penetration testing" because one of our board members who is an IT professional mentioned it in passing once...

And for shit websites I don't care about I use a junk email with the same password. I welcome them to hack that account and find the 50 per day emails offering me the BEST DEAL EVER ;)
 
So retardedly true.... how do they limit you to something so incredibly stupid is beyond me.... 8 to 12? even 8 to 20 is pushing it.

I should probably use password managers but..... meh. I remember the ones i use, right now at least...

If you remember all of your passwords, that indicates you're probably reusing them. If not, awesome, your memory is way better than mine. If you are, though, think of every site where one of those passwords has been reused. If a site is compromised how many other sites share either username or email address with that site and have the same password? That's why password managers are suggested, because it doesn't matter if you rotate 5-10 long/complex passwords if one of the sites you used it on is storing it in plaintext or in a similarly insecure manner.
 
If you remember all of your passwords, that indicates you're probably reusing them. If not, awesome, your memory is way better than mine. If you are, though, think of every site where one of those passwords has been reused. If a site is compromised how many other sites share either username or email address with that site and have the same password? That's why password managers are suggested, because it doesn't matter if you rotate 5-10 long/complex passwords if one of the sites you used it on is storing it in plaintext or in a similarly insecure manner.
Oh, I am definitely reusing passwords. it's virtually impossible not to with all teh sites that want username/passwords. But there are ranks of which I bother with.
 
Oh, I am definitely reusing passwords. it's virtually impossible not to with all teh sites that want username/passwords. But there are ranks of which I bother with.

Please look into using a password database/manager. There are many different kinds depending on what you are comfortable trusting. Completely open source and offline, even. Browser plugin based ones, too. All encrypted. At minimum, I try to keep all of my passwords alpha numeric with special characters and at least 30 characters long. Recycling passwords is guaranteeing compromised accounts. If a site gets hacked, that leaked password that never got used anywhere else should be the only one that anyone could possibly know.

Even if you aren't recycling passwords exactly, if you're remembering them because you stick to a pattern or theme... that's also opening yourself up to having additional accounts compromised. All of them really should be as unique as possible.
 
I keep forgetting passwords cause i have to always change and remember all
At this point passwords are just meaningless. I can't keep track of what password I used where anytime. So most of the time I just end up using the reset password feature when I want to log in somewhere. This is especially true where I don't need to login more than once or twice a month. Or even less.
 
Please look into using a password database/manager. There are many different kinds depending on what you are comfortable trusting. Completely open source and offline, even. Browser plugin based ones, too. All encrypted. At minimum, I try to keep all of my passwords alpha numeric with special characters and at least 30 characters long. Recycling passwords is guaranteeing compromised accounts. If a site gets hacked, that leaked password that never got used anywhere else should be the only one that anyone could possibly know.

Even if you aren't recycling passwords exactly, if you're remembering them because you stick to a pattern or theme... that's also opening yourself up to having additional accounts compromised. All of them really should be as unique as possible.
I don't trust password managers. To me that seems like writing down the passwords on a piece of paper. It presents a single point of attack. If someone gets access to my password list it's like serving it on a silver platter. Everything in one place username, password, and what it opens. And it's not like it's impossible to access. Since I access it all the time.
 
I don't trust password managers. To me that seems like writing down the passwords on a piece of paper. It presents a single point of attack. If someone gets access to my password list it's like serving it on a silver platter. Everything in one place username, password, and what it opens. And it's not like it's impossible to access. Since I access it all the time.

Two factor the manager with a Yubikey. Unless they know your master password AND have the Yubikey in their possession, nobody's getting into that DB.
 
I don't trust password managers. To me that seems like writing down the passwords on a piece of paper. It presents a single point of attack. If someone gets access to my password list it's like serving it on a silver platter. Everything in one place username, password, and what it opens. And it's not like it's impossible to access. Since I access it all the time.

Written down passwords are safer than storing them electronically, because paper cannot be remotely accessed.

Also, the password paper may only need to contain passwords, not what they are used for and what username it corresponds to. You just to learn to recognise the passwords from the list.

I haven't been investigating the use of password managers or even two factor authentications because they almost always tend to be tied to the device they are usually stored on, allowing a catastrophic failure of your device leading to loss of access.

Online password managers have all the problems of online databases: vulnerable to hackers.

Basically, I am looking for a password manager system whereby:

A) It would input the passwords for me automatically without too much hassle (a confirmation screen would be nice)

B) Allows the database to be written to more than 1 location simultaneously (EG a USB drive and local drive), so I have redundancy against hardware failures. This is by far what I require the most.

C) offline.

Not sure if keypass allows for B
 
Last edited:
Two factor the manager with a Yubikey. Unless they know your master password AND have the Yubikey in their possession, nobody's getting into that DB.
This seems like it requires the program or whatnot to implement it, so it seems like it's a bit limited.
 
Keepass can do what you're looking for, chenw. It has a wide variety options for auto-input depending on circumstance, can be used totally offline if you wish, and can sync the database to multiple locations. The latter may require you to set up a plugin or set up an automated job/script, but I'm pretty sure it can be done.

Oh and regarding the Yubikey (or any 2FA), with the proper plugin/setting, you don't need anything besides KeePass itself and the Yubikey to set it up (provided your Yubikey is set up to have HOTP/TOTP generation in one of its "slots".) I seem to remember there's a setting or plugin that will allow it to require HOTP/TOTP keys to access the database, if you wish, as another option.
 
I just started a new job on Monday and interestingly enough a lot of the authentication is done through biometrics. Our time clock is a hand scanner and our security access to keys and other things is based on a fingerprint scanner. Granted, there's still plenty of passwords for Windows login and internal websites, so that hasn't changed. This company isn't anything that has to do with IT so it is nice to see a technology shift with security / asset protection in mind.
 
You have to do what they always tell you not to do, write them down. Then you have to keep them locked in a safe. Now all you have to do is remember the safe combo, and keep your password list in the safe when you aren't using it. It sucks but any other way is just unworkable.
Even if you write your passwords down, you can alter them by adding, changing or removing a character or two and then nobody can use your list even if it gets compromised.
 
That's like the standard amount of days.

It's so pointless, even in high security areas people just sticky note the password somewhere on the their desk. Not everyone has the memory of an elephant.
 
It's so pointless, even in high security areas people just sticky note the password somewhere on the their desk. Not everyone has the memory of an elephant.
Do elephant has good memory? and I don't disagree with you. It's stupid, but there are arguments against it. And people have said that sticky notes are safer.
 
Please look into using a password database/manager. There are many different kinds depending on what you are comfortable trusting. Completely open source and offline, even. Browser plugin based ones, too. All encrypted. At minimum, I try to keep all of my passwords alpha numeric with special characters and at least 30 characters long. Recycling passwords is guaranteeing compromised accounts. If a site gets hacked, that leaked password that never got used anywhere else should be the only one that anyone could possibly know.

Even if you aren't recycling passwords exactly, if you're remembering them because you stick to a pattern or theme... that's also opening yourself up to having additional accounts compromised. All of them really should be as unique as possible.


Give something a thought first.

Which is a greater risk; That someone may gain access to a website and one of your passwords, and then fish around the web looking for other sites that you have used the same username and password for, and that actually has something critical on it.

or

That someone will exploit any one of a dozen or so weaknesses in your own software and take advantage of a weakness in your password manager gaining access to both user account and password info and the list of all your website accounts?

All your eggs in one basket comes to mind.
 
Last edited:
Back
Top