Recommended Posts

Well, I got a call from my bank today. Someone charged $99 dollars on my charge card from iTunes. This is the first time this has happened to me. My bank and my iTunes accounts have been addressed, but now I feel I should go around and change all my passwords. How do you guys manage your passwords? Most of my passwords are exactly the same for all my sites, I know, I know, so now I feel I should go around a change all my passwords just in case. I would love to have a different password for every site, but there is no way I'll remember them. I'm also not a big fan of using password managers because I hate the fact that all of my passwords are sitting in one spot. LastPass looks like a good idea, but again a central point of failure for all your passwords. How do you guys manage your passwords?

Link to comment
https://www.neowin.net/forum/topic/1069232-how-do-you-manage-your-passwords/
Share on other sites

All in my head. Some of them are very complex but regardless I try to avoid saving them anywhere. I let Google Chrome save some passwords that I don't really worry about however. But passwords for things such as email, all in my head.

I remember the important passwords in my head (Facebook, email, bank, work/uni etc, Trade Me(basically NZ's Ebay) anything identity/money involved) and I make it a point to access them often so it is ingrained in my memory.

As for lower risk, I have the same segment of a password in every one of them and then a satirical play of the name. Or simply the name of the website even if I really don't care about that account/website.

I have a random little pattern for my passwords, something like:

[first two letters of site name] + [main password] + [length of site name as a number] + [punctuation mark depending on TLD]

They all mostly the same main password in the middle but with some extra strength around it, which means I likely won't ever forget them but still being different enough that even if someone steals one they probably won't work out the rest...

It's obviously not that pattern though :p

I use LastPass with Yubikey for two-factor authentication. All of my passwords are randomly generated and I don't use similar passwords for any sites.

Same here :)

As far as password length, I use anywhere from 14 (for non-essential sites), to 25 characters long (Most recently my root password for my VPS).

Another vote for KeePass/Dropbox + the mobile app. There is no way in hell I'm going to remember 700+ passwords. It's also good for storing other info to go along with those accounts/services/passwords.

I also use LastPass to store less important passwords (which is most of them), so that I can have faster access to them. (user/password fields get auto filled when logged in to LastPass)

Depends how often they will be used.

Ones i might use now and then usually end up on paper, not labelled in anyway, it is mainly there to jog my memory if i forget it.

Ones i use often then i just remember, i like to think i have a pretty decent system for my passwords, which usually make them easy to remember.

If it is a site, i don't want to register on but they force me to, then i just use a simple password, as i don't care if the account gets hacked.

lol no poll? :)

I use my memory to store all of my passwords from many accounts. All accounts on the net and off the net have different passwords. Everything that allow password to lock, I use passwords, including Windows login.

Windows login

Router/Network (different pass)

Yahoo Mail / MSN / Google (different pass)

Many other web accounts (all different pass)

The only thing I don't recall well enough is the site I register an account with. Once I establish the website location, the password came to me immediately. I got about 20-30 different accounts on the web. All with different passwords and they are not short.

I have a random little pattern for my passwords, something like:

[first two letters of site name] + [main password] + [length of site name as a number] + [punctuation mark depending on TLD]

They all mostly the same main password in the middle but with some extra strength around it, which means I likely won't ever forget them but still being different enough that even if someone steals one they probably won't work out the rest...

It's obviously not that pattern though :p

I like this idea. I remember listening to a Security Now episode where Gibson referred to something like this as Password Haystacks. I might go with this one.

I use LastPass with Yubikey for two-factor authentication. All of my passwords are randomly generated and I don't use similar passwords for any sites.

This looks really interesting. Can you explain a little more how it works? The video is very short.

I use Roboform Everywhere. I have it on on all my machines. I also went through all the sites I had passwords for and generated random passwords. For backup of my passwords in roboform I

1) print out a list of all my passwords all 231 of them and put the paper copy in my safety deposit box at the bank.

2) Burn a copy of the Roboform Data folder to a DVD and put that in the box as well.

3) Backed them up to carbonite

4) Sync them to Roboform online

5) A nightly backup to a drive inside my computer

6) 2 external 1tb hard drives. 1 I keep here and 1 I keep in my safety deposit box (they get rotated monthly)

That is technically my over all backup strategy, just happens the roboform password folder is included.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Google's new hand-wave reCAPTCHA can be bypassed with a stock photo by Ivan Jenic Image: Screenshot Google is testing a new reCAPTCHA method that asks you to wave at your camera to prove you're human. So, besides solving puzzles and reading distorted text, you can now use your computer’s camera to pass the verification test. When the hand gesture verification is triggered, your browser asks for camera access and prompts you to perform a simple gesture, like a wave or an open palm. Google says it records a short video of the movement and uses AI to extract 21 hand-knuckle coordinates to complete the verification process. The video is then immediately deleted, and Google swears it doesn't keep it. The process alone can be uncomfortable for people who wouldn’t want their biometric data, which hand scans technically qualify as, recorded. But it gets even more nuanced, as early testers discovered that the new hand-waving reCAPTCHA can be passed with a simple stock image. A user on X tested the new challenge using a stock image of a hand fed through OBS Virtual Camera, and it passed. I wanted to verify it, so I tried the same thing. It took me a few tries and a few stock images, but in the end, I was also able to pass the test. I simply had to readjust the stock image of a generic person waving inside OBS, and Google’s mechanism registered it as a legitimate hand gesture. Once again, it didn’t even have to be a video or an AI-generated hand animation. Given the simplicity of the process, the entire action can be automated in minutes. All it takes is a simple Python script to render the new reCAPTCHA method obsolete. And it doesn’t even have to be an AI bot, which is usually used for solving puzzles and other verification methods. The new reCAPTCHA method is still in its early phase, and Google will, hopefully, update its AI to at least reject still images. However, this incident, combined with users’ initial skepticism about Google’s practices regarding user data, likely won’t make too many people wave at the camera anytime soon.
    • 🤣🤣🤣🤣🤣 "to fund healthcare and tuition" 🤣🤣🤣🤣 Who do you think you are talking about, some COMMUNIST? We are better than them, doG bless Murica!!! p.s. I'm from a country where government does exactly that, i.e. not form US.
    • Apparently not. I know it is on Edge for business at the moment, but how long will it be before it become on the home version of Edge?
    • Microsoft details new Edge for Business security features, including AI-powered scareware detection So Edge is adding a "scarecrow." Will it be animated?
    • I have this one and it's great, also paired with a Mac. I like the white back aesthetics of it and ability to have all your wireless usb peripherals under a clean lid. 4K @ 120 Hz and 65W usb-c charging is not bad even at its typical price point. The U series is probably better for commercial photo work though; IIRC one reason this one is priced in a different bracket is because it's not calibrated and verified for optimal color accuracy. Not something I think of in daily use, coding, and light gaming though.
  • Recent Achievements

    • Apprentice
      Asgardi went up a rank
      Apprentice
    • One Month Later
      sunrisea2milk earned a badge
      One Month Later
    • Week One Done
      sunrisea2milk earned a badge
      Week One Done
    • Week One Done
      Snow Day Calculator Alert earned a badge
      Week One Done
    • Conversation Starter
      KMilenkoski1202 earned a badge
      Conversation Starter
  • Popular Contributors

    1. 1
      +primortal
      495
    2. 2
      +Edouard
      251
    3. 3
      PsYcHoKiLLa
      154
    4. 4
      Steven P.
      86
    5. 5
      macoman
      65
  • Tell a friend

    Love Neowin? Tell a friend!