I finally changed my password! A first step towards organisational skil


Recommended Posts

Finally,I found the courage to change the usual password to my most important accounts

It needed to done because I have reused the same password on so many different sites over the last 10+ years

I just had to take the plunge after putting it off for so long, a small step in the right direction towards account security. I'm starting to get things under control with LastPass, so hopefully I can get everything secure with strong passwords in the next 10 years. The problem is working out which accounts I have everywhere (I think I have found most accounts and put them into LastPass).

This is part of my efforts to get organised in general (Starting with Passwords). Hopefully I can post another achievement when I have all my paperwork actually in a particular order (Any ideas on how this should be organised in a filing cabinet?) and another when I have all my computer files organised in the same place in a coherent folder structure (Any ideas on this one too? At the moment it is spread across Dropbox & External HDD. I do backup my External HDD so I have already conquered this step) and emails (again, I have no idea how I will structure this, help?).

It is pretty hard to do when you have never been organised before in your whole life and suddenly you have all sorts of papers built up in no order at all when you realise that you need to do something about it. Basically it is like starting from scratch with 10 tons of paperwork, emails, passwords, computer documents waiting to be filed.

I'm in the middle of a similar project - get rid of unused website accounts, clean up and lock down others (Facebook for one). What prompted me to do it? Certain individuals I thought I could trust speculating too much about my private life (which I only found out about by reading IRC log files).

After two separate services got hacked and my passwords leaked, I bit the bullet and spent about half a day going through all of the websites I had accounts for, updating the passwords to a unique 20-digit random password. Everything is stored in 1Password and backed up to multiple places. I'm really liking the workflow!

Kinda hard to say how to file paper documents without knowing what they are. But, separate them into categories i.e.

Bank documents

Vehicle Documents

Mortgage/Property Lease documents

Utility Services Documents

and so on. Then, it would probably be best to file them(in a separate file per category) in date order, with the oldest ones at the back of the file (as you probably won't need access to these to often).

Although you may want the oldest ones at the front of the file, it's really your choice. I work in document management and have seen every kind of filing imaginable, some good, some not so good, which is why they send them to us to scan to CD.

I've locked things down with 2-factor authentication on Lastpass & Google Account. Used every possible security setting on Facebook (including App passwords) and removing unwanted apps. My new password is not very different to my old one but it is not an obvious change, this will let me get used to having a different password and then I will make a really good one as xkcd suggests when I am used to not having the same password.

Keep the tips coming for Document Management, I have to tackle this soon or the tax man will be after me.

I would love to do something similar but seeing so many big corporates being hacked and authentication credentials leaked I'm very sceptical about using any sort of password manager or anything similar.

What would be the recommendation for such a product?

I would love to do something similar but seeing so many big corporates being hacked and authentication credentials leaked I'm very sceptical about using any sort of password manager or anything similar.

What would be the recommendation for such a product?

I weighed KeePass vs. LastPass and I would say that KeePass is more secure because it is completely offline, but a pain to sync and backup everytime you add/change a password. LastPass is hosted online (so don't use if you don't trust "The Cloud") but it has the convenience factor which makes it actually practical to use. They also promise it is secure blah blah blah but for me it is the difference between having everything unmanaged with weak/reused passwords (definitely insecure) or trusting LastPass (more secure than Option A). I don't think that I could handle Keepass because I would not be able to access it remotely without some very complex setup, making it practically useless as I need to access my stuff remotely all the time.

I've been using lastpass for a long time, no problems at all, and imo more secure being online due to theft or loss of a machine / laptop, if your passwords are all stored offline your in trouble, with lastpass you change your master password and all machines now have no access to any passwords until the new master password is entered

Also

11.PNG

and

22.PNG

And there are a couple other authentication settings you can enable such as Grid Authentication etc

I had a reality check a few years ago, when I realised I was using the same password for all my stuff. It was amazing how many times I used the same one and where I used it.

I immediately started using Keepass, and I've never looked back. I sync the database using Dropbox, which I have installed on all my devices. Anytime I reformat my pc or have to reset the phone I only have to remember to note down the keepass password and I'm good to go.

One thing that drew me towards it was it is free, except fro some strange reason using it via the iPad, go figure.

Ive read about the two products some time ago and had some doubts about it...

Keepass seems more Windows oriented product...they dont offer support (or dont take responsability if you like) for contributed projects, like android/iphone...if they did that I would just point the database to a dropbox instalation folder and be done with it.

Lastpass being more cloud oriented has advantages being "always online" and can use Google authenticator but no support for applications passwords yet...

I dont know, I think I will use LastPass for some of my less important sites and see how it goes..

I had a reality check a few years ago, when I realised I was using the same password for all my stuff. It was amazing how many times I used the same one and where I used it.

I immediately started using Keepass, and I've never looked back. I sync the database using Dropbox, which I have installed on all my devices. Anytime I reformat my pc or have to reset the phone I only have to remember to note down the keepass password and I'm good to go.

One thing that drew me towards it was it is free, except fro some strange reason using it via the iPad, go figure.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

Ive read about the two products some time ago and had some doubts about it...

Keepass seems more Windows oriented product...they dont offer support (or dont take responsability if you like) for contributed projects, like android/iphone...if they did that I would just point the database to a dropbox instalation folder and be done with it.

Lastpass being more cloud oriented has advantages being "always online" and can use Google authenticator but no support for applications passwords yet...

I dont know, I think I will use LastPass for some of my less important sites and see how it goes..

Yea the best practise is to use things like this for places / passwords that would be a pain to lose but not threaten anything like banking etc

Keep those important passwords in your head only imo

no support for applications passwords yet

Applications don't access LastPass directly (only the actual LastPass Chrome/Firefox extension etc.) so not really needed. For instance, your Facebook login doesn't authenticate to LastPass directly, Lastpass just saves the password for Facebook and pre-fills the password form with the Facebook password, so Facebook has no access to your LastPass account whatsoever.

It also includes a tool to automatically generate secure passwords (as well as being able to manually choose or use the existing password), so you can make a different secure password for each website/application.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

I think you can password protect the keepass file and if you are paranoid you could true-crypt the file as well.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

I can see what your saying, my Dropbox password was created by the password generator built into keepass it's self, I don't even know what it is So I have to make sure that, is the only password I have to make sure is stored securely else where, and I have access to it at anytime, trust me I've got stuck without access to it a few time when I'm on the move. It's a bit of a vicious circle really. My memory isn't that great so it's the best I can come up with. It's not ideal and some would say its got some flaws but it works. Rather than have one password used everywhere.

I can see what your saying, my Dropbox password was created by the password generator built into keepass it's self, I don't even know what it is So I have to make sure that, is the only password I have to make sure is stored securely else where, and I have access to it at anytime, trust me I've got stuck without access to it a few time when I'm on the move. It's a bit of a vicious circle really. My memory isn't that great so it's the best I can come up with. It's not ideal and some would say its got some flaws but it works. Rather than have one password used everywhere.

My memory is not so good either, but I can remember my lastpass password, so if I get caught out forgetting a site password I can always install lastpass somewhere and use that, and with it being a dedicated password protection / storage / encryption server I would rather rely on that than dropbox :)

I'm using LastPass and put there some credentials now...its a shame that the applications part is a premium feature and a part of another program...even if no autologin is provided I would like to use a more "clean" way of saving those than just making a generic note on the site...lets see how it goes.

I'm using LastPass and put there some credentials now...its a shame that the applications part is a premium feature and a part of another program...even if no autologin is provided I would like to use a more "clean" way of saving those than just making a generic note on the site...lets see how it goes.

Which browser are you using? Integrates with Chrome just fine for free

Which browser are you using? Integrates with Chrome just fine for free

Im using Firefox and it works perfectly.

Im talking about this feature: http://helpdesk.lastpass.com/upgrading-to-premium/lastpass-for-applications/

Even if no autologin was provided I would like to be able to save application passwords in a "cleaner" way than just generic notes, that an PIN's

I recently generated new passwords for all my accounts using lastpass. It's slightly unnerving having no idea what your password is for sites, and I haven't read too much into last pass's security methods but I'm glad I did it

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • A different thing with Russia. When you say is it better, depends on things. It is better that we don't have the E.U making rules and laws that have nothing to do with them. Is the trading part better? No, that is really mucked up, but then we knew that was going to happen and we would have make agreements, like we do with other parts of the world. Freedom of movement is certainly better, but could be improved, we still need more control over our borders. do you live in the U.K?
    • So what am I quoting from them? I never listened to what Farage or his cronies said. I wanted the U.K to leave the E.u years before the referendum and it had nothing to do with Farage and his cronies. So what country do you live in? Did we work much better together? We were always at logger heads with the E.U because we disagreed with them so much. Maggie was always on at them. I would have thought the E.U was glad to get rid of us as we stopped the integration or made it a two tier. Now without us they can integrate more. I would not have voted out if it was just a trading block and we can still work together on somethings.
    • MPC-BE 1.9.0 by Razvan Serea Media Player Classic - BE is a free and open source audio and video player for Windows. Media Player Classic - BE is based on the original "Media Player Classic" project (Gabest) and "Media Player Classic Home Cinema" project (Casimir666), contains additional features and bug fixes. The BE mod (Black Edition Mod) is a skinned version of Media Player Classic Home Cinema, much better looking than the plain old MPC. MPC-BE 1.9.0 changelog: Splitters Fixed crashes in some situations. AudioSplitter Added support for the RF64 format. Fixed reading of channel layout for some WavPack files. Added support for ID3 tags for Wave64 files. Unknown Wave64 chunks are now ignored. AviSplitter Added support for 'y408' video. Improved support for 'HEVC' video. FLVSplitter Added support for VVC video. MP4Splitter Improved handling of corrupted files. MatroskaSplitter Expanded support for V_UNCOMPRESSED video codecs. Fixed support for frame rotation (ProjectionPoseRoll). Improved support for "V_MS/VFW/FOURCC / HEVC". MpcDvdVideoDecoder Fixed conversion to YUY2. Fixed display of menus for some DVD-Videos. RoQVideoDecoder Output in NV12 and YV12 formats is allowed. Full range is used. MPC Video Decoder RGB32 format will be output as a top-down bitmap by default. Added support for the "IID_MediaSideDataDOVIMetadataV2" interface. Removed support for the deprecated "IID_MediaSideDataDOVIMetadata" interface. Fixed retrieving the name of the video adapter when using NVDEC. Fixed crashes in some situations. MPC Video Converter Added support for AYUV video format. MpcAudioRenderer Improved input format validation. Optimized retrieval of supported formats for exclusive mode. Added the "Keep audio device active when paused" setting. Fixed crashes and freezes in various situations. Subtitles Added the ability to open the properties of an external subtitle renderer in the "Subtitles" settings panel. Fixed external subtitle connections for VSFilter. Fixed a crash when rendering PGS/SUP subtitles when using AVX2. YouTube Improved support for yt-dlp. The built-in YouTube parser is no longer used. Player The HTTP read strategy has been changed. If the playlist contains one entry, more key combinations can be used to control the player (jump through chapters, adjust volume). Improved support for reading ASX playlists. The translation of the MediaInfo report for Chinese, Korean and Japanese has been removed. Added blocking of 32-bit filter "PICVideo Lossless JPEG Decompressor" (pvljpg20.dll), because it crashes. Added blocking of the system filter "AVI Decompressor", which will eliminate the crash of VFW codecs. Fixed a rare crash when using the "/slave" key. Fixed a crash when getting a list of fonts for OSD. Added the ability to load an external audio file using hotkeys. Fixed opening a network path starting with \?\UNC. The "Determine duration when adding" playlist setting now works for YouTube video URLs. The "Online media services" settings panel has been redesigned. Added a "Merge files using FFmpeg" option to the file saving dialog. This option is activated when playing multiple streams obtained using yt-dlp. Added loading of local .dpl playlists ("DAUMPLAYLIST"). Fixed a hang when the user closes the player during the URL opening process. Various interface fixes. Installer Updated MPC Video Renderer 0.10.5. Updated MPC Script Source 0.2.17. Added MPC Image Source 0.3.6. Translations Updated Japanese translation (by tsubasanouta). Updated Chinese (Traditional) and Dutch translation (by beter). Updated Romanian translation (by Andrei Miloiu). Updated Hungarian translation (by mickey). Updated Turkish translation (by cmhrky). Updated German translation (by Klaus1189). Updated Chinese (Simplified) translation (by wushantao). Updated Italian translation (by mapi68). Updated Korean translation (by Hackjjang). Updated Chinese (Traditional) (by udfbe). Updated libraries dav1d 1.5.3-6-g04b69f9; ffmpeg n8.2-dev-1857-g4653e68aab; libpng git-v1.6.55-9-g7d52a8087; Little-CMS git-lcms2.18-26-gf739cda; MediaInfo git-v26.05-38-g702c9b7fd; ZenLib git-v0.4.41-91-g073f297; zlib 1.3.2. Download: MPC-BE 64-bit | Portable MPC-BE 64-bit | ~20.0 MB (Open Source) Download: MPC-BE 32-bit | Portable MPC-BE 32-bit Link: Media Player Classic - BE Home Page Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Apple reportedly looks to blacklisted Chinese memory chips as RAM prices climb by Karthik Mudaliar Image via Apple Apple is reportedly trying to get a clearance from the Trump administration to buy memory from ChangXin Memory Technologies (CXMT) to get some relief from soaring DRAM prices. As per a report by the Financial Times, Apple approached the Commerce Department more than a month ago and also spoke to other officials and allies in Washington. For starters, CXMT is a company that's already been placed on the Pentagon's list of Chinese military companies. The Chinese company is the country's top DRAM maker. For Apple, the timing is certainly awkward but not surprising. Tim Cook had recently warned that Apple would have to raise prices because AI companies are buying up large amounts of memory for data centers, and just like that, Apple raised MacBook and iPad prices. Micron also recently revealed that customers have committed billions of dollars to secure memory supply years in advance, which shows us how aggressive securing infrastructure has become. This gives suppliers such as Samsung, SK Hynix, and Micron more leverage, while pushing hardware makers to look for alternatives. CXMT is one of those alternatives, but not the simplest one. Apple has spent many years trying to diversify parts of its supply chain away from China, especially for final assembly, while still depending heavily on Chinese manufacturing and suppliers. Even domestic brands from China are moving towards CXMT and YMTC instead of relying on Samsung, Micron, and SK Hynix. For Apple, though, it would invite more scrutiny than local Chinese companies. For now, this is more like a lobbying effort rather than a confirmed supply deal. There's no official statement from either of the parties. What is clearer, though, is the pressure behind such a request. AI demand has certainly made hardware a bottleneck, and companies are trying everything they can to bring things back to normal, even if that means making politically sensitive choices. Source: Financial Times
    • I did test it a month or so back, but ... the results I expect to be on the first page are not there.
  • Recent Achievements

    • Week One Done
      flexorcist earned a badge
      Week One Done
    • One Month Later
      Woland13 earned a badge
      One Month Later
    • Week One Done
      Woland13 earned a badge
      Week One Done
    • One Year In
      bernmeister earned a badge
      One Year In
    • Week One Done
      Scoobystu earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      486
    2. 2
      +Edouard
      220
    3. 3
      PsYcHoKiLLa
      147
    4. 4
      Steven P.
      74
    5. 5
      FloatingFatMan
      70
  • Tell a friend

    Love Neowin? Tell a friend!