I finally changed my password! A first step towards organisational skil


Recommended Posts

Finally,I found the courage to change the usual password to my most important accounts

It needed to done because I have reused the same password on so many different sites over the last 10+ years

I just had to take the plunge after putting it off for so long, a small step in the right direction towards account security. I'm starting to get things under control with LastPass, so hopefully I can get everything secure with strong passwords in the next 10 years. The problem is working out which accounts I have everywhere (I think I have found most accounts and put them into LastPass).

This is part of my efforts to get organised in general (Starting with Passwords). Hopefully I can post another achievement when I have all my paperwork actually in a particular order (Any ideas on how this should be organised in a filing cabinet?) and another when I have all my computer files organised in the same place in a coherent folder structure (Any ideas on this one too? At the moment it is spread across Dropbox & External HDD. I do backup my External HDD so I have already conquered this step) and emails (again, I have no idea how I will structure this, help?).

It is pretty hard to do when you have never been organised before in your whole life and suddenly you have all sorts of papers built up in no order at all when you realise that you need to do something about it. Basically it is like starting from scratch with 10 tons of paperwork, emails, passwords, computer documents waiting to be filed.

I'm in the middle of a similar project - get rid of unused website accounts, clean up and lock down others (Facebook for one). What prompted me to do it? Certain individuals I thought I could trust speculating too much about my private life (which I only found out about by reading IRC log files).

After two separate services got hacked and my passwords leaked, I bit the bullet and spent about half a day going through all of the websites I had accounts for, updating the passwords to a unique 20-digit random password. Everything is stored in 1Password and backed up to multiple places. I'm really liking the workflow!

Kinda hard to say how to file paper documents without knowing what they are. But, separate them into categories i.e.

Bank documents

Vehicle Documents

Mortgage/Property Lease documents

Utility Services Documents

and so on. Then, it would probably be best to file them(in a separate file per category) in date order, with the oldest ones at the back of the file (as you probably won't need access to these to often).

Although you may want the oldest ones at the front of the file, it's really your choice. I work in document management and have seen every kind of filing imaginable, some good, some not so good, which is why they send them to us to scan to CD.

I've locked things down with 2-factor authentication on Lastpass & Google Account. Used every possible security setting on Facebook (including App passwords) and removing unwanted apps. My new password is not very different to my old one but it is not an obvious change, this will let me get used to having a different password and then I will make a really good one as xkcd suggests when I am used to not having the same password.

Keep the tips coming for Document Management, I have to tackle this soon or the tax man will be after me.

I would love to do something similar but seeing so many big corporates being hacked and authentication credentials leaked I'm very sceptical about using any sort of password manager or anything similar.

What would be the recommendation for such a product?

I would love to do something similar but seeing so many big corporates being hacked and authentication credentials leaked I'm very sceptical about using any sort of password manager or anything similar.

What would be the recommendation for such a product?

I weighed KeePass vs. LastPass and I would say that KeePass is more secure because it is completely offline, but a pain to sync and backup everytime you add/change a password. LastPass is hosted online (so don't use if you don't trust "The Cloud") but it has the convenience factor which makes it actually practical to use. They also promise it is secure blah blah blah but for me it is the difference between having everything unmanaged with weak/reused passwords (definitely insecure) or trusting LastPass (more secure than Option A). I don't think that I could handle Keepass because I would not be able to access it remotely without some very complex setup, making it practically useless as I need to access my stuff remotely all the time.

I've been using lastpass for a long time, no problems at all, and imo more secure being online due to theft or loss of a machine / laptop, if your passwords are all stored offline your in trouble, with lastpass you change your master password and all machines now have no access to any passwords until the new master password is entered

Also

11.PNG

and

22.PNG

And there are a couple other authentication settings you can enable such as Grid Authentication etc

I had a reality check a few years ago, when I realised I was using the same password for all my stuff. It was amazing how many times I used the same one and where I used it.

I immediately started using Keepass, and I've never looked back. I sync the database using Dropbox, which I have installed on all my devices. Anytime I reformat my pc or have to reset the phone I only have to remember to note down the keepass password and I'm good to go.

One thing that drew me towards it was it is free, except fro some strange reason using it via the iPad, go figure.

Ive read about the two products some time ago and had some doubts about it...

Keepass seems more Windows oriented product...they dont offer support (or dont take responsability if you like) for contributed projects, like android/iphone...if they did that I would just point the database to a dropbox instalation folder and be done with it.

Lastpass being more cloud oriented has advantages being "always online" and can use Google authenticator but no support for applications passwords yet...

I dont know, I think I will use LastPass for some of my less important sites and see how it goes..

I had a reality check a few years ago, when I realised I was using the same password for all my stuff. It was amazing how many times I used the same one and where I used it.

I immediately started using Keepass, and I've never looked back. I sync the database using Dropbox, which I have installed on all my devices. Anytime I reformat my pc or have to reset the phone I only have to remember to note down the keepass password and I'm good to go.

One thing that drew me towards it was it is free, except fro some strange reason using it via the iPad, go figure.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

Ive read about the two products some time ago and had some doubts about it...

Keepass seems more Windows oriented product...they dont offer support (or dont take responsability if you like) for contributed projects, like android/iphone...if they did that I would just point the database to a dropbox instalation folder and be done with it.

Lastpass being more cloud oriented has advantages being "always online" and can use Google authenticator but no support for applications passwords yet...

I dont know, I think I will use LastPass for some of my less important sites and see how it goes..

Yea the best practise is to use things like this for places / passwords that would be a pain to lose but not threaten anything like banking etc

Keep those important passwords in your head only imo

no support for applications passwords yet

Applications don't access LastPass directly (only the actual LastPass Chrome/Firefox extension etc.) so not really needed. For instance, your Facebook login doesn't authenticate to LastPass directly, Lastpass just saves the password for Facebook and pre-fills the password form with the Facebook password, so Facebook has no access to your LastPass account whatsoever.

It also includes a tool to automatically generate secure passwords (as well as being able to manually choose or use the existing password), so you can make a different secure password for each website/application.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

I think you can password protect the keepass file and if you are paranoid you could true-crypt the file as well.

Doesn't that mean that all your passwords are now only as strong as your dropbox password, essentially meaning you still only have 1 password for everything ?

I can see what your saying, my Dropbox password was created by the password generator built into keepass it's self, I don't even know what it is So I have to make sure that, is the only password I have to make sure is stored securely else where, and I have access to it at anytime, trust me I've got stuck without access to it a few time when I'm on the move. It's a bit of a vicious circle really. My memory isn't that great so it's the best I can come up with. It's not ideal and some would say its got some flaws but it works. Rather than have one password used everywhere.

I can see what your saying, my Dropbox password was created by the password generator built into keepass it's self, I don't even know what it is So I have to make sure that, is the only password I have to make sure is stored securely else where, and I have access to it at anytime, trust me I've got stuck without access to it a few time when I'm on the move. It's a bit of a vicious circle really. My memory isn't that great so it's the best I can come up with. It's not ideal and some would say its got some flaws but it works. Rather than have one password used everywhere.

My memory is not so good either, but I can remember my lastpass password, so if I get caught out forgetting a site password I can always install lastpass somewhere and use that, and with it being a dedicated password protection / storage / encryption server I would rather rely on that than dropbox :)

I'm using LastPass and put there some credentials now...its a shame that the applications part is a premium feature and a part of another program...even if no autologin is provided I would like to use a more "clean" way of saving those than just making a generic note on the site...lets see how it goes.

I'm using LastPass and put there some credentials now...its a shame that the applications part is a premium feature and a part of another program...even if no autologin is provided I would like to use a more "clean" way of saving those than just making a generic note on the site...lets see how it goes.

Which browser are you using? Integrates with Chrome just fine for free

Which browser are you using? Integrates with Chrome just fine for free

Im using Firefox and it works perfectly.

Im talking about this feature: http://helpdesk.lastpass.com/upgrading-to-premium/lastpass-for-applications/

Even if no autologin was provided I would like to be able to save application passwords in a "cleaner" way than just generic notes, that an PIN's

I recently generated new passwords for all my accounts using lastpass. It's slightly unnerving having no idea what your password is for sites, and I haven't read too much into last pass's security methods but I'm glad I did it

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • I don't use Edge, I don't even use Windows these days as my main driver. Mac these days I use and Zen browser
    • Apple releases iOS 26.5.2 with dozens of security fixes for iPhone by Karthik Mudaliar Apple has released iOS 26.5.2 and iPadOS 26.5.2, which are security-only updates for the iPhone and the iPad. The update brings a bunch of security fixes for WebKit, WebRTC, WebKit Storage, WebKit Canvas, Web Extensions, libxslt, IOGPUFamily, and even the kernel. Some of the WebKit issues that were fixed could have allowed malicious web content to disclose sensitive user information, exfiltrate cross-origin data, crash Safari, or process restricted web content outside the browser sandbox. One notable WebKit Storage bug could let a malicious website to silently hijack clipboard data, according to Apple’s description. Other WebKit-related flaws involved memory corruption, use-after-free bugs, type confusion, out-of-bounds writes, permissions problems, and cross-origin data handling issues. The update also includes three kernel-related fixes. Apple says one of the flaws could let an app write kernel memory or cause unexpected system termination, while another may leak sensitive kernel state, and a third could corrupt kernel memory or terminate the system unexpectedly. Although Apple hasn't described them as remote web attacks, kernel bugs are still important to fix, as they can sometimes be chained with other flaws to escape app or browser restrictions. The updates are available for iPhone 11 and later, iPad Pro 12.9-inch 3rd generation and later, iPad Pro 11-inch 1st generation and later, iPad Air 3rd generation and later, iPad 8th generation and later, and iPad mini 5th generation and later. Similar security fixes also came with the latest update to macOS Tahoe 26.5.2, which Apple released on the same day. That overlap is not surprising, since Safari, WebKit, WebRTC, and other underlying components are shared across Apple’s platforms. Users are advised to update their devices sooner rather than later as these security fixes are crucial. iOS 26.5.2 can be installed from Settings > General > Software Update. Similarly, Mac users can find macOS Tahoe 26.5.2 through System Settings > General > Software Update.
    • Taken them long enough, that is one good thing. I still refuse to have a Whatsapp account, because it still need a phone number to have an account. don't want to give Meta my phone number
    • Good think I still have SDRAM and FP RAM sitting around.
    • Fitbit Charge 6 fitness tracker with Google apps is now at its lowest price with 47% off by Fiza Ali Amazon is currently offering the Fitbit Charge 6 fitness tracker at its all-time low price with a 47% discount. The device features an AMOLED touchscreen display protected by Corning Gorilla Glass 3 that should offer improved scratch resistance and durability. The Charge 6 is equipped with a range of sensors including an optical heart rate sensor, a 3-axis accelerometer, built-in GPS with GLONASS support, red and infrared sensors for SpO2 monitoring, a skin temperature sensor, an ambient light sensor, a vibration motor, NFC, and multipurpose electrical sensors compatible with the ECG and EDA Scan apps. Heart rate is recorded every second during exercise tracking and every five seconds during normal daily use. The device requires the Google Health app for setup and synchronisation. Furthermore, Bluetooth provides wireless connectivity for syncing and communication with devices running Apple iOS 16.4 or later and Android 11.0 or later. The tracker stores up to 7 days of minute-by-minute activity data and retains daily activity totals for the previous 30 days. In terms of water resistance, the Fitbit Charge 6 has a 5 ATM rating that should make it suitable for swimming and water activities. The tracker operates in temperatures ranging from 14°F to 113°F and at altitudes of up to 28,000 feet. Moreover, the included Infinity band is made from a flexible silicone material and features a loop-and-peg fastening. The small band fits wrists measuring 5.1 to 6.7 inches, while the large band fits wrists measuring 6.7 to 8.3 inches. Both small and large bands are included in the box. When it comes to battery performance, the Fitbit Charge 6 should deliver up to 7 days of battery life under typical usage conditions. Features such as the Always-On Display, built-in GPS, and SpO2 monitoring increase power consumption and may require more frequent charging. The rechargeable lithium-polymer battery should take approximately two hours to charge from empty to full. Fitbit Charge 6 Fitness Tracker with Google Apps: $85.45 (Amazon US) - 47% off Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
  • Recent Achievements

    • Reacting Well
      NovaEdgeX earned a badge
      Reacting Well
    • Week One Done
      NovaEdgeX earned a badge
      Week One Done
    • One Year In
      BA the Curmudgeon earned a badge
      One Year In
    • Conversation Starter
      rosiecharles earned a badge
      Conversation Starter
    • First Post
      KMilenkoski1202 earned a badge
      First Post
  • Tell a friend

    Love Neowin? Tell a friend!