• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Password storing apps such as Keeper

Status
Not open for further replies.

OscarH

Established Member
Joined
15 Sep 2020
Messages
1,269
Location
Crawley
keep the second factor separate from your passwords!
This is something that annoys me with some password managers, they've started supporting 2FA. Defeats the point to keep them in the same place

(ones with WebAuthn support like 1password are slightly less pointless, as at least you should get the right-site protection, but it's still nowhere near as good as an actual second factor)
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Puffing Devil

Established Member
Joined
11 Apr 2013
Messages
3,167
I use LastPass; it's as good/safe/cheap as any commercial competitor. What's important is appropriate encryption to protect your data from the baddies. And MFA. Always MFA.

Change your Master Password frequently, don't re-use user names and never re-use a password.

Ideally, buy yourself a domain and give each service you use its own email, eg: RailUK Forums@Mydomain.co.uk
 

JamesT

Established Member
Joined
25 Feb 2015
Messages
4,836
I use LastPass; it's as good/safe/cheap as any commercial competitor. What's important is appropriate encryption to protect your data from the baddies. And MFA. Always MFA.

Change your Master Password frequently, don't re-use user names and never re-use a password.

Ideally, buy yourself a domain and give each service you use its own email, eg: RailUK Forums@Mydomain.co.uk
Some email services like gmail offer subaddressing, so as well as username@gmail.com, you can use username+tag@gmail.com. So in a similar fashion, assign a tag to every service and you'll know who's leaked your email address when you get a flood of spam to it.
 

Lucan

Established Member
Joined
21 Feb 2018
Messages
1,251
Location
Wales
Random mixtures of letters and numbers is a complete nightmare (maybe unless you can copy and paste it)
Copy and paste is what I do.

I have a text file with hundreds of sets of IDs, email addresses and passwords, a different set for every entity I deal with. For banks and sellers I must obviously use my real name, and for websites where it would not matter (like hobby forums) I use the same password. I am with an email provider (several in fact) that allows an unlimited number of email addresses and I now have hundreds of them. This file is encrypted with a master password and stored on two different devices, and I have different files for finance and non-finance. I open the file if I need to look up an ID and password and then I close it again, but I can remember the ones that use my common low security password. I see no need to pay someone else to host such a file.

If someone discovered my password for this forum for example and logged in pretending to be me, it would not be the end of the world; there is nothing much in here that links me to anything else beyond what is in the text of my comments, and I am quite careful with that. They could place me in a vague geographical area but even so Google (for example, by the ads they show me) thinks I live 200 miles from where I do, and that I want to buy an industrial air compressor. I don't, but I am not going to correct them.
 
Status
Not open for further replies.

Top