security_presentation
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| security_presentation [2021.12.03 07:56] – [Remembering Passwords and Associated Issues] Steve Isenberg | security_presentation [2025.08.01 12:58] (current) – Steve Isenberg | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| - | ~~NOCACHE~~ <fc # | + | ~~NOCACHE~~ <fc # |
| + | visits {{counter|today| time| times}} today, {{counter|yesterday| time| times}} yesterday, and {{counter|total| time total| total times}}]</ | ||
| We all have bank accounts, credit cards, insurance policies, | We all have bank accounts, credit cards, insurance policies, | ||
| Line 32: | Line 33: | ||
| * (Can you think of others?) | * (Can you think of others?) | ||
| - | How long to crack: From [[https:// | + | Recent from WikiHow: [[https:// |
| + | Gives a set of steps to follow to guess someone' | ||
| + | - Figure out the password requirements for the site or app | ||
| + | - Ask for a hint or security questions (the ” | ||
| + | - Check the list of easy-to-remember passwords | ||
| + | - like: 123456, 123456789, Qwerty, Password, Pa$$w0rd, Qwerty123, Iloveyou, etc | ||
| + | - Phone screen passwords may be easy to guess (123456, 147258, etc) | ||
| + | - Names of family members and pets | ||
| + | - What you know about the target' | ||
| + | - Significant numbers and dates | ||
| + | - like: address, birth/ | ||
| + | - Reverse or change the letters | ||
| + | - Adlihnurb, tsorfmada | ||
| + | - Substituting $ for s, 0 for o, 3 for e, 1 for i, etc (P@$$w0rd, w1k1h0w) | ||
| + | - If you have access to their machine, check for saved passwords in Browsers | ||
| + | |||
| + | How long to crack: From [[https:// | ||
| ^Length^numbers only^lowercase letters^U/L letters^Numbers, | ^Length^numbers only^lowercase letters^U/L letters^Numbers, | ||
| |10|instantly|58 min|1 month|7 months|5 years| | |10|instantly|58 min|1 month|7 months|5 years| | ||
| Line 62: | Line 79: | ||
| ====Remembering Passwords and Associated Issues==== | ====Remembering Passwords and Associated Issues==== | ||
| - | |Method|Plusses|Minuses| | + | ^Method^Plusses^Minuses^ |
| - | |Piece of paper|Free, flexible|Loss. Smudges/ | + | |Piece of paper|Free, flexible|Loss. Smudges/ |
| - | |Sticky note attached to computer|Free|Can be seen or stolen by others. Fall off/loss. Smudges/ | + | |Sticky note attached to computer|Free|Can be seen or stolen by others. Fall off/loss. Smudges/ |
| |Spreadsheet|Free, | |Spreadsheet|Free, | ||
| - | |Password Manager|Free, | + | |Password Manager|Free, |
| or there' | or there' | ||
| - | {{: | + | {{: |
| ====How to create hard-to-guess passwords==== | ====How to create hard-to-guess passwords==== | ||
| - | If a human is going to guess the password then make it unhuman. | + | If a human is going to guess the password then make it unhuman. |
| - | Also see [[https:// | + | You can also do a DuckDuckGo (or Google if you're still using Google) search for “Best Password Managers” |
| - | Do a DuckDuckGo (or Google if you're still using Google) search for “Best Password Managers” | + | |
| - | All offer unlimited | + | //All of these offer login and text note storage in a secure vault protected by your master password, and can generate (and store) strong passwords.// |
| + | //Following data updated 2/ | ||
| + | |||
| + | ====Password Managers Summary==== | ||
| ^Manager^Free version. | ^Manager^Free version. | ||
| - | |[[https:// | + | |* [[https:// |
| - | |[[https:// | + | |[[https:// |
| - | |[[https:// | + | |[[https:// |
| - | |[[https:// | + | |[[https:// |
| - | |[[https://bitwarden.com/|bitwarden.com]]|* passwords file kept online\\ *<fs small> | + | |[[https:// |
| - | |[[https:// | + | |[[https://1password.com/]]|no free version, only paid, 2wk free trial|unlimited pw & devices, |
| - | |Others?| | + | |[[https:// |
| + | |[[https:// | ||
| + | KeePassXC is a KeePass port, see Tech Radar' | ||
| + | |||
| + | Refs: | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | * [[https:// | ||
| + | |||
| + | ====My Recommendations==== | ||
| + | If you're looking for a fast answer...here' | ||
| + | - KeePass on iCloud or Box. (You' | ||
| + | * You need to be willing to learn to use KeePass and set up cloud storage. | ||
| + | - BitWarden. | ||
| + | * Possibility of a breach, see ' | ||
| + | |||
| + | I am interested in your thoughts on these, and other, possibilities you like! | ||
| ====Caveat==== | ====Caveat==== | ||
| Line 96: | Line 134: | ||
| ====What I do==== | ====What I do==== | ||
| //These are my practices for your information. You should make a decision that's best for you.// | //These are my practices for your information. You should make a decision that's best for you.// | ||
| - | * KeePass on multiple devices | + | * Use KeePass |
| + | * On MacBook: KeePassXC | ||
| + | * On iPhone and iPad: KeePass Touch | ||
| + | * On Android: | ||
| + | * On Windows: KeePassXC | ||
| * Store password file in iCloud | * Store password file in iCloud | ||
| - | * Copy password file to local Documents | + | * Copy password file to local Document storage |
| - | * Copy password file to Dropbox, | + | * Copy password file to Box (free cloud storage) and Dropbox, |
| + | |||
| + | To note: | ||
| + | * KeePassXC updates the iCloud version whenever I make a change | ||
| + | * On iPhone and iPad I need to download a latest version of password file | ||
| + | * I added an entry in the password file that tracks latest changes (so I can tell if I have the latest on a given device) | ||
| Benefits: | Benefits: | ||
| * Free | * Free | ||
| + | * Available on all my devices | ||
| * One password to remember | * One password to remember | ||
| - | * I can use long and complex passwords | + | * I can use long and complex passwords |
| + | * Can keep a history of past passwords | ||
| + | * I can store other information in the vault, like those recovery passwords ” | ||
| Using a password manager: | Using a password manager: | ||
| - | * you can create quite long and complex passwords | + | |
| + | | ||
| * you can create secure passwords and not have to remember all of them | * you can create secure passwords and not have to remember all of them | ||
| * you only have to remember One password | * you only have to remember One password | ||
| + | * you can store your password file encrypted in multiple places including USB drives so it's unlikely to be lost | ||
| * you have all of your important access information in one spot, the encrypted file | * you have all of your important access information in one spot, the encrypted file | ||
| - | * (your next of kin would likely find this useful) | + | * //your next of kin would likely find this useful// |
| ====More About KeePass==== | ====More About KeePass==== | ||
| //Note that many of these features can be handled/ | //Note that many of these features can be handled/ | ||
| Line 151: | Line 203: | ||
| * I use a DB entry to log changes | * I use a DB entry to log changes | ||
| - | * “Last changed | + | * “Last changed |
| - | * Enter change(s) made, eg: ”1201: updated CCS entry, new password Kohls” | + | * Enter change(s) made, eg: ”0921: updated CCS entry, new password Kohls” |
| * This I do manually | * This I do manually | ||
| * Helps me synchronize databases | * Helps me synchronize databases | ||
| Line 158: | Line 210: | ||
| * I use KeePass application to create new entries and login passwords | * I use KeePass application to create new entries and login passwords | ||
| * Passwords typically 14+ characters (upper/ | * Passwords typically 14+ characters (upper/ | ||
| - | * KeePass tells me if a password is/isn't secure | + | * KeePass tells me how secure |
| Here is a possible password I might use: '' | Here is a possible password I might use: '' | ||
| Line 173: | Line 225: | ||
| ====Next: Live demo of KeePass==== | ====Next: Live demo of KeePass==== | ||
| + | on smi macbook | ||
| + | |||
| + | * open, select PasswordExample.kbdx pw=1234 | ||
| + | * Save as CSV and look | ||
| + | * Save as HTML and look | ||
| + | * Database> | ||
| ====Questions and Answers==== | ====Questions and Answers==== | ||
| Line 185: | Line 243: | ||
| * [[https:// | * [[https:// | ||
| * [[https:// | * [[https:// | ||
| + | * [[https:// | ||
| + | |||
| - | <fc # | ||
security_presentation.1638546996.txt.gz · Last modified: (external edit)
