Jump to content

Recommended Posts

Posted

Hello everyone!

Could you please tell me what applications you use to store passwords?

How safe is it to store all passwords on your computer in your opinion?

Posted
Hello everyone!

Could you please tell me what applications you use to store passwords?

How safe is it to store all passwords on your computer in your opinion?

When you say "on your computer" what are you referring to? Do you mean in the browser? Definitely a No!

Do you mean in an encrypted / password protected document? Better than having a doc without a password on it.

Posted

Develop some proper requirements. Off the top of my head:

Passwords for what?

Is this is personal use?

Do you need to share passwords within a team? And if so you’ll presumably need audit info on use & changes?

Do you need something that will rotate passwords for you?

How will you backup and recover this password store? And keep your backup secure?

Posted
Why not use the browser?
It's not secure. Passwords are often stored in an unencrypted format so anyone with access to your computer can find your password.

 

There's also a lot of malware that can steal passwords from the browser.

 

Password Managers have their flaws, but they're a safer option (LastPass excluded).

  • Thanks 1
Posted

I'd too suggest a Password manager, unique passwords, hardware MFA, strong master password (or passphrase) at least 21 characters and high iterations.

 

Many options for password managers out there including hosting your own. But if you host your own make sure it is highly secure and I'd only make it available via a VPN and only then if absolutely necessary and still enforce hardware MFA for the access however it is accessed.

  • Thanks 1
Posted
It's not secure. Passwords are often stored in an unencrypted format so anyone with access to your computer can find your password.

 

There's also a lot of malware that can steal passwords from the browser.

 

Password Managers have their flaws, but they're a safer option (LastPass excluded).

 

When you say often, how often? Anyone with access to your computer can always find your autofilled passwords, that's just how it works.

 

Malware can steal passwords from any password manager on the same device.

Posted (edited)

The main reason I'd give for reommending a dedicated password manager over using built-in browser password management is that a dedicated password manager will allow you to store all the other information associated with accounts, such as MFA details, PINs, descriptive notes, certificates, answers to security questions, etc. and can work more easily between browsers. Built-in browser tools only store URL, username and password, and are obviously less browser-agnostic.

 

Also, not every password or account is for a website.

 

If you're considering a non-cloud based manager, such as KeePass, then Syncthing seems a popular choice for making your data available across multiple devices without having to rely on a cloud service. Not used Syncthing myself, but it looks neat.

Edited by jthompson
  • Thanks 2
Posted
Thank you for your response! This is for private use. I'm wondering what apps are used for this and how safe it is.
Posted

If you use Android then store them in Chrome, way easier to sync than anything else. Pretty sure Google knows something about security.

 

If you care about security, don't let other people use your computer when it's logged in as you

Posted

With storing password you always have to think of your threat model really. When people say don't store them in your browser etc because if some one has access to your computer/device then its not safe (This can also apply to password mangers too). When someone has access to your computer you have a lot more to worry about other than access your password passwords, depending on if its physical person or malware/remote access trojan etc.

 

As long as you have unique complex passwords of length then this just stops others from accessing your online services with credential reuse for example. I know the password system in Chrome creates unique passwords and saves them to your google account Password managers just make it easy to create different unique passwords (and username/email addressees) and they have the ability to share these with a team. Yes they are safe but again if someone has access to your computer it could be game over.

 

So you need to decide who needs access to the accounts if its multiple people then use a password manager if its only you then a browser may be fine. You could also think storing them on paper in a safe would be best (its off line and only the people with the key have access and no one can remote access the safe can they.)

 

You always have to think what is your threat model and how best to mitigate this.

 

Also on a personal note you need to make sure family can access your passwords etc if something happens to you.

 

I hope I am making some sense here and not gone down some rabbit hole.

Posted (edited)

You have to way this up at the end of the day.

 

Excel spreadsheet

Written down and/or USB key in a fireproof safe pros and cons

Use web browser saving passwords which has it pros and cons but is convenient.

Use a password manager extension, bit more flexible and can have protections such as idle timeout etc and still require a password to re-authenticate or a pin in some cases. Again has security Pro and cons but these could be minimal if other things are in place

Access a password manager separately what could use hardware token MFA. Can also have some pros and cons.

 

You should still protect as many accounts as you can with some sort of MFA hardware token prob the best choice.

Edited by Davit2005
  • Thanks 1
Posted

There's always secret option c) Don't have so many passwords, use sso

 

In Chrome you either need to know their password, or go to a page, wait for autocomplete, then inspect element, so you're only stealing 1 password at a time anyway. Solution: lock your computer

Posted
But if you go to the History folder you can see what websites have been accessed?? Services cannot even agree MFA standards or password complexity standard (although that is a good thing as it is one sure way to make people use different passwords, lol) .
Posted

As the attacker to find website to autofill? Or as the investigator trying to work out what was stolen?

 

If you can't login with OAuth, don't buy the product, and tell them why.

Posted
So are we working on the threat model of "that someone has gained access to your PC either remotely or in person for them to look through your history folder?"
Posted
1password

 

This here too for work - great product.

 

Lastpass seem to be addressing some of the issues they had recently - I still use it for personal password management and had messages inside the App this week about what they were doing not that I read them.

Posted
I believe the national cyber security centre has said that storing passwords in the browser is acceptable.

 

More of a better than nothing option. They say need to ensure os and browser updates and installed promptly. They also say it should not be used on shared computers.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...