Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This scares the crap out of me. I have to remember this one, super long and complex password for my password manager. If I ever accidentally paste it somewhere else, type it in somewhere or somehow it's leaked from the password manager then I am completely screwed. This one, tiny thing can completely turn my life upside down. For sites that require security questions those are easy to game so the only way to be secure is making up answers. So I wouldn't even be able to reset a large amount of very important passwords!

I wish we had a better alternative to passwords. Something that's actually good, solid, can't lose or forget. I get the feeling we won't have that until we can start implanting chips in ourselves.



It's really not so bad. I was reluctant to use 1password until being forced to by work, and discovered how wonderful having a password manager is.

First off, your passphrase should only be used for the password manager itself. So if you accidentally paste it on twitter, you just change your passphrase.

Secondly, you're way more easily fooled than a password manager. I don't know my passwords (they're generated), so to phish me you have to convince 1password as well. That means e.g the google open redirect bug on HN yesterday can't trick me with a fake password page on a different domain.

Third, it makes your passwords way easier to use on mobile. Most of the managers support whatever biometric integration your phone has nowadays, so rather than trying to type your 24 character alphanumeric symbol crap (or worse, a crappy password because you didn't want to make a good one on mobile) by hand you can just paste it in.

Lastly, it encourages you to actually use separate passwords for all your accounts. And when passwords get leaked, your manager can tell you which sites need new passwords.

In conclusion, password managers improve your internet security and experience immeasurably. Go buy 1password!

- satisfied 1password customer


Make sure you turn on 2FA on your password manager. That should allay most of those fears. (Of course you would still change the password if it was leaked somehow.)


1Password doesn't have 2FA because it needs to decrypt your data. It does have a long "secret account" key that you need along with your password.


I use a pass phrase which is much easier to remember. I know the source material for my pass phrase so if I need to reconstruct my master password I go to the source material and convert it into the password by encoding the first letters, punctuation symbols and letters from the passphrase into the password.

I need to get into the habit of exporting my password list to plaintext csv and storing it in a safe or safe deposit box but I haven't disciplined myself for that yet.

I am worried about the ability for the 1Password database to be hacked if someone were able to get their hands on that.


> I am worried about the ability for the 1Password database to be hacked if someone were able to get their hands on that.

This is one among several reasons I don't go in for any "cloud" based syncing of password managers. I use keypass and sync the file with syncthing on LAN only mode.


How about using the password manager to store security question answers too? It's mildly inconvenient because each site seems to require at least three, but then you wouldn't risk forgetting them and you could use random generated strings instead of having to make them up.


> How about using the password manager to store security question answers too?

That was my point: I use my password manager to store those security questions and answers but if someone got ahold of my password manager account I would be screwed because many sites require the answers to those questions to reset a password.


You just immediately change the master password and delete previous versions of the database file ?


Not really. If someone gets into someone else's password manager they can easily get a copy of all usernames and passwords and, if they're quick enough, they can start resetting them / closing them / committing fraud.

So yeah change the password and delete previous versions is a good first step but everything else has already leaked to who knows where.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: