Gentoo Archives: gentoo-user

From: Dale <rdalek1967@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Coming up with a password that is very strong.
Date: Mon, 04 Feb 2019 21:39:22
Message-Id: 75d871d1-b60f-6bc0-c2b0-d78220260fc8@gmail.com
In Reply to: Re: [gentoo-user] Re: Coming up with a password that is very strong. by Rich Freeman
1 Rich Freeman wrote:
2 > On Mon, Feb 4, 2019 at 3:09 PM Dale <rdalek1967@×××××.com> wrote:
3 >> I'm not sure if one can convert that to NSA time or not. o_O The
4 >> password contains upper/lower case letters, couple symbols from up top
5 >> of the number keys and several numbers. None of which anyone would be
6 >> able to guess in any way. They have nothing to do with that list of
7 >> things not to use, birthdays etc. If a person was trying to just guess
8 >> it, even a best friend who knows me extremely well, they would not be
9 >> able to guess it much less the order of it. The only bad thing, it
10 >> isn't to easy to type. Of course, a really good password usually isn't
11 >> so . . .
12 > And do you use that password on only a single site?
13 >
14 > If you use it on more than one, then as soon as one of those sites is
15 > compromised it will sniff your password and then your password can be
16 > used on all the others without any cpu cycles wasted on brute-forcing
17 > it at all.
18 >
19 > That is the weakness of random passwords. Unless you use some kind of
20 > password manager you won't actually use a unique password on each site
21 > due to difficulty with memorization...
22 >
23
24
25 Right now, I'm coming up with a master password for LastPass and maybe a
26 new set of keys.  I may use something different for my keys to your
27 point.  My encryption thingy broke on Seamonkey, the keys are broken
28 somehow.  I googled, tried some stuff but can't figure out how to fix
29 them so I revoked the things and am going to start fresh.  Heck, only
30 one person ever uses them anyway.  lol 
31
32 Once I get logged into LastPass, I generate unique passwords with it for
33 each site.  Depending on the site, I try to generate as long and use as
34 many characters as the site will allow.  If it allows the symbols on top
35 of the number keys, I enable them.  If it doesn't, I cut that off.  If
36 it allows 20 characters, I set it to generate 20.  It's not like I have
37 to remember it or even type it in either.  I may as well be as secure
38 and random as possible.  The master password is the current project tho. 
39
40 Way back, I used to have three passwords.  One fairly secure one for
41 financial type sites, one somewhat decent one for stuff like social
42 sites and one I could care less about.  None of them would be easy to
43 guess but the complexity changed.  Nowadays, I wouldn't even dream of
44 doing like that.  Far to many script kiddys out there trying to steal
45 stuff.  That doesn't even mention the pros and what they do. 
46
47 You are right tho, reusing passwords is a really bad idea.  It makes it
48 dead simple to hack everything else. 
49
50 Dale
51
52 :-)  :-)