Gentoo Archives: gentoo-user

From: Tanstaafl <tanstaafl@×××××××××××.org>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Coming up with a password that is very strong.
Date: Tue, 05 Feb 2019 19:49:36
Message-Id: 71aa9151-e07d-0838-29c9-fca0240e7af8@libertytrek.org
In Reply to: Re: [gentoo-user] Coming up with a password that is very strong. by Dale
1 On 2/4/2019, 8:10:57 PM, Dale <rdalek1967@×××××.com> wrote:
2 > Tanstaafl wrote:
3 >> I've been using a little Firefox Addon called Passwordmaker for many,
4 >> many years, and despite all of its warts, I've been loathe to give it
5 >> up, even though it will never be upgraded to work as a WebExtension.
6 >>
7 >> 2 things I loved about it -
8 >>
9 >> a) it doesn't save the password locally, only info about the
10 >> site/account, and
11 >> b) you can use an unlimited number of Master Passwords
12 >>
13 >> I'm looking at migrating to KeePassXC, and even though I really hate the
14 >> idea of saving the actual password - Passwordmaker simply generates the
15 >> password on the fly each time based on certain specified criteria (ie,
16 >> the site URL, username, password length, etc for each account - one
17 >> technique I adopted shortly after assisting in updating the
18 >> Passwordmaker website eases my mind about it...
19 >>
20 >> This is a simple technique I strongly recommend that everyone employ,
21 >> especially if you use a Password manager (like LastPass or KeePass)...
22 >>
23 >> It is uncrackable (well, as long as it isn't the CIA or NSA that wants
24 >> to crack it and they are willing to kidnap/torture you to do so).
25 >>
26 >> You sit down and come up with a ... call it a 'password modification
27 >> protocol' ... whereby, you always modify your generated/stored password
28 >> in a specific way before pressing enter.
29 >>
30 >> For example, you delete characters 3, 5 and 7, then add 2 characters to
31 >> the beginning and 2 to the end.
32 >>
33 >> It is very simple, and negates worrying about someone stealing your
34 >> password vault.
35
36 > I tried to find it just to see how it works but it isn't listed.
37
38 What... Passwordmaker (the old one I still use and why I keep an old
39 Firefox 56 portable version around)?
40
41 > From what you wrote, you may want to at least check into LastPass.
42
43 I did a massive amount of research (including LastPass), and settled on
44 KeePassXC for a good reason.
45
46 > Still, I'm sure there is a tool that will suite your needs.
47
48 ? Its like you didn't really read my email. I already said, I'm
49 migrating to KeePassXC. But my complaint is, nothing works like
50 Passwordmaker (again, it doesn't store passwords, can only use one
51 Master Password).
52
53 > I'm not sure I understand what you mean password modification protocol. 
54 > It sounds like you change your master password each time you use it.
55
56 No, I'm talking about the saved (or in Passwordmakers case, generated)
57 password, not the Master Password.
58
59 Doing this with the Master Password wouldn't make any sense.

Replies

Subject Author
Re: [gentoo-user] Coming up with a password that is very strong. Dale <rdalek1967@×××××.com>