Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem with password managers is, when you're away from whatever machine you managed to get the thing set up on, you're locked out of all your accounts.


Keyloggers exist. Ergo, you shouldn't ever type an important password into a machine that doesn't belong to you.

Fortunately, as others have pointed out, it isn't 1990 anymore and I carry a mobile computer wherever I go, disguised as a phone.


The 1Password iPhone app has pretty much solved that problem for me:

http://itunes.apple.com/us/app/1password-pro/id319898689?mt=...


Same thing for android https://market.android.com/details?id=com.onepassword.passwo...

Also, if you share your 1password db on dropbox, you can later access it via a local web interface (always making sure that you trust the machine you're using).


This is why I always keep my encrypted keyfile on DropBox (usually a KeePass safe and a standalone installation of PasswordSafe USB mode).

This way, you can access your passwords from home, work, or your phone as long as you trust the machine you're logged into enough to log into DropBox and type your password safe password. If you can't tell if the machine is free of keyloggers, you probably shouldn't be logging into anything of personal value.


this. I use Dropbox with Keepass and Truecrypt. You can get these apps anytime from the web, put on USB keychain, or just remember Dropbox and run Keepass and Truecrypt from there. Just make sure to have a very long/secure Dropbox password, as that becomes the weakest link.

There's also Dropbox and Keepass for Android.


I use Keepass, but thought it took care of encryption for me. Is there a compelling reason to use additional encryption...?


The extra encryption is mostly for keys that I use with the passwords on Keepass.


Do browsers sync these yet? I know Chrome, Firefox et al. have various syncing options, but I've never looked into how they work exactly.

Edit: looked into it, and the situation for password sync is

- Chrome: built in since V. 11

- Firefox: available through add-ons/extensions (XMarks)

- Opera: since beta 11.5 (the latest as of right now)

- Safari: available through extensions/other services (mobileme? not sure)

- IE: unclear


Re: Safari, yes, you can have MobileMe sync your keychain, which contains your saved login info, etc.


Firefox 4 and up have built-in password syncing (along with bookmarks, history etc). Everything's encrypted client-side, so you never have to worry about unauthorized access to them.


Thanks, interesting that this didn't show up in my brief research.


I put a copy of the database in cloud storage. There might be a little set-up to open it, but it's very rare that I need to get the contents on a new machine.

The nitpick with pw databases is they don't fully solve the problem; I still need to know the passwords for all my computers, cloud storage account, e-mail, the db master password.

The big advantage is how much more secure lesser used accounts are (and drop in frequency of password reset requests on those accounts).


This is not entirely true. You only need to really "know" two passwords... your cellphone screen lock and the password to the encrypted password database on your cellphone.

If your cellphone uses DropBox to store the database, then you can even lose your cellphone or simply access the database on desktops and laptops directly.


While this is true in theory, I don't maintain a copy of the database on my phone - when I converted to using a pw database I looked into it and didn't feel comfortable with the level of security on iPhone apps. I want to know exactly when and how information is being transported and when something is in memory.

The state of the art is probably more mature now, but this is information I'm not taking any chances with.


This is not true with Lastpass and Passpack. I highly recommend Passpack. Very secure.


This is not the case with passwordcard.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: