Security Recomendations for UserNames, SecurityQuestions, Passwords

Closed Thread
Thread Tools
  #31  
Old 06-10-2021, 01:18 PM
OrangeBlossomBaby OrangeBlossomBaby is online now
Sage
Join Date: Feb 2015
Posts: 8,488
Thanks: 6,846
Thanked 9,437 Times in 3,081 Posts
Default

Quote:
Originally Posted by GrumpyOldMan View Post
Good advice except for the password. Encouraging an "Easily remembered" is a doorway to less secure passwords. The imp[ortant part is to be as long as possible, second, it should be random.

Security has spiraled down into an abyss of complications for the average user. We need better. Biometrics would help but aren't ubiquitous enough yet.

There are very good password managers available for all platforms. Everyone should be using one. Password managers are apps that remember the password for you, so you don't have to. And good PW managers will also give advice on potential issues like you are reusing a password at multiple places (another no-no).

Apple has a very good password manager called "Keychain" which meets all those requirements and more.

It would pay users to get and learn and try to always use a good password manager.
Yeah I had a password manager set up, and then when windows did an automatic upgrade, it logged me out of EVERYTHING -

including the password manager.

And I didn't know the password to the password manager, because I had google auto-fill the password for me.

And then there are all those accounts that require you to change your password every 90 days.

And then there are the few accounts that are left over from the dinosaur days, that finally catch up with the 21st century and tell you that you have to make a new password that's at least 8 characters long, require a special character, a capital letter, and a numeric digit. So all those "orangebaby" passwords now have to be "0rangeB^by"
  #32  
Old 06-10-2021, 01:50 PM
GrumpyOldMan GrumpyOldMan is offline
Soaring Eagle member
Join Date: Jul 2019
Posts: 2,016
Thanks: 333
Thanked 2,477 Times in 753 Posts
Default

Quote:
Originally Posted by OrangeBlossomBaby View Post
Yeah I had a password manager set up, and then when windows did an automatic upgrade, it logged me out of EVERYTHING -

including the password manager.

And I didn't know the password to the password manager, because I had google auto-fill the password for me.

And then there are all those accounts that require you to change your password every 90 days.

And then there are the few accounts that are left over from the dinosaur days, that finally catch up with the 21st century and tell you that you have to make a new password that's at least 8 characters long, require a special character, a capital letter, and a numeric digit. So all those "orangebaby" passwords now have to be "0rangeB^by"
I understand completely. I tried several Windows Password managers for my wife who runs windows (I run MacOS) and never found one I was happy with.

Since she has an iPad I talked her into using Apples Keychain and now she is a happy camper. She has to type in passwords on windows, but she can always find them on her iPad or iPhone.
  #33  
Old 06-10-2021, 03:34 PM
Windguy Windguy is offline
Senior Member
Join Date: Jun 2016
Posts: 451
Thanks: 1,713
Thanked 679 Times in 246 Posts
Default

Quote:
Originally Posted by CFrance View Post
Can you recommend a good password manager for a dyed-in-the-wool Windows user?
I really like Keeper. Not only does it work on Windows, it makes the passwords available on all your mobile devices, too. If you upgrade Windows and get logged out of everything and forget your Keeper password, you can use your phone or tablet to log into Keeper using your face or finger print. Still, Keeper requires me to enter my Keeper password on Windows every time. It’s the only password I need to remember and it’s a good one, but easy to remember.
  #34  
Old 06-10-2021, 08:29 PM
OrangeBlossomBaby OrangeBlossomBaby is online now
Sage
Join Date: Feb 2015
Posts: 8,488
Thanks: 6,846
Thanked 9,437 Times in 3,081 Posts
Default

I just checked on Keeper, it seems to do everything Google already does. Stores my passwords, checks for breaches and warns me of them, saves anything I want to the cloud and syncs with all my devices. I don't pay anything for it though.
  #35  
Old 06-11-2021, 02:09 PM
CFrance's Avatar
CFrance CFrance is offline
Sage
Join Date: Dec 2011
Location: Tamarind Grove/Monpazier, France
Posts: 14,480
Thanks: 388
Thanked 1,922 Times in 783 Posts
Default

Quote:
Originally Posted by Tunesmith View Post
I've been using RoboForm for my passwords. At first, I just used the free version, but it didn't automatically sync passwords between all my devices. So I bought the more advanced version and that has been working great for syncing up any new or changed passwords with all my other devices. Go to roboform dot com, price for 1 year is about $24. Well worth it to remember 20-character randomly-generated passwords for you!
I just checked how long it would take to break a 20-character password that RoboForm generated. I used the "Use a Passphrase" link that was posted on page 1. The results for this password (BZfaUHBr.SJYGikf8393) was:
Approximate Crack Time: 31,167,128,343,915,984 centuries. Good enough for me.
When you sign up for this, do you have to change all your existing passwords?
__________________
It's harder to hate close up.
  #36  
Old 06-11-2021, 02:43 PM
oldtimes oldtimes is offline
Veteran member
Join Date: Nov 2018
Posts: 982
Thanks: 156
Thanked 1,376 Times in 499 Posts
Default

Quote:
Originally Posted by CFrance View Post
When you sign up for this, do you have to change all your existing passwords?
No. It will make suggestions but it will not force you. It's very slick, I use it on my laptop, on my ipad and on my phone. You only need to remember the one password that logs you on to the app and it takes care of the rest.
  #37  
Old 06-11-2021, 04:12 PM
OrangeBlossomBaby OrangeBlossomBaby is online now
Sage
Join Date: Feb 2015
Posts: 8,488
Thanks: 6,846
Thanked 9,437 Times in 3,081 Posts
Default

Quote:
Originally Posted by oldtimes View Post
No. It will make suggestions but it will not force you. It's very slick, I use it on my laptop, on my ipad and on my phone. You only need to remember the one password that logs you on to the app and it takes care of the rest.
How does it handle passwords that are required to change every 90 days, and you're not allowed to use the same password you used "x" times prior (each company seems to have different rules)?
  #38  
Old 06-11-2021, 04:19 PM
oldtimes oldtimes is offline
Veteran member
Join Date: Nov 2018
Posts: 982
Thanks: 156
Thanked 1,376 Times in 499 Posts
Default

Quote:
Originally Posted by OrangeBlossomBaby View Post
How does it handle passwords that are required to change every 90 days, and you're not allowed to use the same password you used "x" times prior (each company seems to have different rules)?
There are not many sites that require password changes anymore. I am not subscribed to any but there is an update password ability for any that are changed. The automatic password generator has options you can set.
  #39  
Old 06-11-2021, 08:22 PM
CFrance's Avatar
CFrance CFrance is offline
Sage
Join Date: Dec 2011
Location: Tamarind Grove/Monpazier, France
Posts: 14,480
Thanks: 388
Thanked 1,922 Times in 783 Posts
Default

Quote:
Originally Posted by oldtimes View Post
No. It will make suggestions but it will not force you. It's very slick, I use it on my laptop, on my ipad and on my phone. You only need to remember the one password that logs you on to the app and it takes care of the rest.
One more question, if you don't mind. What happens if you pass away and your heirs are handling your estate? I would have left the main password & user name, but would they have to have the RoboForm program in order to access my accounts, etc.?


When we had our trust revised, we were told to put a list of user names and passwords with the trust in the safe deposit box. Getting that list together has been daunting.
__________________
It's harder to hate close up.
  #40  
Old 06-11-2021, 09:31 PM
oldtimes oldtimes is offline
Veteran member
Join Date: Nov 2018
Posts: 982
Thanks: 156
Thanked 1,376 Times in 499 Posts
Default

Quote:
Originally Posted by CFrance View Post
One more question, if you don't mind. What happens if you pass away and your heirs are handling your estate? I would have left the main password & user name, but would they have to have the RoboForm program in order to access my accounts, etc.?


When we had our trust revised, we were told to put a list of user names and passwords with the trust in the safe deposit box. Getting that list together has been daunting.
Actually I use Lastpass which I am sure is very similar to Roboform in the way it works. It is free for one device and I paid $27 to use on all my devices. It is web based so they could log in from anywhere as long as they had the main password with the premium plan and could easily log in on your main device if you had the free version.
  #41  
Old 06-11-2021, 09:53 PM
CFrance's Avatar
CFrance CFrance is offline
Sage
Join Date: Dec 2011
Location: Tamarind Grove/Monpazier, France
Posts: 14,480
Thanks: 388
Thanked 1,922 Times in 783 Posts
Default

Quote:
Originally Posted by oldtimes View Post
Actually I use Lastpass which I am sure is very similar to Roboform in the way it works. It is free for one device and I paid $27 to use on all my devices. It is web based so they could log in from anywhere as long as they had the main password with the premium plan and could easily log in on your main device if you had the free version.
Got it; thanks.
__________________
It's harder to hate close up.
Closed Thread

Tags
throw, remember, easy, financial, security

Thread Tools

You are viewing a new design of the TOTV site. Click here to revert to the old version.

All times are GMT -5. The time now is 10:02 AM.