Free Republic
Browse · Search
General/Chat
Topics · Post Article

To: Crusher138

That’s the same system I came up with, you must be an IT. There was a time when I had to manage over 45 passwords for all of the system access that I needed.


18 posted on 07/09/2024 9:32:23 AM PDT by wildcard_redneck (He who sacrifices freedom for security deserves neither.)
[ Post Reply | Private Reply | To 11 | View Replies ]


To: wildcard_redneck; Crusher138
> That’s the same system I came up with, you must be an IT. There was a time when I had to manage over 45 passwords for all of the system access that I needed.

I used to use that scheme too for years (I've been in IT for decades). But the drawback of that scheme is that if ever any of those passwords is leaked in plaintext (remember, Windows stores your password in plaintext and it's not very hard to read it out), the scheme becomes obvious and a hacker can pretty quick determine the "fixed" part and the "per-site" part, and guess it for other sites.

So since I have around 250 passwords to deal with, I use 16-character random strings of upper, lower, digits, and punctuation, and two different password manager programs, encrypted and backed up to multiple computers.

Oh, and I have 2FA/MFA on the 25 or so most critical accounts, using Google-Auth, MS-Auth, and Duo-Auth on my phone. I back up my phone data (encrypted of course) to two different computers.

I can't afford to be hacked, and I can't afford to lose access to those passwords or 2FA.

My level of effort is not necessary for most people, but so far it has served me well.

23 posted on 07/09/2024 9:52:36 AM PDT by dayglored (Strange Women Lying In Ponds Distributing Swords! Arthur Pendragon in 2024)
[ Post Reply | Private Reply | To 18 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson