Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The problem with writing passwords down is that I need to fly places and it's not unheard of if you work in financial tech or military tech to have your things riffled through at the boarder. Plus a mugger can say "give me your things!" or "Empty your pockets!" and now he has my credentials.

Passwords are not easy. My current solution for the long tail of things that need passwords is two factor + really strong password I generate then don't save anywhere. If I get signed out I do password reset to my gmail. Gmail is two factor (obviously) with a really strong password and recovery email to an email address nobody knows.

This is still a huge pain though.



If you used any stateful password manager instead of a piece of paper, then the passwords would be stored in an encrypted fashion. Don't give out your master password and your passwords are useless to an attacker.

If you use a paper based solution, just alter the passwords you write down using some additional information only known to you - maybe some prefix or suffix and the list would be useless for an attacker.

If you think they can force you to divulge the master password or your password scheme if you're using paper (they probably can, see https://xkcd.com/538/), then LessPass won't be of any help to you either.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: