Don't store your passwords online or in a document file labeled "secret passwords"….The best place to keep a record of your passwords is on a secured piece of paper
7 min read
Don't store your passwords online or in a document file labeled "secret passwords"….The best place to keep a record of your passwords is on a secured piece of paper
Hi Linda
Many experts recommend the use of secure password managers and the ones you mention all have their devotees.
Alongside all the many advantages of using a secure password manager ( and there are many advantages) is a potential drawback…..
There is an old saying about not keeping all your eggs in the one basket….
I do not think that Doug in his comments made over 5 years ago now (and of course a lot of changes have happened in the last 5 years) meant that you should keep important information laying around on various bits of paper…. he did refer to a "secured piece of paper."
Many folks keep a secured piece of paper with important information on it…. PIN s for bank cards, credit cards and the like, perhaps the number required to arm/disarm their burglar alarm, important account numbers and the like ( I'm sure you can think of many more apart from of course important passwords)
Some experts recommend that all passwords should be changed (every 28 days is often put forward) whilst others do not feel that so doing would substantially improve security……and may also harbour dark thoughts that if all users of the Internet changed all their passwords at that sort of frequency then some of the servers involved in handling that sort of workload might well "fall over" leading to a fair amount of chaos
Here are some extra thoughts for you… if you use a password manager you can create very long and complicated passwords that would be very difficicult and time consuming to break if all potential combinations were to be tried….
What is to be done if one forgets (or remembers incorrectly) your password manager's "master password"….?
With advancing age ( please don't think I am referring to you here Linda….but it certainly applies to my own cohort)
remembering things correctly can become not quite as easy as it once was….. some folks, customers etc., are beginning to notice a reduction in some of their mental faculties,( particularly short term memory) some maybe are developing early onset Alzheimers and similar conditions, so they need a more foolproof method…… a secured piece of paper may be a suitable "vehicle" for this ( always assuming that one can remember where it is kept!)
There is the problem of having important things secured by strong passwords when the inevitable happens, and someone dies….
If they have not planned for the inevitable it's possible that important matters, could be "out of bounds" indefinitely, and the special access codes for numbered bank accounts, on line site, and computer access and the like could remain in the sole custody of the deceased….
This may be what is required……. but…. it may not….
On that cheery thought I will leave others to make their recommendations….. I'm off to add some extra information to my secured piece of paper!
Regards
paws
Great words there indeed, personally I use LastPass, my understanding is the password is encrypted before it leaves your PC, then is stored in the cloud, even if the cloud did get "hacked" the info would be useless as they don't have the encryption, that's my understanding anyway, the downside is if you forget your password for LastPass your stuffed, they do not have or know it, so there is no rescue or password hints if you do forget, you would have to start all over again with a new account, easy to do, BUT, a major pain, and time consuming if you have lot's of details saved.
The great thing with this is you only need to remember 1 password, and that's the password for using the program, the software remembers ALL your other passwords for you, it also contains a password generator, so you can create passwords that you would have no chance of remembering, which also means it is a password people around you won't be able to guess, as that's one of the most common ways people get "hacked" as someone who knows you can take guesses at what you may use.
I recently saw an article saying that it is NOT wise to change your password on a regular basis, as it becomes a pattern that could become a weakness in your security, and no one will be able to guess the passwords that this software can generate, because they are truly random, and if you really want to lock it down you can use 2-Step Verification, you can also install this to a thumb drive, and use on ANY system by using that, and the details are not on the "donor" system, and using an encrypted thumb drive it's as safe as you can be IMHO.
So even if someone does get into your account, you can still get it back, because you need to remember the password for the account, it means it is at risk of being guessed by those who know you (even if only virtually), but all other passwords are as secure as you choose, personally I use 31 characters with ALL the variations I can, the limitation is some sites only allow x characters, and some do not allow special characters, otherwise you can use what you want as a rule.
The major downside with using such big passwords is if you use your phone for certain things, if you pay for the full version you're fine, otherwise you have to painstakingly type in all the characters, and the slightest error means retyping again and again until you get it right lol, my tip here is do NOT use 0 (zero) or o (letter, regardless of case type), they are far too easy to confuse and get wrong when manually typing them.
I must admit though, I do not have my banking or any money details saved with this, as good as it is there are still some things that I prefer to keep old school (in my head basically), and use a virtual onscreen keyboard to type them into the banks pages, as I use Kaspersky (free from my bank) it comes up when clicked, add to that using Trusteer Rapport to lock the screen down, with that even if someone has got into your system, and can view what you do, as soon as you go to a site using this they can see nothing, it's as secure as I can come up with.
As said above, others will have their favorite ways to do such things, many will say what I do is extreme, maybe so, but I have done the best I can to stay safe, so if the worst ever happened, any problems that could come from someone accessing your account(s), you can show them it wasn't your fault that it happened, and you should recoup any losses that could in the worst case happen, that's my thinking anyway, hope it helps you decide on what you do.