The "To Keep Up" Wiki

A collection of information we find useful

User Tools

Site Tools


security_presentation

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
security_presentation [2022.10.09 13:59] Steve Isenbergsecurity_presentation [2022.10.11 15:31] (current) – [How to create hard-to-guess passwords] Steve Isenberg
Line 33: Line 33:
   * (Can you think of others?)   * (Can you think of others?)
  
-How long to crack: From [[https://www.komando.com/security-privacy/check-your-password-strength/783192/|Kim Komando]]+Recent from WikiHow: [[https://www.wikihow.com/Guess-a-Password]] 
 +Gives a set of steps to follow to guess someone's password. 
 +  - Figure out the password requirements for the site or app 
 +  - Ask for a hint or security questions (the "hint" may be easy to guess) 
 +  - Check the list of easy-to-remember passwords 
 +    - like: 123456, 123456789, Qwerty, Password, Pa$$w0rd, Qwerty123, Iloveyou, etc 
 +  - Phone screen passwords may be easy to guess (123456, 147258, etc) 
 +  - Names of family members and pets 
 +  - What you know about the target's interests (Golfpro, Mathwhiz, etc) 
 +  - Significant numbers and dates 
 +    - like: address, birth/marriage/etc dates, lucky numbers, graduation date 
 +  - Reverse or change the letters 
 +    - Adlihnurb, tsorfmada 
 +    - Substituting $ for s, 0 for o, 3 for e, 1 for i, etc  (P@$$w0rd, w1k1h0w) 
 +  - If you have access to their machine, check for saved passwords in Browsers 
 + 
 +How long to crack: From [[https://www.komando.com/security-privacy/check-your-password-strength/783192/|Kim Komando]] March 2021
 ^Length^numbers only^lowercase letters^U/L letters^Numbers, U/L^Numbers, U/L, Symbols^ ^Length^numbers only^lowercase letters^U/L letters^Numbers, U/L^Numbers, U/L, Symbols^
 |10|instantly|58 min|1 month|7 months|5 years| |10|instantly|58 min|1 month|7 months|5 years|
Line 63: Line 79:
  
 ====Remembering Passwords and Associated Issues==== ====Remembering Passwords and Associated Issues====
-|Method|Plusses|Minuses| +^Method^Plusses^Minuses^ 
-|Piece of paper|Free, flexible|Loss. Smudges/can't read writing. Processed by washing machine. Someone else can get. You create passwords.| +|Piece of paper|Free, flexible|Loss. Smudges/can't read writing. Processed by washing machine. Someone else can get. You create the passwords.| 
-|Sticky note attached to computer|Free|Can be seen or stolen by others. Fall off/loss. Smudges/can't read writing. Only available on computer its posted. You create passwords.|+|Sticky note attached to computer|Free|Can be seen or stolen by others. Fall off/loss. Smudges/can't read writing. Only available on computer its posted. You create the passwords.|
 |Spreadsheet|Free, flexible|Where do you store it. Overwrittenable by accident. You create passwords.| |Spreadsheet|Free, flexible|Where do you store it. Overwrittenable by accident. You create passwords.|
-|Password Manager|Free, or paid. Can produce good passwords|Where are passwords stored. Possible breech if stored online. Loss or theft if stored in thumb drive or your computer.|+|Password Manager|Free, or paid. Can produce good passwords in one spot. Backupable.|Where are passwords stored. Possible breech if stored online. Loss or theft if stored in thumb drive or your computer.|
 or there's this option,\\ credit to John McPherson of [[http://closetohome.com|Close to Home]]:\\  or there's this option,\\ credit to John McPherson of [[http://closetohome.com|Close to Home]]:\\ 
-{{:20211202solution.jpg?direct&250|}}+{{:20211202solution.jpg?direct&500|}}
  
 ====How to create hard-to-guess passwords==== ====How to create hard-to-guess passwords====
-If a human is going to guess the password then make it unhuman.  Consider: a password "safe" Here are some free alternatives.  From [[https://www.techradar.com/news/software/applications/the-best-password-manager-1325845|Tech RadarThe best free password manager 2019]] with updates I took from the application sites 20211129\\  +If a human is going to guess the password then make it unhuman.  Consider: a password "safe" Here are some alternatives, many are free or have free options.\\   
-Also see [[https://www.pcmag.com/roundup/331555/the-best-free-password-managers|PC Magazine's picks]]\\  +You can also do a DuckDuckGo (or Google if you're still using Google) search for "Best Password Managers" and look for those with recent information.
-Do a DuckDuckGo (or Google if you're still using Google) search for "Best Password Managers" and look for those with 2020 or 2021 information.+
  
 //All of these offer login and text note storage in a secure vault protected by your master password, and can generate (and store) strong passwords.// //All of these offer login and text note storage in a secure vault protected by your master password, and can generate (and store) strong passwords.//
  
 +//Following data updated 10/9/2022.  There are MANY other options, these are a few.  You should study all of the features and drawbacks of any option you consider or select.//
 ^Manager^Free version.  ^Paid version.  ^Cost.  ^platforms^ ^Manager^Free version.  ^Paid version.  ^Cost.  ^platforms^
-|[[https://www.lastpass.com/|www.lastpass.com]] |Access on one device type |1GB Secure cloud storage\\ Multi Factor Authentication\\ Contingency plan (loved one access in emergency) |Free for one device type; $3/month 1 user, $4/month 6 users (group and share items, family manager)|Win, Mac, Linux, Mobile| +|[[https://www.lastpass.com/|www.lastpass.com]] |Access on one device type (computer or mobile) |1GB encrypted cloud storage\\ Multifactor Authentication (MFA)\\ Contingency plan (loved one access in emergency) |Free for one device type; $36/yr 1 user, $48/yr 6 users (group and share items, family manager)|Browser based. Win, Mac, Linux, Mobile| 
-|[[https://www.dashlane.com/|www.dashlane.com]]|Up to 50 passwords, one device|unlimited passwords, unlimited devices, 1GB max| $4.99/mo billed annually, multiple accounts $7.49/mo billed annually|Win, Mac, iOS, Android| +|[[https://www.dashlane.com/|www.dashlane.com]]|One device, secure sharing|unlimited devices, 1GB max, VPNFree; $60/yr or $90/yr (10 accts)|Browser based.  Win, Mac, iOS, Android| 
-|[[https://keepersecurity.com|keepersecurity.com]]|access on one device|unlimited device access|$2.91/month, $34.99 annually|Mac, Windows, Linux, iOS, Android| +|[[https://keepersecurity.com|keepersecurity.com]]|no free option|(Personal) no limits on storage, devices, sharing; (family) 5 vaults, 10GB secure storage|Personal $35/yrFamily $75/yr|App: Mac, Windows, Linux, iOS, Android; Browser extension
-|[[https://www.roboform.com/lp?frm=everywhere-offer&rec=TechRadar&dc=TR30&affid=a6277|www.roboform.com]]| |sync across devices, cloud backup, web access, all cost|<del>$23.88</del>$16.68/1yr, <del>$71.64</del>$45.14/3yr, <del>$119.40</del>$69.60/5yr|Windows, Mac, iOS, Android, Linux, Chrome OS+|[[https://www.roboform.com/lp?frm=everywhere-offer&rec=TechRadar&dc=TR30&affid=a6277|www.roboform.com]]|one device |sync across devices, cloud backup, web access. Family plan is 5 users.|Personal: $16.68/1yr, $45.14/3yr, $69.60/5yr\\ Family: $33.40/1yr, $90.20/3yr, $139.30/5yr|Windows, Mac, iOS, Android, Linux, Chromebook, Browsers
-|[[https://bitwarden.com/|bitwarden.com]]|* passwords file kept online\\ *<fs small>(but you can install it on your own server)</fs>\\ *one file, share w/another | 1GB encrypted storage | $10/yr one user, $39.96/yr up to 6 users |Windows, Mac, Linux, iOS, Android| +|[[https://bitwarden.com/|bitwarden.com]]|Unlimited pw, devices | 2FA, emergency access, share w/1-6 people | $10/yr one user, $40/yr up to 6 users |Windows, Mac, Linux, iOS, Android, Browsers
-|[[https://keepass.info/|keepass.info]]|* Can run from USB\\ * Many customizable options\\ * A little intimidating? You judge.|FOSS((FOSS=Free, Open-Source Software)) - there is no paid version -- all features in free version\\ Many ports, with different features and UI|Note, no cost. Does not provide place to store the Password Safe, that's up to you|Windows, Android, iPhone/iPad, Mac, Chromebook, Blackberry, Linux, and more| +|[[https://1password.com/]]|no free version, only paid, 2wk free trial|unlimited pw & devices, 1GB storage, 2FA.|Individual: $36/yr, Families (5 family members): $60/yr|Mac, Win, Linux, iOS, Android, Browsers| 
-|Others?|+|[[https://nordpass.com/]]|unlimited pw, notes also, credit cards|emergency access |Premium $24/yr, Family (6 accts) $60/yr|Win, Mac, Linux, Android, iOS, Browsers| 
 +|[[https://keepass.info/]]\\ [[https://keepassxc.org/download/|KeePassXC]]|* Can run from USB\\ * Many customizable options\\ * A little intimidating? You judge.|FOSS((FOSS=Free, Open-Source Software)) - there is no paid version -- all features in free version\\ Many ports, with different features and UI|Note, no cost. Does not provide place to store the Password Safe, that's up to you|Windows, Android, iPhone/iPad, Mac, Chromebook, Blackberry, Linux, and more| 
 +KeePassXC is a KeePass port, see Tech Radar's review: [[https://www.techradar.com/reviews/keepassxc]]. It's free but accepts donations. 
 + 
 +Refs:  
 +  * [[https://www.techradar.com/news/software/applications/the-best-password-manager-1325845|Tech Radar, The best free password manager 2019]] 
 +  * [[https://www.pcmag.com/roundup/331555/the-best-free-password-managers|PC Magazine's picks]] 
 +  * [[https://www.pcmag.com/picks/the-best-password-managers]] 
 +  * [[https://www.cnet.com/tech/services-and-software/best-password-manager/]] 
 +  * [[https://www.techradar.com/best/password-manager]] a good site for reviews of offerings 
 +  * [[https://www.techradar.com/reviews/keepassxc]] TechRadar's review of KeePassXC
  
 ====Caveat==== ====Caveat====
Line 116: Line 142:
   * One password to remember   * One password to remember
   * I can use long and complex passwords   * I can use long and complex passwords
 +  * Can keep a history of past passwords
  
 Using a password manager: Using a password manager:
-    * you can create quite long and complex passwords+    * easy to create long and complex passwords 
 +    * you can use long and complex passwords
     * you can create secure passwords and not have to remember all of them     * you can create secure passwords and not have to remember all of them
     * you only have to remember One password     * you only have to remember One password
 +    * you can store your password file encrypted in multiple places including USB drives so it's unlikely to be lost
     * you have all of your important access information in one spot, the encrypted file     * you have all of your important access information in one spot, the encrypted file
-      * (your next of kin would likely find this useful)+      * //your next of kin would likely find this useful//
 ====More About KeePass==== ====More About KeePass====
 //Note that many of these features can be handled/provided by other password manager software, free and at cost// //Note that many of these features can be handled/provided by other password manager software, free and at cost//
Line 162: Line 191:
    
   * I use a DB entry to log changes   * I use a DB entry to log changes
-    * "Last changed 20211201.2007(Dec 22021, 8:07pm) +    * "Last changed 20221009.1817meaning October 92022 at 6:17pm 
-    * Enter change(s) made, eg: "1201: updated CCS entry, new password Kohls"+    * Enter change(s) made, eg: "0921: updated CCS entry, new password Kohls"
     * This I do manually     * This I do manually
     * Helps me synchronize databases     * Helps me synchronize databases
Line 169: Line 198:
   * I use KeePass application to create new entries and login passwords   * I use KeePass application to create new entries and login passwords
     * Passwords typically 14+ characters (upper/lower case and numbers)     * Passwords typically 14+ characters (upper/lower case and numbers)
-    * KeePass tells me if a password is/isn't secure+    * KeePass tells me how secure given password is
  
 Here is a possible password I might use: ''cqLbq2NHcuNmgU'' -- 14 characters, upper and lower case letters, and at least one number.  This one has entropy 82.06 which is deemed "good".   Here is a possible password I might use: ''cqLbq2NHcuNmgU'' -- 14 characters, upper and lower case letters, and at least one number.  This one has entropy 82.06 which is deemed "good".  
Line 184: Line 213:
  
 ====Next: Live demo of KeePass==== ====Next: Live demo of KeePass====
 +on smi macbook
 +
 +  * open, select PasswordExample.kbdx pw=1234
 +  * Save as CSV and look
 +  * Save as HTML and look
 +  * Database>Reports
 ====Questions and Answers==== ====Questions and Answers====
  
security_presentation.1665349140.txt.gz · Last modified: 2022.10.09 13:59 by Steve Isenberg