The "To Keep Up" Wiki

A collection of information we find useful

User Tools

Site Tools


security_presentation

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
security_presentation [2022.10.09 17:14] Steve Isenbergsecurity_presentation [2025.02.25 18:43] (current) – [Caveat] Steve Isenberg
Line 85: Line 85:
 |Password Manager|Free, or paid. Can produce good passwords in one spot. Backupable.|Where are passwords stored. Possible breech if stored online. Loss or theft if stored in thumb drive or your computer.| |Password Manager|Free, or paid. Can produce good passwords in one spot. Backupable.|Where are passwords stored. Possible breech if stored online. Loss or theft if stored in thumb drive or your computer.|
 or there's this option,\\ credit to John McPherson of [[http://closetohome.com|Close to Home]]:\\  or there's this option,\\ credit to John McPherson of [[http://closetohome.com|Close to Home]]:\\ 
-{{:20211202solution.jpg?direct&350|}}+{{:20211202solution.jpg?direct&500|}}
  
 ====How to create hard-to-guess passwords==== ====How to create hard-to-guess passwords====
-If a human is going to guess the password then make it unhuman.  Consider: a password "safe" Here are some free alternatives.  From [[https://www.techradar.com/news/software/applications/the-best-password-manager-1325845|Tech RadarThe best free password manager 2019]] with updates I took from the application sites 20211129\\  +If a human is going to guess the password then make it unhuman.  Consider: a password "safe" Here are some alternatives, many are free or have free options.\\   
-Also see [[https://www.pcmag.com/roundup/331555/the-best-free-password-managers|PC Magazine's picks]]\\  +You can also do a DuckDuckGo (or Google if you're still using Google) search for "Best Password Managers" and look for those with recent information.
-Do a DuckDuckGo (or Google if you're still using Google) search for "Best Password Managers" and look for those with 2020 or 2021 information.+
  
 //All of these offer login and text note storage in a secure vault protected by your master password, and can generate (and store) strong passwords.// //All of these offer login and text note storage in a secure vault protected by your master password, and can generate (and store) strong passwords.//
  
 +//Following data updated 2/25/2025.  There are MANY other options, these are a few.  You should study all of the features and drawbacks of any option you consider or select as information may change.//
 ^Manager^Free version.  ^Paid version.  ^Cost.  ^platforms^ ^Manager^Free version.  ^Paid version.  ^Cost.  ^platforms^
-|[[https://www.lastpass.com/|www.lastpass.com]] |Access on one device type |1GB Secure cloud storage\\ Multi Factor Authentication\\ Contingency plan (loved one access in emergency) |Free for one device type; $3/month 1 user, $4/month 6 users (group and share items, family manager)|Win, Mac, Linux, Mobile| +|[[https://www.lastpass.com/|www.lastpass.com]] |Access on one device type (computer or mobile) |1GB encrypted cloud storage\\ Multifactor Authentication (MFA)\\ Contingency plan (loved one access in emergency) |Free for one device type; $36/yr 1 user, $48/yr 6 users (group and share items, family manager)|Browser based. Win, Mac, Linux, Mobile| 
-|[[https://www.dashlane.com/|www.dashlane.com]]|Up to 50 passwords, one device|unlimited passwords, unlimited devices, 1GB max| $4.99/mo billed annuallymultiple accounts $7.49/mo billed annually|Win, Mac, iOS, Android| +|[[https://www.dashlane.com/|www.dashlane.com]]|One device, secure sharing|unlimited devices, 1GB max, VPNFree (1 device25 passwords); $48/yr (many devices, passwords, and passkeys)|Browser based.  Win, Mac, iOS, Android| 
-|[[https://keepersecurity.com|keepersecurity.com]]|access on one device|unlimited device access|$2.91/month, $34.99 annually|Mac, Windows, Linux, iOS, Android| +|[[https://keepersecurity.com|keepersecurity.com]]|no free option|(Personal) no limits on storage, devices, sharing; (family) 5 vaults, 10GB secure storage|Personal $35/yrFamily $75/yr|App: Mac, Windows, Linux, iOS, Android; Browser extension
-|[[https://www.roboform.com/lp?frm=everywhere-offer&rec=TechRadar&dc=TR30&affid=a6277|www.roboform.com]]| |sync across devices, cloud backup, web access, all cost|<del>$23.88</del>$16.68/1yr, <del>$71.64</del>$45.14/3yr, <del>$119.40</del>$69.60/5yr|Windows, Mac, iOS, Android, Linux, Chrome OS+|[[https://www.roboform.com|www.roboform.com]]|one device |sync across devices, cloud backup, web access. Family plan is 5 users.|website lists prices in Pounds.\\ Personal: $16.68/1yr, $45.14/3yr, $69.60/5yr\\ Family: $33.40/1yr, $90.20/3yr, $139.30/5yr|Windows, Mac, iOS, Android, Linux, Chromebook, Browsers
-|[[https://bitwarden.com/|bitwarden.com]]|* passwords file kept online\\ *<fs small>(but you can install it on your own server)</fs>\\ *one file, share w/another | 1GB encrypted storage | $10/yr one user, $39.96/yr up to 6 users |Windows, Mac, Linux, iOS, Android| +|[[https://bitwarden.com/|bitwarden.com]]|Unlimited pw, passkeys, devices | 2FA, emergency access, share w/1-6 people | $10/yr one user, $40/yr up to 6 users |Windows, Mac, Linux, iOS, Android, Browsers
-|[[https://keepass.info/|keepass.info]]|* Can run from USB\\ * Many customizable options\\ * A little intimidating? You judge.|FOSS((FOSS=Free, Open-Source Software)) - there is no paid version -- all features in free version\\ Many ports, with different features and UI|Note, no cost. Does not provide place to store the Password Safe, that's up to you|Windows, Android, iPhone/iPad, Mac, Chromebook, Blackberry, Linux, and more| +|[[https://1password.com/]]|no free version, only paid, 2wk free trial|unlimited pw & devices, 1GB storage, 2FA.|Individual: $36/yr, Families (5 family members): $60/yr|Mac, Win, Linux, iOS, Android, Browsers| 
-|Others?|+|[[https://nordpass.com/]]|unlimited pw, notes also, credit cards|emergency access, multiple device access |Premium $20/yr, Family (6 accts) $44/yr|Win, Mac, Linux, Android, iOS, Browsers| 
 +|[[https://keepass.info/]]\\ [[https://keepassxc.org/download/|KeePassXC]]|* Can run from USB\\ * Many customizable options\\ * A little intimidating? You judge.|FOSS((FOSS=Free, Open-Source Software)) - there is no paid version -- all features in free version\\ Many ports, with different features and UI|Note, no cost. Does not provide place to store the Password Safe, that's up to you|Windows, Android, iPhone/iPad, Mac, Chromebook, Blackberry, Linux, and more| 
 +KeePassXC is a KeePass port, see Tech Radar's review: [[https://www.techradar.com/reviews/keepassxc]]. It's free but accepts donations. 
 + 
 +Refs:  
 +  * [[https://www.techradar.com/news/software/applications/the-best-password-manager-1325845|Tech Radar, The best free password manager 2019]] 
 +  * [[https://www.pcmag.com/roundup/331555/the-best-free-password-managers|PC Magazine's picks]] 
 +  * [[https://www.pcmag.com/picks/the-best-password-managers]] 
 +  * [[https://www.cnet.com/tech/services-and-software/best-password-manager/]] 
 +  * [[https://www.techradar.com/best/password-manager]] a good site for reviews of offerings 
 +  * [[https://www.techradar.com/reviews/keepassxc]] TechRadar's review of KeePassXC 
 + 
 +====My Recommendations==== 
 +If you're looking for a fast answer...here's my thoughts 
 +  - KeePass on iCloud or Box.  (You're in full control of your passwords and who can see them and are relatively immune to data breaches.) 
 +    * You need to be willing to learn to use KeePass and set up cloud storage. 
 +  - BitWarden.  Free version is a good solution and it's turnkey. 
 +    * Possibility of a breach, see 'Caveat' below. 
 + 
 +I am interested in your thoughts on these, and other, possibilities you like! 
  
 ====Caveat==== ====Caveat====
Line 117: Line 136:
     * On iPhone and iPad: KeePass Touch     * On iPhone and iPad: KeePass Touch
     * On Android:     * On Android:
-    * On Windows:+    * On Windows: KeePassXC
   * Store password file in iCloud   * Store password file in iCloud
   * Copy password file to local Document storage on each device (so it's available when there's no internet)   * Copy password file to local Document storage on each device (so it's available when there's no internet)
-  * Copy password file to Dropbox, pCloud (as backup)+  * Copy password file to Box (free cloud storageand Dropbox, for redundancy. 
  
 To note: To note:
Line 131: Line 150:
   * Available on all my devices   * Available on all my devices
   * One password to remember   * One password to remember
-  * I can use long and complex passwords+  * I can use long and complex passwords (and KeePass helps me create them and tells how secure they are) 
 +  * Can keep a history of past passwords 
 +  * I can store other information in the vault, like those recovery passwords "what's your father's middle name" so I can use a fake un-guessable answer
  
 Using a password manager: Using a password manager:
-    * you can create quite long and complex passwords+    * easy to create long and complex passwords 
 +    * you can use long and complex passwords
     * you can create secure passwords and not have to remember all of them     * you can create secure passwords and not have to remember all of them
     * you only have to remember One password     * you only have to remember One password
 +    * you can store your password file encrypted in multiple places including USB drives so it's unlikely to be lost
     * you have all of your important access information in one spot, the encrypted file     * you have all of your important access information in one spot, the encrypted file
-      * (your next of kin would likely find this useful)+      * //your next of kin would likely find this useful//
 ====More About KeePass==== ====More About KeePass====
 //Note that many of these features can be handled/provided by other password manager software, free and at cost// //Note that many of these features can be handled/provided by other password manager software, free and at cost//
Line 178: Line 201:
    
   * I use a DB entry to log changes   * I use a DB entry to log changes
-    * "Last changed 20211201.2007(Dec 22021, 8:07pm) +    * "Last changed 20221009.1817meaning October 92022 at 6:17pm 
-    * Enter change(s) made, eg: "1201: updated CCS entry, new password Kohls"+    * Enter change(s) made, eg: "0921: updated CCS entry, new password Kohls"
     * This I do manually     * This I do manually
     * Helps me synchronize databases     * Helps me synchronize databases
Line 185: Line 208:
   * I use KeePass application to create new entries and login passwords   * I use KeePass application to create new entries and login passwords
     * Passwords typically 14+ characters (upper/lower case and numbers)     * Passwords typically 14+ characters (upper/lower case and numbers)
-    * KeePass tells me if a password is/isn't secure+    * KeePass tells me how secure given password is
  
 Here is a possible password I might use: ''cqLbq2NHcuNmgU'' -- 14 characters, upper and lower case letters, and at least one number.  This one has entropy 82.06 which is deemed "good".   Here is a possible password I might use: ''cqLbq2NHcuNmgU'' -- 14 characters, upper and lower case letters, and at least one number.  This one has entropy 82.06 which is deemed "good".  
Line 200: Line 223:
  
 ====Next: Live demo of KeePass==== ====Next: Live demo of KeePass====
 +on smi macbook
 +
 +  * open, select PasswordExample.kbdx pw=1234
 +  * Save as CSV and look
 +  * Save as HTML and look
 +  * Database>Reports
 ====Questions and Answers==== ====Questions and Answers====
  
security_presentation.1665350077.txt.gz · Last modified: 2022.10.09 17:14 by Steve Isenberg