{"id":3019,"date":"2018-10-14T11:57:31","date_gmt":"2018-10-14T11:57:31","guid":{"rendered":"https:\/\/blog.paranoidprofessor.com\/?p=3019"},"modified":"2018-10-22T20:46:03","modified_gmt":"2018-10-22T20:46:03","slug":"safe-computing-passwords","status":"publish","type":"post","link":"https:\/\/blog.paranoidprofessor.com\/index.php\/2018\/10\/14\/safe-computing-passwords\/","title":{"rendered":"safe computing &#8211; passwords"},"content":{"rendered":"<p>Have you ever done something despite the knowledge that it isn&#8217;t really safe?\u00a0 This generic sentence\u00a0could be anything from jaywalking to unprotected sex.<\/p>\n<p>In my case, the situation is perhaps a both\u00a0more mundane and a 21st century problem.\u00a0 I do have quite a few email accounts that are used for different purposes.\u00a0 One of the ones that I used to catch spam should know better when it comes to security.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-3022 size-full\" src=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/oohay.png\" alt=\"\" width=\"380\" height=\"297\" srcset=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/oohay.png 380w, https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/oohay-300x234.png 300w\" sizes=\"(max-width: 380px) 100vw, 380px\" \/><\/p>\n<p>This login dialog looks very similar to many other login dialogs.\u00a0 The only interesting part is the checkbox &#8220;Angemeldet bleiben&#8221; which simply means that your user will stay logged in.\u00a0 This is not an unsurprising\u00a0feature for personal email accounts.\u00a0 If this value is stored on the computer or with the account it would make perfect sense.<\/p>\n<p>The insecure thing is that every time you go to this site this value is set to true.\u00a0 By default, your credentials will be stored on the computer, not a problem if this is your computer at home but an extremely poor policy if the computer is public used.<\/p>\n<h2>A proper solution<\/h2>\n<p>It is not a good solution to store the password or some token in a cookie on your computer.\u00a0 A much better solution would be to have the password memorized and use it each time.\u00a0 It is possible to keep a few passwords in your head but after a while, the number starts to exceed the memory of even the best person.<\/p>\n<p>Of course, it is possible to scribble your password on a sticky note or write it down in your notepad but if security is truly a requirement then storing the password list in an encrypted file is the best solution.<\/p>\n<h2>Keepassx<\/h2>\n<p>There are a lot of password managers that are available &#8211; it must be true as when I googled &#8220;password manager&#8221; it returned 480,000,000.\u00a0 There may not be that many but there are easily dozens of free and commercial versions in the Google Play store alone.<\/p>\n<p>Basically a password manager, sometimes referred to as a password safe is just a small application that collects passwords not too dissimilar to an address book for email addresses.<\/p>\n<p>The real trick is not finding a password manager that runs on your phone but one that fits how you best operate. In my case that was a password manager that is truly multi-platform.\u00a0 The usability of my password manager, Keepassx, is just fine on my smartphone.<\/p>\n<p>Multiplatform does not have to be a requirement.\u00a0 The only time I really wanted a multiplatform was when I had too many passwords and wanted to restructure how they were grouped.<\/p>\n<p>The reason that I ended up deciding on\u00a0keepassx\u00a0was it was possible to install the app on my smartphone but also to install the application on my Linux\u00a0Mint installation.<\/p>\n<p>It is possible to create a folder structure separate different aspects of your passwords.\u00a0 It is also possible to store any other important number.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3024\" src=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx.png\" alt=\"\" width=\"712\" height=\"537\" srcset=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx.png 712w, https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-300x226.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/p>\n<p>It is possible to create entries to store the simple user and password.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3025\" src=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry.png\" alt=\"\" width=\"712\" height=\"537\" srcset=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry.png 712w, https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry-300x226.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/p>\n<p>Keepassx has been made flexible enough to allow adding\u00a0other values as attributes.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3026\" src=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry2.png\" alt=\"\" width=\"712\" height=\"537\" srcset=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry2.png 712w, https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry2-300x226.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/p>\n<p>Finally, it is possible to assign cute little icons to your entries and folders.\u00a0 This is not just a fun feature but makes it possible to visually see which types of entries contain what types of data.<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-3027\" src=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry3.png\" alt=\"\" width=\"712\" height=\"537\" srcset=\"https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry3.png 712w, https:\/\/blog.paranoidprofessor.com\/wp-content\/uploads\/2018\/09\/keepassx-entry3-300x226.png 300w\" sizes=\"(max-width: 712px) 100vw, 712px\" \/><\/p>\n<p>I cannot recommend this software enough.\u00a0 it is easy to use on your phone but it also possible to copy the keepassx database to your computer and edit it without any difficulties.<\/p>\n<p><a href=\"https:\/\/community.linuxmint.com\/software\/view\/keepassx\" target=\"_blank\" rel=\"noopener\">https:\/\/community.linuxmint.com\/software\/view\/keepassx<\/a><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Have you ever done something despite the knowledge that it isn&#8217;t really safe?\u00a0 This generic sentence\u00a0could be anything from jaywalking to unprotected sex. In my case, the situation is perhaps a both\u00a0more mundane and a 21st century problem.\u00a0 I do &hellip; <a href=\"https:\/\/blog.paranoidprofessor.com\/index.php\/2018\/10\/14\/safe-computing-passwords\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[89],"tags":[17],"_links":{"self":[{"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/posts\/3019"}],"collection":[{"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/comments?post=3019"}],"version-history":[{"count":5,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/posts\/3019\/revisions"}],"predecessor-version":[{"id":3069,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/posts\/3019\/revisions\/3069"}],"wp:attachment":[{"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/media?parent=3019"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/categories?post=3019"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.paranoidprofessor.com\/index.php\/wp-json\/wp\/v2\/tags?post=3019"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}