<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Keeping Track of Passwords</title>
	<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords/</link>
	<description>Comments on Ask MetaFilter post Keeping Track of Passwords</description>
	<pubDate>Sat, 31 Jan 2004 11:23:14 -0800</pubDate>
	<lastBuildDate>Sat, 31 Jan 2004 11:23:14 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Keeping Track of Passwords</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords</link>	
		<description>What&apos;s the best way to keep track of an escalating number of logins and passwords? For the web, there&apos;s Opera&apos;s magic wand, but what about hosting accounts, ftp servers, ATM PINs, etc? Encrypted text file on the desktop? Scribbled note under the pillow? How do you manage (and hide) your password library?</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2004:site.5030</guid>
		<pubDate>Sat, 31 Jan 2004 11:08:59 -0800</pubDate>
		<dc:creator>muckster</dc:creator>
		
			<category>management</category>
		
			<category>password</category>
		
			<category>authentication</category>
		
			<category>library</category>
		
			<category>information</category>
		
			<category>manager</category>
		
			<category>software</category>
		
	</item> <item>
		<title>By: mcsweetie</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110911</link>	
		<description>I usually use one of 2 different user names/logins/etc and one of 3 different passwords for just about everything, so that I can usually get access to things in under 6 tries.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110911</guid>
		<pubDate>Sat, 31 Jan 2004 11:23:14 -0800</pubDate>
		<dc:creator>mcsweetie</dc:creator>
	</item><item>
		<title>By: vacapinta</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110914</link>	
		<description>I have two different types of passwords:&lt;br&gt;
&lt;br&gt;
secure passwords: like for server logins, online banking etc. These are all distinct and i have them written down on paper only in the rare case that i forget them (usually just rely on memory) &lt;br&gt;
&lt;br&gt;
unsecure passwords. this is what i use for logons to sites that ask for registration, games, metafilter. I use an algorithm thats easy to remember that incorporates a base rule plus the name of the site. &lt;br&gt;
&lt;br&gt;
For example (this is not the algorithm but a simpler example): if the rule is use the 1st and 3rd letters of the site name and replace them in the base then, if the base is &apos;tijae45&apos; the password i use here on metafilter would be &apos;mitae45&apos;&lt;br&gt;
&lt;br&gt;
As i said, thats not my rule (its a bit more subtle) and thats not my base but you get the picture. For each site i have a different password and yet all i need to remember is how to &apos;generate&apos; it.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110914</guid>
		<pubDate>Sat, 31 Jan 2004 11:32:17 -0800</pubDate>
		<dc:creator>vacapinta</dc:creator>
	</item><item>
		<title>By: substrate</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110915</link>	
		<description>My method to handle the madness is this:&lt;br&gt;
&lt;br&gt;
Anyplace that can conceivably be tied to money gets a unique random password. I never ever fill in the &quot;What&apos;s your mother&apos;s maiden name fields&quot; for hints because it&apos;s a trivial social hacking to get that information. I don&apos;t go and open up bank accounts or accounts with online vendors very often so this is manageable. &lt;br&gt;
&lt;br&gt;
For places like metafilter I have the same password and a couple of different user names. The most that can happen is somebody posts something I wouldn&apos;t, I can get over it.&lt;br&gt;
&lt;br&gt;
I also have a couple dozen other accounts and passwords.&lt;br&gt;
&lt;br&gt;
I keep everything in a plain text file on my home machine but it&apos;s encrypted with &lt;a href=http://gnupg.org/&gt;GPG&lt;/a&gt;. If need be I can ssh to my home machine and grab the password I need.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110915</guid>
		<pubDate>Sat, 31 Jan 2004 11:34:24 -0800</pubDate>
		<dc:creator>substrate</dc:creator>
	</item><item>
		<title>By: tomorama</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110924</link>	
		<description>I keep everything in a password-protected access database.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110924</guid>
		<pubDate>Sat, 31 Jan 2004 11:56:47 -0800</pubDate>
		<dc:creator>tomorama</dc:creator>
	</item><item>
		<title>By: rhyax</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110927</link>	
		<description>I use apple&apos;s keychain program</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110927</guid>
		<pubDate>Sat, 31 Jan 2004 12:16:41 -0800</pubDate>
		<dc:creator>rhyax</dc:creator>
	</item><item>
		<title>By: nicwolff</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110934</link>	
		<description>I MD5 hash the name of the domain or server or whatever with my secret word to generate a unique password for each site using &lt;a href=&quot;http://angel.net/~nic/passwd.html&quot;&gt;this little Javascript thing&lt;/a&gt; I wrote.&lt;br&gt;
&lt;br&gt;
That way I just have to remember one master password, and each site or server gets a different password so I don&apos;t have to worry about renegade admins borrowing my identity. And I can use it from any computer anywhere on the Net, and I don&apos;t have to worry about losing a password list.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110934</guid>
		<pubDate>Sat, 31 Jan 2004 12:27:52 -0800</pubDate>
		<dc:creator>nicwolff</dc:creator>
	</item><item>
		<title>By: majick</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110938</link>	
		<description>Tally up another vote for the plain text file encrypted with GPG.  It&apos;s not &lt;i&gt;that&lt;/i&gt; secure, since the private key resides on the same spindle as the text in question instead of on removable media I keep on my person at all times, but since all I &lt;b&gt;must&lt;/b&gt; remember is my pass phrase, it&apos;s good enough for me.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110938</guid>
		<pubDate>Sat, 31 Jan 2004 12:41:12 -0800</pubDate>
		<dc:creator>majick</dc:creator>
	</item><item>
		<title>By: jessamyn</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110946</link>	
		<description>I have a two-tiered password system. Insecure, for logging in to the NYTimes, Friendster and whatnot, and secure for banking, paypal, Ebay etc. The insecure one is one of two. The secure one is one of four that rotate OR when absolutely necessary to have one that is unique [often sites have special requirements that render my other ones unusable] I use a mnemonic to make new ones using the first letters of whatever song line is stuck in my head at the time, alternating upper/lower case, special character at the end. So, The Goats song that has the line that goes &quot;I&apos;m not your typical American&quot; becomes iNyTa! and I can write, in plaintext, either the song artist and title, or, more likely, the first two characters in some unobtrusive way that doesn&apos;t say &quot;THIS IS A PASSWORD HINT&quot;. New York Times - iN for example. In any case, I never write the password down, I only leave myself clues to it, based on weird &quot;only I know what I am talking about&quot; codes. I am pretty lucky that I can usually get my first name as a login nearly anyplace with less than a million users.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110946</guid>
		<pubDate>Sat, 31 Jan 2004 13:18:05 -0800</pubDate>
		<dc:creator>jessamyn</dc:creator>
	</item><item>
		<title>By: signal</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110956</link>	
		<description>keyboard typing patterns.&lt;br&gt;
that&apos;s all I&apos;m gonna say.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110956</guid>
		<pubDate>Sat, 31 Jan 2004 14:01:02 -0800</pubDate>
		<dc:creator>signal</dc:creator>
	</item><item>
		<title>By: turbodog</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110966</link>	
		<description>I&apos;ve been using MultiPad for quite a while. Basically it encrypts text notes into a simple hierarchical structure. It hasn&apos;t been updated in years, though, and its &lt;a href=&quot;http://welcome.to/emmental&quot;&gt;homepage&lt;/a&gt;&lt;/a&gt; seems to be gone.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110966</guid>
		<pubDate>Sat, 31 Jan 2004 14:21:11 -0800</pubDate>
		<dc:creator>turbodog</dc:creator>
	</item><item>
		<title>By: keswick</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110976</link>	
		<description>Palm Tungsten. eWallet. Any questions? :)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110976</guid>
		<pubDate>Sat, 31 Jan 2004 14:49:23 -0800</pubDate>
		<dc:creator>keswick</dc:creator>
	</item><item>
		<title>By: yerfatma</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110977</link>	
		<description>&lt;a href=&quot;http://sourceforge.net/projects/passwordsafe/&quot;&gt;Password Safe.&lt;/a&gt; As for Access databases, I would just mention that MS password protection is &lt;a href=&quot;http://lastbit.com/access/default.asp&quot;&gt;pretty crap&lt;/a&gt; at best.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110977</guid>
		<pubDate>Sat, 31 Jan 2004 14:55:08 -0800</pubDate>
		<dc:creator>yerfatma</dc:creator>
	</item><item>
		<title>By: vacapinta</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110981</link>	
		<description>That&apos;s awesome, nicwolff. I think I&apos;m gonna start using your method (for &apos;insecure&apos; passwords) The problem I see with all the &apos;encrypted file on a computer&apos; options is that its not very portable.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110981</guid>
		<pubDate>Sat, 31 Jan 2004 15:12:14 -0800</pubDate>
		<dc:creator>vacapinta</dc:creator>
	</item><item>
		<title>By: Alylex</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110995</link>	
		<description>Oh, but it is portable with a PDA. I use SplashID, which syncs nicely between Mac and Palm.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110995</guid>
		<pubDate>Sat, 31 Jan 2004 16:14:25 -0800</pubDate>
		<dc:creator>Alylex</dc:creator>
	</item><item>
		<title>By: Tubes</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110996</link>	
		<description>I use a swell little free utility called &lt;a href=&quot;http://www.passkeeper.com&quot;&gt;Passkeeper&lt;/a&gt; (Windows). It&apos;s tiny, quick, stable &amp;amp; handy.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110996</guid>
		<pubDate>Sat, 31 Jan 2004 16:20:16 -0800</pubDate>
		<dc:creator>Tubes</dc:creator>
	</item><item>
		<title>By: _sirmissalot_</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#110998</link>	
		<description>I write them down in a notebook next to my computer.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-110998</guid>
		<pubDate>Sat, 31 Jan 2004 16:21:34 -0800</pubDate>
		<dc:creator>_sirmissalot_</dc:creator>
	</item><item>
		<title>By: majick</title>
		<link>http://ask.metafilter.com/5030/Keeping-Track-of-Passwords#111036</link>	
		<description>&lt;i&gt;&quot;not very portable.&quot;&lt;/i&gt;&lt;br&gt;
&lt;br&gt;
A legitimate concern, and one that should inform your decision how to protect your passwords and key store.  For me, I&apos;m rarely in a place where I can&apos;t SSH to my data store from a semitrusted client, and if I am, it&apos;s exceedingly unlikely that I&apos;ll need access to my password list or be willing to expose my passwords to an untrusted host.&lt;br&gt;
&lt;br&gt;
If portability were a requirement for me, though, I&apos;d certainly be looking into one of these PDA based schemes.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2004:site.5030-111036</guid>
		<pubDate>Sat, 31 Jan 2004 19:49:10 -0800</pubDate>
		<dc:creator>majick</dc:creator>
	</item>
	</channel>
</rss>
