<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
     xmlns:admin="http://webns.net/mvcb/"
     xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">
	<channel> 

	<title>Comments on: Online password storage, crazy or stupid?</title>
	<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid/</link>
	<description>Comments on Ask MetaFilter post Online password storage, crazy or stupid?</description>
	<pubDate>Tue, 04 Sep 2007 08:22:38 -0800</pubDate>
	<lastBuildDate>Tue, 04 Sep 2007 08:22:38 -0800</lastBuildDate>
	<language>en-us</language>
	<docs>http://blogs.law.harvard.edu/tech/rss</docs>
	<ttl>60</ttl>

	<item>
		<title>Question: Online password storage, crazy or stupid?</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid</link>	
		<description>Where can I store my passwords online safely? &lt;br /&gt;&lt;br /&gt;  95% of the places I need passwords are on the web, so it is the most practical solution for me. Additionally I frequently find myself on different OSes and computers that are not mine. &lt;br&gt;
&lt;br&gt;
&lt;a href=&quot;https://www.agatra.com/&quot;&gt;Agatra&lt;/a&gt; seems to be what I want but I only know what I read in the FAQ. I found them through a Google search so I really don&apos;t know anything about them. &lt;br&gt;
&lt;br&gt;
Does anyone have any recommendations? Is anyone else doing this? Am I crazy or stupid for thinking about trying this? How much trouble would I be in if the password site was compromised? I assume they would be storing my passwords as hashes (or whatever) so I wouldn&apos;t be too exposed if they were compromised (again assuming they are actually doing what they claim).</description>
		<guid isPermaLink="false">post:ask.metafilter.com,2007:site.70745</guid>
		<pubDate>Tue, 04 Sep 2007 08:18:56 -0800</pubDate>
		<dc:creator>The Radish</dc:creator>
		
			<category>web</category>
		
			<category>based</category>
		
			<category>password</category>
		
			<category>storage</category>
		
	</item> <item>
		<title>By: fusinski</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055369</link>	
		<description>Nowhere.&lt;br&gt;
&lt;br&gt;
Seriously.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055369</guid>
		<pubDate>Tue, 04 Sep 2007 08:22:38 -0800</pubDate>
		<dc:creator>fusinski</dc:creator>
	</item><item>
		<title>By: radgardener</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055373</link>	
		<description>http://ask.metafilter.com/33609/How-can-I-store-my-passwords-online-securely&lt;br&gt;
&lt;br&gt;
This previous AskMetafilter thread settled on GMail.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055373</guid>
		<pubDate>Tue, 04 Sep 2007 08:24:28 -0800</pubDate>
		<dc:creator>radgardener</dc:creator>
	</item><item>
		<title>By: damn dirty ape</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055392</link>	
		<description>This is the best idea in the thread: &lt;a href=&quot;http://ask.metafilter.com/33609/How-can-I-store-my-passwords-online-securely#523715&quot;&gt;Write them down and put them in your wallet.&lt;/a&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055392</guid>
		<pubDate>Tue, 04 Sep 2007 08:32:36 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item><item>
		<title>By: Burhanistan</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055401</link>	
		<description>The best advice I think I&apos;ve seen on this is that it is ok to write them on paper, but then you should guard that paper as if it were a piece of monetary currency with a large denomination.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055401</guid>
		<pubDate>Tue, 04 Sep 2007 08:36:13 -0800</pubDate>
		<dc:creator>Burhanistan</dc:creator>
	</item><item>
		<title>By: damn dirty ape</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055412</link>	
		<description>Also you can add a layer of trickery into the paper. Lets say all your passwords start with your dogs name. Instead of writing &quot;Mittens123&quot; you can just write m123 as the password field.  instead of writing www.chase.com  username: 8377127127 password: Mittens666 you can write:&lt;br&gt;
&lt;br&gt;
bank, username social, pass m666&lt;br&gt;
&lt;br&gt;
In other words treat it like crib notes.  Keep the real list at home safely locked up or buried in a layer of encryption.&lt;br&gt;
&lt;br&gt;
The paper should be useless to a non-determined attacker.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055412</guid>
		<pubDate>Tue, 04 Sep 2007 08:41:39 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item><item>
		<title>By: Leon</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055422</link>	
		<description>USB key on a keyring, with a copy of Firefox Portable. Of course, if you lose your keys you&apos;re screwed.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055422</guid>
		<pubDate>Tue, 04 Sep 2007 08:45:19 -0800</pubDate>
		<dc:creator>Leon</dc:creator>
	</item><item>
		<title>By: Freaky</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055428</link>	
		<description>If you&apos;re expecting to get the passwords back, they won&apos;t be storing them as hashes, since they&apos;re non-reversible.  They could be stored encrypted with you just giving them a master password to decrypt them, which may be &quot;secure enough&quot; if you have sufficient trust in them and/or your passwords aren&apos;t *that* critical.&lt;br&gt;
&lt;br&gt;
Something like &lt;a href=&quot;http://www.angel.net/~nic/passwdlet.html&quot;&gt;this&lt;/a&gt; might be a good solution.  It&apos;s a public chunk of Javascript you can bookmark; you have the browser execute it and feed it a master password, and it generates a site-specific password for whatever site you&apos;re on using a cryptographic hash function.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055428</guid>
		<pubDate>Tue, 04 Sep 2007 08:48:56 -0800</pubDate>
		<dc:creator>Freaky</dc:creator>
	</item><item>
		<title>By: fogster</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055430</link>	
		<description>I agree with putting them in your wallet. Now I have a Palm app to do it (&lt;a href=&quot;http://gnukeyring.sourceforge.net/&quot;&gt;Keyring&lt;/a&gt;), but in the past, I carried a short list of passwords and PINs in my wallet. I figured if I lost my wallet, having someone know my e-mail password was the least of my problems.&lt;br&gt;
&lt;br&gt;
A few things you can do to make it more secure:&lt;br&gt;
&lt;br&gt;
- Don&apos;t write down what the passwords go to.&lt;br&gt;
&lt;br&gt;
- If you do write down what they go do, don&apos;t put them in the right order. (Example: in high school, I had to remember three different combinations. I listed all three on a sheet of paper, and labeled each one, but the actual combination was the one on the line &lt;i&gt;below&lt;/i&gt; the lock name.&lt;br&gt;
&lt;br&gt;
- Disguise them. PIN numbers become phone numbers in the local area. (E.g., if your bank code is 1234, you might have &quot;Work fax number: 555-1234&quot; scrawled on a slip of paper and stashed in the back of your wallet.) Or, subtract one from them, and you could even put &quot;ATM PIN Code: 1233.&quot; Only you would think to add one to the number.&lt;br&gt;
&lt;br&gt;
But really, I think even if you don&apos;t do any of these little &apos;tricks,&apos; a slip of paper in your wallet is pretty secure.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055430</guid>
		<pubDate>Tue, 04 Sep 2007 08:49:57 -0800</pubDate>
		<dc:creator>fogster</dc:creator>
	</item><item>
		<title>By: The Radish</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055439</link>	
		<description>Let me clarify a bit. The piece of paper thing seems like a hassle, it seems kludgey and I&apos;ll loose it, or more likely send it through the washing machine. Additionally I&apos;m making an effort to rotate my passwords more frequently.  This piece of paper could get unwieldily pretty quick as I change my passwords. The problem with a USB key (or some mobile phone app) is if I loose or beak it  I&apos;m screwed. The idea of having it online gives me some reassurance that it will always be there. The G-mail idea for some reason makes me really really uneasy.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055439</guid>
		<pubDate>Tue, 04 Sep 2007 09:00:54 -0800</pubDate>
		<dc:creator>The Radish</dc:creator>
	</item><item>
		<title>By: fogster</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055449</link>	
		<description>The problem is that storing passwords at any online service is inherently unsafe. You have to trust that, not only will no one break into the account, but also that the site admin is trustworthy. You&apos;re essentially trusting some random website with all of your passwords.&lt;br&gt;
&lt;br&gt;
Even if I hosted the script that stored them, I&apos;d worry about security flaws and someone obtaining access. The advantage with something like an e-mail account with the &apos;big guys&apos; (GMail, Yahoo, Hotmail...) is that it&apos;s rather unlikely that they&apos;ll &apos;turn bad&apos; and start reading your stuff.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055449</guid>
		<pubDate>Tue, 04 Sep 2007 09:07:57 -0800</pubDate>
		<dc:creator>fogster</dc:creator>
	</item><item>
		<title>By: Nelson</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055451</link>	
		<description>For computers that are mine, I store my passwords in Firefox and use Google Desktop to sync them between computers. I also use &lt;a href=&quot;https://www.pwdhash.com/&quot;&gt;pwdhash&lt;/a&gt; as a simple way to securely use the same password on a lot of sites. pwdhash is a bit of a pain without the Firefox extension, but it&apos;s simple and works.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055451</guid>
		<pubDate>Tue, 04 Sep 2007 09:08:54 -0800</pubDate>
		<dc:creator>Nelson</dc:creator>
	</item><item>
		<title>By: bonaldi</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055455</link>	
		<description>If your passwords make sense to you, just keep in plaintext what that meaning is. So if your password is hon3ybe4r after your first teddy bear, just put &quot;numbered first teddy&quot; in the document. Then it doesn&apos;t need to be kept secret.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055455</guid>
		<pubDate>Tue, 04 Sep 2007 09:11:56 -0800</pubDate>
		<dc:creator>bonaldi</dc:creator>
	</item><item>
		<title>By: electriccynic</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055473</link>	
		<description>Personally, I just have a personal seven-character code (eg Date of Birth, zipcode, whatever), and append the middle two-letters of the website to the end or beginning, or scatter it throughout the password.&lt;br&gt;
&lt;br&gt;
Ta-da - an ever-changing password for each website which only you know, and can easily remember.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055473</guid>
		<pubDate>Tue, 04 Sep 2007 09:21:49 -0800</pubDate>
		<dc:creator>electriccynic</dc:creator>
	</item><item>
		<title>By: damn dirty ape</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055544</link>	
		<description>Ok, there&apos;s a difference between storage and easy retrieval. If you just want to store this thing you can make a truecrypt file with a big password.&lt;br&gt;
&lt;br&gt;
If you just want to make this incredibly easy to retrieve make a text file with all your passwords.  Zip it.  Use zip&apos;s built in password protection.  Choose a VERY GOOD password (note: it ignores anything past 8 characters, so make the first 8 count*).  Any computer, anywhere can open an encrypted zip file.  Windows, linux, and osx do this natively.  Put the zip file on your webspace.  Download it and open it as needed.  Make changes as needed.  When done wipe it from the computer (shift delete on windows). dOnt leave it in the recycling bin.&lt;br&gt;
&lt;br&gt;
Thats not a perfect solution but good enough for everyday users.&lt;br&gt;
&lt;br&gt;
*Make the first 8 count:&lt;br&gt;
Bad password: dogfood12374662178247!11($*@&lt;br&gt;
good password: !d0gf@@d</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055544</guid>
		<pubDate>Tue, 04 Sep 2007 10:04:56 -0800</pubDate>
		<dc:creator>damn dirty ape</dc:creator>
	</item><item>
		<title>By: geminus</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055563</link>	
		<description>&lt;a href=&quot;http://www.clipperz.com/&quot;&gt;Clipperz&lt;/a&gt;? (Disclaimer: never used it, probably wouldn&apos;t either... But it does exactly what you want. YMMV).&lt;br&gt;
&lt;br&gt;
Surprised that no one has suggested &lt;a href=&quot;http://keepass.info/download.html&quot;&gt;Keepass&lt;/a&gt; yet. There are ports to Linux/Mac/Palm although it is primarily a Windows application.&lt;br&gt;
&lt;br&gt;
There is also a portable version which will work from your USB key.&lt;br&gt;
&lt;br&gt;
I hate the idea of online storage for passwords, but I would consider mailing the encrypted password file to myself on Gmail. My master password is reasonably lengthy and not easily guessable or cracked (I hope).</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055563</guid>
		<pubDate>Tue, 04 Sep 2007 10:26:48 -0800</pubDate>
		<dc:creator>geminus</dc:creator>
	</item><item>
		<title>By: philomathoholic</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055602</link>	
		<description>Instead of storing it in Firefox Portable, or in a Truecrypt vault, you could store it in an &lt;a href=&quot;http://projects.metafilter.com/837/Message-Vault&quot;&gt;encrypted message vault&lt;/a&gt;. It&apos;s just an html file with javascript (that every browser on every OS can read). If you lose your USB key it&apos;s still encrypted with 128-bit AES, so you won&apos;t be screwed.&lt;br&gt;
&lt;br&gt;
Or you can store the vault in your webspace somewhere and download it to wherever you need it. The only thing that will be left in the browser&apos;s cache is a secured webpage (that other people can&apos;t read without the password). Or you can store it in Gmail, so that it isn&apos;t world accessible (so that people aren&apos;t trying to hack into the file). Be sure to still set a strong password for it though.&lt;br&gt;
&lt;br&gt;
Personally, what I have set up is a wiki on my home computer for this and other stuff. Every time I need something from it, I create an ssh tunnel to the server and view it with portable firefox. This would work with linux or osx too, because all I need is ssh and a browser.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055602</guid>
		<pubDate>Tue, 04 Sep 2007 10:50:04 -0800</pubDate>
		<dc:creator>philomathoholic</dc:creator>
	</item><item>
		<title>By: philomathoholic</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055613</link>	
		<description>For an actual online service, try &lt;a href=&quot;https://kyps.no-ip.org/&quot;&gt;kyps&lt;/a&gt;. It&apos;s designed to circumvent key loggers and whatnot.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055613</guid>
		<pubDate>Tue, 04 Sep 2007 10:58:50 -0800</pubDate>
		<dc:creator>philomathoholic</dc:creator>
	</item><item>
		<title>By: a robot made out of meat</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055650</link>	
		<description>Putting sensitive data on someone else&apos;s computer is inherently risky.  That said, I tend to put passwords in a plain text file (without notes on what they go to), then encrypt it with an easily available piece of software.  I can back up that encrypted file in as many places as I like; the password on it tends to be super strong.  EG, my server, an external HD, a flash key, and a multi session disk.&lt;br&gt;
&lt;br&gt;
For my flash drive I tend to use dscrypt; for the things that I leave on my server and access remotely, I use pgp/gpg.  There probably exists a nice portable windows gpg, I just don&apos;t know what it is.  I&apos;m unlikely to lose all the backup media at once.  I can take them with me anywhere, or ssh to my server if I somehow don&apos;t have my key.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055650</guid>
		<pubDate>Tue, 04 Sep 2007 11:28:38 -0800</pubDate>
		<dc:creator>a robot made out of meat</dc:creator>
	</item><item>
		<title>By: theora55</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055712</link>	
		<description>I use a standard password, which is a word cut in half, with numbers inserted, i.e., geo11rge, geo96rge, etc.  I keep a list of sites, with just the number, i.e., mefi=66.  Some passwords I email to gmail.  &lt;small&gt;George was a great dog we had when I was a kid, and is not my password.  &lt;/small&gt;</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055712</guid>
		<pubDate>Tue, 04 Sep 2007 12:27:43 -0800</pubDate>
		<dc:creator>theora55</dc:creator>
	</item><item>
		<title>By: dmd</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1055867</link>	
		<description>Another hash service: &lt;a href=&quot;http://passwordmaker.org/&quot;&gt;Passwordmaker&lt;/a&gt;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1055867</guid>
		<pubDate>Tue, 04 Sep 2007 14:25:59 -0800</pubDate>
		<dc:creator>dmd</dc:creator>
	</item><item>
		<title>By: nicwolff</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1056237</link>	
		<description>Hey, that&apos;s my password generator that Freaky linked to up there; it really solves this problem well. But if you&apos;re just starting with it you should use &lt;a href=&quot;http://angel.net/~nic/passwd.sha1.1a.html&quot;&gt;this improved version&lt;/a&gt; which uses SHA-1 instead of MD5 for hashing, base64 instead of hex for encoding, and adds &quot;1a&quot; to the end of all passwords so they work at sites that require a letter and a number.&lt;br&gt;
&lt;br&gt;
(All those other password hash services got the idea from me! &lt;a href=&quot;http://weblog.infoworld.com/udell/2005/05/03.html&quot;&gt;Here&apos;s an old InfoWorld column&lt;/a&gt; that includes a screencast showing how it works.)</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1056237</guid>
		<pubDate>Tue, 04 Sep 2007 20:58:19 -0800</pubDate>
		<dc:creator>nicwolff</dc:creator>
	</item><item>
		<title>By: CuJoe</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1056348</link>	
		<description>I just recently started using Clipperz.com and I like it.  From what I understand from using it, they just store a file that is locally (done in your browser and not on the server) encrypted/decrypted.  The only danger would be a keylogger, which would always be a danger with using a computer to do anything with passwords.  A quote from their site says &quot;Clipperz lets you submit confidential information into your browser, but your data are locally encrypted by the browser itself before being uploaded. The key for the encryption processes is a passphrase that never gets sent or saved to the server! Therefore no one except you can access your data.&quot;&lt;br&gt;
&lt;br&gt;
They offer up their code for you to download to check it for flaws, security or otherwise (http://www.clipperz.com/learn_more/reviewing_the_code).&lt;br&gt;
&lt;br&gt;
Most useful for me is the fact that you can download an offline copy where your stored info is stored in its encrypted state into an html file that works exactly like the website with the exception that you can&apos;t store new info.  Whenever I make an update to my info, I create a new offline copy and Gmail it to myself.&lt;br&gt;
&lt;br&gt;
I am in no way affiliated with the site other than as a user.  They were just the first site that seemed to do secure info management somewhat securely in a manner useful to me.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1056348</guid>
		<pubDate>Wed, 05 Sep 2007 01:48:37 -0800</pubDate>
		<dc:creator>CuJoe</dc:creator>
	</item><item>
		<title>By: philomathoholic</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1058251</link>	
		<description>FYI, Cujoe: What you describe about saving the file, is exactly what the html file I linked to does. Except, it&apos;ll let you add new info also. To review the code, just &apos;View Source&apos;.</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2007:site.70745-1058251</guid>
		<pubDate>Thu, 06 Sep 2007 17:01:36 -0800</pubDate>
		<dc:creator>philomathoholic</dc:creator>
	</item><item>
		<title>By: abpsoftware</title>
		<link>http://ask.metafilter.com/70745/Online-password-storage-crazy-or-stupid#1326948</link>	
		<description>&lt;a href=&quot;http://www.NeedMyPassword.com&quot; title=&quot;Online Password Storage&quot;&gt;NeedMyPassword.com&lt;/a&gt; is the absolute best site for password storage.  I am not just saying that because I am the developer.  It is really easy to use and you can change the setting to &quot;Super Secure&quot; and no one is going to get in.&lt;br&gt;&lt;br&gt;Give it a try, it is absolutely free!</description>
		<guid isPermaLink="false">comment:ask.metafilter.com,2008:site.70745-1326948</guid>
		<pubDate>Fri, 02 May 2008 09:28:41 -0800</pubDate>
		<dc:creator>abpsoftware</dc:creator>
	</item>
	</channel>
</rss>
