{"id":12225,"date":"2018-05-07T14:30:19","date_gmt":"2018-05-07T22:30:19","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2018\/05\/07\/news-5994\/"},"modified":"2018-05-07T14:30:19","modified_gmt":"2018-05-07T22:30:19","slug":"news-5994","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/05\/07\/news-5994\/","title":{"rendered":"I&#8217;m done with remembering passwords"},"content":{"rendered":"<p><strong>Credit to Author: Alex Perekalin| Date: Mon, 07 May 2018 15:05:42 +0000<\/strong><\/p>\n<p>Twitter <a target=\"_blank\" href=\"https:\/\/threatpost.com\/twitter-urges-users-to-change-passwords-due-to-glitch\/131693\/\">recently reported<\/a> a glitch that caused passwords to be accidentally stored in an internal log without a <a target=\"_blank\" href=\"https:\/\/securelist.com\/threats\/encryption-glossary\/\">mask<\/a> \u2014 in plain text. The company said that there were no signs of hacking, the storage error had been fixed, and passwords did not end up in the wrong hands. There probably wasn&#8217;t a leak, they said, but they advised changing your password in any case. And the new password, as we all know, should be strong and unique.<a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/05\/07110113\/remembering-passwords-is-dead-featured.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2018\/05\/07110113\/remembering-passwords-is-dead-featured.jpg\" alt=\"\" width=\"1460\" height=\"958\" class=\"aligncenter size-full wp-image-22335\" \/><\/a><\/p>\n<p>For me and many others, this was painful. I store passwords in my head and nowhere else. To make them easy to remember yet strong, I use my own <a target=\"_blank\" href=\"https:\/\/www.kaspersky.com\/blog\/false-perception-of-it-security-passwords\/7036\/\">technique<\/a> to generate them. I start with one keyword, add a few digits, change the letter case in certain parts, and sprinkle in some special characters and a few more symbols related to the service I&#8217;m using. That way the password is unique, quite long and complex, yet memorable.<\/p>\n<p>The technique has long served me well \u2014 no matter how many services I use, I can still recall the passwords even for ones I seldom use because I know my password-generating technique. But over time my approach has run into a problem: Services leak users&#8217; passwords every so often, thereby forcing people to change them.<\/p>\n<p>Unfortunately, my technique provides only one password for each service. To create another means tweaking the technique, which can make the new password much harder to recall. Either a new keyword is needed or a different set of digits, or I could use some other letters related to the service (for example, if before it was the first two characters of the company&#8217;s name and the last two characters of the service name, now I might use three characters instead).<\/p>\n<p>Changing the technique is a major problem for the old gray cells, because some passwords are generated with the old method, and others with the new one. And if like me you&#8217;ve been using this approach for more than a few years, the technique has probably gone through a fair few iterations.<\/p>\n<p>It&#8217;s happening more and more that when signing into a service, I suffer a mental block. My muddled thought process is something like: &#8220;OK, what password do I use for this service? This one, I think. No, wait, there was a breach and I changed the password. It probably uses the secondary keyword now. Ah, no, the breach was ages ago, I wasn&#8217;t using this keyword yet. So what did I tinker with? Maybe the digits\u2026?&#8221; You get the picture.<\/p>\n<p>It&#8217;s not that I have a bad memory, but after so many breaches, sometimes I can&#8217;t remember a password. When that happens I have to reset it, which further complicates my already complex password world. The keywords and sets of digits go on multiplying \u2014 and every time, I have to recall what combination of parameters I used for each service. The algorithmic certainty of having one password per service has been shattered.<\/p>\n<blockquote class=\"twitter-pullquote\">\n<p>The rules for remembering passwords no longer work. Seems like it&#8217;s password manager time.<\/p>\n<p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2Fwj1h&#038;text=The+rules+for+remembering+passwords+no+longer+work.+Seems+like+it%26%238217%3Bs+password+manager+time.\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\">Tweet<\/a><\/p><\/blockquote>\n<p>As the accounts stack up (new banks, car-sharing services, forums, etc.), my set of passwords becomes messier and messier. So for me, Twitter&#8217;s recent statement was the last straw.<\/p>\n<p>It seems the time has come to entrust the storage of this hodgepodge to a password manager. When passwords have to be changed frequently, the mnemonic system breaks down \u2014 the rules become too numerous.<\/p>\n<p>But for a password manager it&#8217;s child&#8217;s play. All you need to do is go into the service settings and click the &#8220;Change password&#8221; button, and <KPM PLACEHOLDER>Kaspersky Password Manager<\/KPM PLACEHOLDER> will automatically insert your current password and offer to generate a new one.<\/p>\n<p>The password manager automatically saves the new password to its database. There&#8217;s no need to remember it, either. The only thing you must commit to memory is the single master key to Kaspersky Password Manager, something that is eminently doable.<\/p>\n<p> <input type=\"hidden\" class=\"category_for_banner\" value=\"kpm-download\" \/> <\/p>\n<p>For a long time, I balked at the prospect of using a password manager \u2014 my own brainpan (and the techniques that I came up with) seemed a far more reliable option. But the times are changing, and data leaks continue to rise in number and scale. What worked yesterday is clumsy and obsolescent in this brave new world.<\/p>\n<p>I guess it&#8217;s time to succumb to the inevitable and switch <a href=\"https:\/\/www.kaspersky.com\/password-manager?redef=1&#038;reseller=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\">to a password manager<\/a>.<\/p>\n<p><a href=\"https:\/\/www.kaspersky.com\/blog\/remembering-passwords-is-dead\/22334\/\" target=\"bwo\" >https:\/\/blog.kaspersky.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Alex Perekalin| Date: Mon, 07 May 2018 15:05:42 +0000<\/strong><\/p>\n<p>How Twitter\u2019s \u201cnot-a-leak\u201d made me realize that remembering passwords no longer works.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10425,10378],"tags":[12928,11346,11387,11347,10602,15495,10438,454],"class_list":["post-12225","post","type-post","status-publish","format-standard","hentry","category-kaspersky","category-security","tag-breaches","tag-kaspersky-password-manager","tag-leaks","tag-password-manager","tag-passwords","tag-special-projects","tag-threats","tag-twitter"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12225","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12225"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12225\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12225"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12225"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12225"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}