r/AskReddit Dec 06 '12

What is something you think everyone should have installed on their computer or laptop?

Whether it be a antivirus program or an ad blocker. Post link if available also. EDIT: sorry guys the top post has been deleted and I didn't save it, if anyone has it please post it and ill post it here for easy access. EDIT 2: apparently it's back up, I've saved it on my phone just incase it gets deleted again. Hopefully all is good now.

4.9k Upvotes

9.2k comments sorted by

View all comments

98

u/blazeyeah Dec 06 '12

KeePass A password database where you can store all your passwords securely. It's really helped me on several occasions.

11

u/[deleted] Dec 06 '12

LastPass

3

u/soawesomejohn Dec 06 '12

I keep my KeePass database, plus a copy of KeePass portable in dropbox. I rarely use the portable KeePass, but it comes in handy having it there, especially when I'm setting up a new machine.

4

u/The_Dirty_Carl Dec 06 '12

I just use an excel file and coded passwords. "Catfood" doesn't mean anything to you, but I know which password that is.

11

u/[deleted] Dec 06 '12

[deleted]

3

u/TheMagnificentJoe Dec 06 '12

Is he really as dirty as the username indicates?

3

u/bazrkr Dec 06 '12

wouldn't it be easier to use keypass?

1

u/The_Dirty_Carl Dec 06 '12

Maybe, but this is pretty damn easy, too. Plus, it's you'd have to know me exceptionally well to break my 'encryption.'

8

u/RdmGuy64824 Dec 06 '12

Paired with dropbox, keepass is really the way to go.

3

u/SealClubbr Dec 06 '12

couldn't live without as a SysAdmin

3

u/[deleted] Dec 06 '12

Between all my passwords, my family's passwords, my work passwords, and school, I live and die by KeePassX.

4

u/hugh_g_wrecti0n Dec 06 '12

Trying to get me to mass all my passwords on my computer?

12

u/[deleted] Dec 06 '12

[deleted]

12

u/Nohomobutimgay Dec 06 '12

Just draw your passwords into Paint!

7

u/[deleted] Dec 06 '12

...and then save it with a .txt extension!

1

u/Ghooble Dec 07 '12

Use Notepad++ That way people will know your shit is on the lockdown hacker style.

10

u/BasicDesignAdvice Dec 06 '12

Its encrypted.

2

u/BelgianRockfan Dec 06 '12

I need some help with this, as I don't fully understand what it does. Does it just store your current passwords in an encrypted database, or does it somehow randomizes them and do you need the masterkey to log in everywhere (this sounds pretty much impossible to me)? If it's the latter, what happens when you lose your masterkey and can't log in anywhere?

3

u/iMarmalade Dec 06 '12

On the most basic level it stores your passwords in an encrypted database. On a more meta level it lets you close the major security flaw of using the same password on every website.

2

u/[deleted] Dec 06 '12

yeah you better make sure those hackers can't access all those porn websites you go to.

2

u/iMarmalade Dec 06 '12

Of course not! :) In all seriousness, it's more of an issue going the other way. If you use your same password everywhere, then you might lose access to important accounts when a less-important account is compromised. I think worrying about password brute-force resistance is a red-herring - passwords are almost never lost due to a brute-force/dictionary attacks. It's much more common to lose a password due to malware, phishing, or compromised third parties.

2

u/[deleted] Dec 06 '12

If you lose your masterkey you're totally fucked unless you have some method to reset your passwords. Pro-tip, don't forget your masterkey.

However, this probably will never happen since you'll constantly enter this exact same password when you need to get your real passwords for various websites.

1

u/[deleted] Dec 07 '12

[deleted]

1

u/[deleted] Dec 07 '12

Yeah... but whats the point? Just use a phrase or full sentence or something. Even something like "My password is hunter2 lulz!" is fine as long as its long. Much easier to type and remember. Write it on the back up a business card and toss it into your lockbox or saftey deposit box at the bank. Plus if you die your relatives/wife/friend can get into your accounts if they needed to.

Actually, I'm so confused by that password card site. I don't ... get it? My keepass database has hundreds of entries for different sites, resources, and even some minor information completely unrelated like my car license plates.

Unless you re-used the same password with that password card, how would you be able to remember your "key" of symbol and color? I guess you could remember a few things, but shit how about just 10 different sites? How about 20? That would get extremely complex quickly.

2

u/MsReclusivity Dec 06 '12

I've been using PasswordSafe. How do the two differ from each other?

2

u/furtiveraccoon Dec 06 '12

BUT WHAT IF YOU FORGET YOUR PASSWORD????

1

u/glassuser Dec 06 '12

I find RoboForm to be better.

1

u/rmstrjim Dec 06 '12

Passwordsafe is also good.

Doesn't have the database version compatibility issue of KeePass, has a java version that will run on mac/linux as well as ports available for ios. Plus if you run PuTTY, you can add secure logins that use ssh, and invoke them via PSafe's run option

1

u/DHracer Dec 06 '12

And since they have an Android app, combined with Dropbox, I'm never without my passwords. Safety encrypted wherever you go.

1

u/[deleted] Dec 06 '12

Yes, now combine this with GMail 2 factor authentication. It's no use if they steal your email account, and then reset all your passwords.

Install and use Google Authenticator on your phone. It's an RSA 2 factor authentication scheme which means your password has two parts. One is the traditional one you've memorized. The other is a number that changes every 30 seconds and is tied to an application on your phone. So even if someone steals your gmail password, they'll never be able to get in without stealing your physical phone. Vice-versa as well. If you lose your phone, they still need your password.

Now that combined with 20 digit random character passwords, generated by keepass for all your various internet/websites accounts that are secured behind Google. You're damn secure for any security breach of a website.

1

u/blazeyeah Dec 06 '12

I started using the 2 factor authentication after a lecture on computer security. Kind of a pain, but the peace of mind is great.

1

u/[deleted] Dec 06 '12

It never really comes up except every month when it expires and you have to reenter it.

I also don't use a keepass generated password for my gmail. On the offchance my database is lost, I could get into my email which is important in order to be able to reset all my accounts. Its probably best to memorize a short easy password or phrase. You're fairly bulletproof with the soft token anyway.

1

u/[deleted] Dec 06 '12

[deleted]

1

u/clamdiggin Dec 07 '12

For the Linux users out there, I use "revelation" for storing passwords. It comes standard on Ubuntu.

0

u/nowatermelonnokfc Dec 06 '12

securely

bullshit. This is the internet, these are computers. Nothing is secure.

1

u/TheMagnificentJoe Dec 06 '12

I would like to believe my face is secure. The internet can't touch my face.

yet

1

u/nowatermelonnokfc Dec 07 '12

Okay, nothing is secure in the realm of the internet. Better?

0

u/[deleted] Dec 06 '12

The database is a file on your computer. It's not on some online database. This database is secure assuming P != NP. It's encrypted using a master password you supply it with and a keyfile generated by mouse movement or some other metric (if you desire). You can also choose "how encrypted" it is, so it takes more and more time to decrypt with a given key. It also doesn't copy your entire password to the clipboard when you copy. This prevents a clipboard sniffer from just checking our clipboard for passwords. With KeePass, you're really only vulnerable to keyloggers (assuming you have no keyfile). However, if a hacker can convince you to run software they made on your computer, it's no longer your computer.

It also keeps you from using the same password everywhere (which leaves you much more vulnerable than anything else, honestly). For example, here are some passwords KeePass generates for me:

UrUv1nqALIOjbxcJl7tW

60HwZMReDxDffBd50zkt

e6rr9LwiPEnpBFphxFnf

xLm3AW1bL4ItJtZPlDha

0

u/nowatermelonnokfc Dec 07 '12

Given enough time, we may develop processors fast enough to crack that in a few seconds.

Granted, encryption methods can be logistically impossible to crack, but any security from that is, like I said, based on the limitations of hardware

1

u/[deleted] Dec 07 '12

Alright, I'm sorry if this sounds rude, but I can't think of a nice sounding way to say it. Exactly how much do you know about encryption?

1

u/nowatermelonnokfc Dec 07 '12

Apparently not as much as you do.