Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Writing Down Passwords?

Posted by Cliff on Wed Jun 08, 2005 04:40 PM
from the would-you-write-down-your-safe's-combination dept.
Atryn wonders: "I was recently checking for the latest firmware for a Netgear router when I decided to click on their Guide to Internet Security where it states: 'Contrary to much 'expert' advice, there is very little risk writing down passwords. In fact, years from now you may discover you need them to access old files.' I'm wondering what Slashdot thinks of Netgear's recommendation." Update: 06/08 21:19 GMT by T : Reader 654043 reminds us of the Microsoft recommendation to write down passwords which ran a few weeks back, and which has some pretty sound reasoning behind it.
+ -
story
This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by jusdisgi (617863) on Wednesday June 08 2005, @04:42PM (#12762221)
    No, no, just post them to Google Groups! That way you can always get back to them no matter where you are!
    • Re:Google groups (Score:5, Interesting)

      by Janitha (817744) on Wednesday June 08 2005, @04:47PM (#12762298) Homepage
      Ive actually done that... should I be shot? Not plain text of course, simply use a word shift encryption which can be easily deciphered by hand. I posted all my current passwords like that and it has come in handy quite a bit. (I also have posted same list on slashdot comments)
  • Aren't all the reasons that this is a good/bad idea the same as they were then?
  • by Draknor (745036) on Wednesday June 08 2005, @04:45PM (#12762264) Homepage
    I found out about KeePass (http://keepass.sourceforge.net/ [sourceforge.net]) on that previous story, so I've started using it. It's a very handy utility to have! It can keep track of all my passwords for various email accounts, websites, etc. It's a simple program that (based on my experience so far), just works!

    If you wanted portability, you could keep your password database on a USB memory drive and carry that around with you.

    I see that they just released 1.0 on June 4th - congrats!! I highly recommend people check it out!
  • by otisg (92803) on Wednesday June 08 2005, @04:48PM (#12762310) Homepage Journal
    Hide them where cr@ck3rz will least expect them - your blog!
  • Context! (Score:4, Insightful)

    by coyote-san (38515) on Wednesday June 08 2005, @04:50PM (#12762336)
    Should you drive on the left hand side of the road, or the right hand side?

    Despite what some people seem to think, there's no "right" answer other than following the context. I live in the US and routinely drive on the left hand side of the road... on one way streets where I'll be turning left soon. I've done it on interstates... where the right hand lanes were closed due to construction and the oncoming traffic was moved onto the access road.

    Writing down passwords is the same deal. It's a Bad Idea in your cubicle. It's a Cause For Termination Idea if you're a sysadmin.

    But on a router at home, or in a locked wiring cabinet? It's a damn good idea. On a card in your wallet, especially in that zippered compartment so it can't accidently slip out? Good idea, unless you routinely leave your wallet unsecured. In which case you're an idiot with bigger problems than just writing down your passwords.
  • Could be (Score:5, Insightful)

    by Have Blue (616) on Wednesday June 08 2005, @04:50PM (#12762346) Homepage
    Well, how good is your physical security?. If the system will be accessed from an environment where there are likely to be unauthorized people wandering around all the time (large office, public area, etc), then don't write it down. If the system will be accessed from a place that only people you trust have access to (home), then it's not a danger- and if your home is ever compromised, having your router password in plain sight is the least of your worries.
  • by otisg (92803) on Wednesday June 08 2005, @04:54PM (#12762386) Homepage Journal
    See Jon Udell's
    Simple single sign-on [infoworld.com] article from May 2005:

    It points out a few simple solutions that will solve many people's problems.
  • Like anything else (Score:5, Insightful)

    by wowbagger (69688) on Wednesday June 08 2005, @04:57PM (#12762432) Homepage Journal
    The security of writing down passwords depends upon the security of the paper they are written upon.

    If you have a router/firewall on your Internet connection, and you write the password(s) to the router on a piece of paper taped to the router, then you are not really reducing your security - if the bad guys are in the room reading the password you are already in trouble.

    However, if you write your workstation password down on a piece of paper under your keyboard, and other people can reasonably be expected to have access to your office, then you are greatly reducing your security. If, on the other hand, you have your password written down on a piece of paper you keep in your wallet, then the reduction in security is fairly minimal - especially if there is nothing in your wallet that would lead the bad guys to your workstation.

  • Get a keyring (Score:5, Informative)

    by 26199 (577806) on Wednesday June 08 2005, @04:59PM (#12762444) Homepage

    A real, physical, password keyring. ThinkGeek has some rather expensive ones, but they'll definitely do the job. I have one of the earlier (cheaper) keyrings from the same company, and it's wonderful. I have strong passwords, I don't have to worry about forgetting them, and they're secure.

  • 1. pick a number (one to three digits probably)

    2. add 5

    3. multiply by 3

    4. square this number

    5. add the digits over and over until you get only one digit (i.e. 64=6+4=10=1+0=1)

    6. if the number is less than 5 then add five otherwise subtract 4

    7. multiply by 2

    8. subtract 6

    9. use this number to select a letter of the alphabet 1=A, 2=B, 3=C, etc.

    10. pick the name of a country that begins with that letter

    11. take the second letter in the country name and think of an animal that begins with that letter

    but wait...

    there are no elephants in Denmark!
  • by Skjellifetti (561341) on Wednesday June 08 2005, @10:14PM (#12764961) Journal
    I'm sitting here reading /. because I fucking can't remember the fucking root password to a server that I'm supposed to administer as a favor to a friend. I changed it two months ago, haven't needed to get on the fucking machine since and now, when I need to fix it, I can't remember what the fuck I changed it to. And no, I can't just stick a rescue boot disk in because I don't know what fucking city the server is in.

    Note to self: Next time, write down the fucking password and put it in the fucking file cabinet.

    Note to poster: Did you ask this fucking question just to fuck with my mind or was it pure coincidence?
    • by cursion (257184) on Wednesday June 08 2005, @04:44PM (#12762245) Homepage
      I've got this thing called a spiral bound notebook...
        • by rjelks (635588) on Wednesday June 08 2005, @05:04PM (#12762493) Homepage
          It's a good idea to hide passwords that you've written on paper - but you don't need a safe. Just stick it to the bottom of the keyboard like I do. No one will every find it there.
            • Re:recommendations? (Score:4, Interesting)

              by Martin Blank (154261) on Wednesday June 08 2005, @07:16PM (#12763790) Journal
              Just as long as they're being appropriately hidden. One of the few times that I ever snapped at a user without being provoked was when I saw, in the HR department, the name of the bank, dial-up number, account number, and password for the payroll account on a Post-It on the user's bulletin board, with the following words in big letters:

              PAYROLL ACCOUNT MASTER LOGIN

              I ripped it down and handed it to her, telling her somewhat angrily that she needed to lock it in a secure location, or I would escalate it to the head of HR and the head of IT. I came back everyday for a week, and periodically for a few months afterward, at times when the user was not there to ensure that it had not been placed in any semi-obvious location, and that all of the cabinet drawers were locked. I still ended up telling the mentioned managers, but in a more general way that they needed to do more to focus on security of accounts, among other things. They implemented training a couple of weeks later, fortunately.
    • PGP disk.
      You can then store your passwords in any format you like, xls, txt..etc
    • by ikewillis (586793) on Wednesday June 08 2005, @04:57PM (#12762418) Homepage
      vim has integrated cryptographic functionality through VimCrypt. :help :X for more information.

      I have a rather large master password list for every server at work which I store this way. It's quite handy.

    • Re:recommendations? (Score:5, Interesting)

      by nizo (81281) * on Wednesday June 08 2005, @05:15PM (#12762593) Homepage Journal
      Becoming tired of remembering passwords, I wrote a little perl program to randomly generate a matrix like this:


      a-E9 b-?p c-&m
      d-6K e-aY f-eP
      g-!S h-gn i-D=
      j-Hd k-vw l-Cb
      m-W5 n-4$ o-R3
      p-x% q-7M r-NF
      s-+2 t-s* u-Ay
      v-fL w-zG x-Zu
      y-cX z-Qr


      I then print this, laminate it, and put it in my wallet (a backup copy somewhere isn't a bad idea either). Then, for every password I just remember a word (maybe "bank" for my bank for example) which gives me a password of: ?pE94$vw
      Hard to guess, easy for me to "remember". If someone gets my paper (say I lose my wallet), it is still not simple to figure out what my passwords are, or even what the heck that little paper is. Shoulder surfing doesn't work too well either, unless you can memorize the whole card and then figure out which word I am using (it would be easier to try to watch me type the password on the keyboard then get it off the paper. Luckily I type fast and get annoyed when people stand over me while I type a password :-) ).

        • Re:recommendations? (Score:4, Informative)

          by dknj (441802) on Wednesday June 08 2005, @06:07PM (#12763141) Journal
          i wrote this in 2 seconds, but it duplicates what the original post does. you need string::random [cpan.org], you could roll your own but i'm lazy and counterstrike is calling my name. enjoy!
          use String::Random;

          $pass = new String::Random;

          for($i=0;$i<26;$i+=3)
          {
          printf("%c-%s\t",($i+65),$pass->randpattern("...") );
          printf("%c-%s\t",($i+66),$pass->randpattern("...") );
          printf("%c-%s\n",($i+67),$pass->randpattern("...") );
          }
          -dk
        • by bnardone (881744) on Wednesday June 08 2005, @06:53PM (#12763608)
          I thought what he had posted was the Perl script.
    • My experience with it is that it is ok. I'm not a raving proponent, but it works as advertised.
    • I use it and it works well. I started when I got an online banking account that wouldn't let me use my standard username. I had to have mixed case and numbers in both my username and password. I got KeepPass and now store everything in there.

      It runs in my system tray and I can click, enter my master password and have access to all my passwords. It has also let me use long random passwords for my very important sites since I don't need to remember them any more.

      Also you can use a USB key as part of the key