LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-24-2006, 06:00 PM   #1
njdube
Member
 
Registered: Mar 2006
Posts: 46

Rep: Reputation: 15
Cross Platform Password Managment


My first goal is to find software that I can use on SUSE 10 to randomly generate long highly secure passwords. I want a differant password for EVERY THING.

What I need next is a secure but easy way to manage all these passwords on a USB flash drive in a way that can be used for any operating system. The bulk of my passwords will be used for websites.

Currently I use KDE Wallet to store them. The problem is that it only stores passwords on this one machine. And I need to take my passwords with me ever where I go. Which is what my key chain USB flash drive will be used for.

I'm looking for recommendations and ideas on how any of you manage your passwords and take them with you.
 
Old 05-24-2006, 06:44 PM   #2
gilead
Senior Member
 
Registered: Dec 2005
Location: Brisbane, Australia
Distribution: Slackware64 14.0
Posts: 4,141

Rep: Reputation: 168Reputation: 168
I generate my passwords manually based on phrases or songs I know. Then I randomly change letters to digits and mix between upper and lower case to make them harder to guess.

My password list is encrypted with gpg and kept on my USB flash-drive. GPG is installed on all of the boxes I use here (Linux and Windows) so I can just decrypt the password list when I need it.

I spend most of my time using the CLI here so I don't mind the typing that this requires. In other words, I don't know the equivalent gui tools for doing this...

Last edited by gilead; 05-24-2006 at 06:45 PM.
 
Old 05-24-2006, 07:20 PM   #3
camh
Member
 
Registered: Feb 2005
Distribution: Slack/Debian
Posts: 163
Blog Entries: 2

Rep: Reputation: 33
I keep them all in my head.

IMO, having a different password for everything is more insecure. The chance of forgetting one, or someone getting access to a USB key with them on it are far greater than by using a limited number of passwords and keeping them in your head.

I use kind of a tier based system, for example:

Tier 1: Low risk (eg. forums)

I have a few shorter 'stronger' passwords that I rotate or just pick randomly
(eg. p4ssw0rd)

Tier 2: Medium risk (eg. webmail)

Same deal, but add some special chars/mixed case (if supported).
(eg. P@ssw0rd)

Tier 3: High risk (eg. banking)

I generally use 'strong' passphrases for highly sensitive things.
(eg. myP@ssw0rdispassword)

My problem with encryption solutions is that, generally, you need to have the decryption software on the machine you are wishing to use, or have the ability to install it. This ultimately limits how portable your password list is.

Anyway, just my $.02
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
cross platform macros dmail Programming 4 12-20-2005 09:16 PM
cross platform c++ nyomon Programming 6 07-03-2005 03:24 PM
cross platform filesystem z9_87 Linux - Hardware 5 03-20-2005 06:49 PM
Cross platform VNC ®åD\° Linux - Software 1 08-03-2004 04:04 PM
Cross Platform biggiefatts Linux - Software 4 06-04-2002 03:00 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:00 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration