# Passwords & alternatives?

**URL:** https://boards.straightdope.com/t/passwords-alternatives/671214
**Category:** Factual Questions
**Created:** [October 14, 2013, 2:25pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214 "2013-10-14T14:25:26Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)
#### Post date: [October 15, 2013, 8:35pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/21 "2013-10-15T20:35:53Z")

</div>

> [@sailor](#):
>
> It seems to me smartcard and password is the way to go but I think smartcard protocols are not really standardized yet so each vendor has their own thing. I suppose with time it will become easier and cheaper.

Unlikely to ever happen - smartcards had their chance and missed it. Their role has been replaced by mobile devices.

Here’s the standard where I work:

1. Long random passwords, unique for each site, generated by a password manager like 1Password or Lastpass.

2. Two-factor authentication on sites that support it (Google in particular).

3. Physical security on computers and mobile devices - login passwords and encryption enabled. I’m told Facebook requires its engineers to power down laptops and never use sleep/hibernate.

Two-factor auth basically means that to log in you need both your password, and a 6-digit code generated by an app on your phone that changes every minute. The apps Google Authenticator and Authy are supported by a number of large sites now.

---

<div class="post-metadata">

### Author: ![Cartoonacy](https://avatars.discourse-cdn.com/v4/letter/c/848f3c/32.png) [@Cartoonacy](https://boards.straightdope.com/u/Cartoonacy)
#### Post date: [October 15, 2013, 8:38pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/22 "2013-10-15T20:38:01Z")

</div>

> [@sailor](#):
>
> Because someone has a copy of your finger, your hand or whatever you are using to authenticate. Now what do you do?

Simpler than that. Biometric devices scan your fingerprint (palm, retina,etc.) and convert the scan to a string of data, which is your “password.” Someone who gets a copy of your data string can bypass the biometric scanner and feed the data directly to the password-checking software. Your security is broken, and you can’t set a new “password.”

---

<div class="post-metadata">

### Author: ![Learjeff](https://avatars.discourse-cdn.com/v4/letter/l/94ad74/32.png) [@Learjeff](https://boards.straightdope.com/u/Learjeff)
#### Post date: [October 15, 2013, 9:11pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/23 "2013-10-15T21:11:01Z")

</div>

I use (free) Password Corral for this. Works great.

---

<div class="post-metadata">

### Author: ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)
#### Post date: [October 15, 2013, 9:34pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/24 "2013-10-15T21:34:17Z")

</div>

> [@tellyworth](#):
>
> Unlikely to ever happen - smartcards had their chance and missed it. Their role has been replaced by mobile devices.
> 
> Here’s the standard where I work:
> 
> 1. Long random passwords, unique for each site, generated by a password manager like 1Password or Lastpass.
> 
> 2. Two-factor authentication on sites that support it (Google in particular).
> 
> 3. Physical security on computers and mobile devices - login passwords and encryption enabled. I’m told Facebook requires its engineers to power down laptops and never use sleep/hibernate.
> 
> Two-factor auth basically means that to log in you need both your password, and a 6-digit code generated by an app on your phone that changes every minute. The apps Google Authenticator and Authy are supported by a number of large sites now.

I believe the US Government, specially military, CIA, NSA, etc use smartcards. They are more secure and do not require a smartphone. On the other hand it may well be that for civilians, who are assumed to have a smartphone and do not require the same level of security, a amrtphone application is enough.

---

<div class="post-metadata">

### Author: ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)
#### Post date: [October 15, 2013, 9:39pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/25 "2013-10-15T21:39:00Z")

</div>

> [@sailor](#):
>
> I believe the US Government, specially military, CIA, NSA, etc use smartcards.

Do you have a cite for that? I’m not disputing, just interested.

---

<div class="post-metadata">

### Author: ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)
#### Post date: [October 15, 2013, 9:46pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/26 "2013-10-15T21:46:18Z")

</div>

> [@tellyworth](#):
>
> Do you have a cite for that? I’m not disputing, just interested.

My impression comes from several clues. I remember some poster here who was in the military, maybe in Iraq, mentioning the smartcard needed to access his laptop computer. I would have a hard time finding it but I remember it was here. I recall several anecdotal instances like this.

Also, I have bought several used Dell laptops on ebay over the years and for several reasons had a feeling they came from government surplus. They all had smartcard readers but it was impossible for me to find the smartcards because they seemed to be specific and proprietary. I never could use the reader.

---

<div class="post-metadata">

### Author: ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)
#### Post date: [October 15, 2013, 9:49pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/27 "2013-10-15T21:49:50Z")

</div>

> [@Chronos](#):
>
> Most likely? Bleed to death.

Good one 🙂

---

<div class="post-metadata">

### Author: ![seal\_cleaner](https://avatars.discourse-cdn.com/v4/letter/s/e274bd/32.png) [@seal\_cleaner](https://boards.straightdope.com/u/seal_cleaner)
#### Post date: [October 15, 2013, 10:07pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/28 "2013-10-15T22:07:43Z")

</div>

nm

---

<div class="post-metadata">

### Author: ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)
#### Post date: [October 15, 2013, 10:59pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/29 "2013-10-15T22:59:55Z")

</div>

> [@tellyworth](#):
>
> Do you have a cite for that? I’m not disputing, just interested.

I found this:

> [@Why would I want a smart-card reader?](https://boards.straightdope.com/t/why-would-i-want-a-smart-card-reader/619136/11):
>
> That’s how we log into and lock our computers where I work (a US Air Force base). To my knowledge, that’s the standard way of operating for most DoD [NIPRNet](http://en.wikipedia.org/wiki/NIPRNet) computers. If our heads-up-their-asses IT folks have deployed it, the system can’t be all that slick.
> 
> I have a card reader on my personal laptop so I can log into my work webmail from home or on the road. I don’t care to take a work laptop when I travel because I can’t do anything fun with it. And by fun, I mean porn.

---

<div class="post-metadata">

### Author: ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)
#### Post date: [October 15, 2013, 11:19pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/30 "2013-10-15T23:19:39Z")

</div>

Interesting, thanks.

Probably not all that relevant to the OP, since it has no traction in the civilian world. 2FA via phone apps is available today on many major sites.

---

<div class="post-metadata">

### Author: ![sailor](https://avatars.discourse-cdn.com/v4/letter/s/a587f6/32.png) [@sailor](https://boards.straightdope.com/u/sailor)
#### Post date: [October 15, 2013, 11:35pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/31 "2013-10-15T23:35:20Z")

</div>

> [@tellyworth](#):
>
> Interesting, thanks.
> 
> Probably not all that relevant to the OP, since it has no traction in the civilian world. 2FA via phone apps is available today on many major sites.

[In Spain the national ID card is a contact Smartcard](http://www.xataka.com/hogar-digital/como-usar-el-dni-electronico) and can be used for legal identification online but, in fact, it has been slow to spread and, in fact, many people, like myself, use a digital certificate I got before the smartcard ID and I just continue to use that one. I think the main use of the Smartcard ID is for filing taxes and voting. When you vote they take your card and put it in a slot and it registers that you voted. I almost felt like arguing whether that was necessary or could be required to vote but I thought better of it. For online stuff I just use the digital certificate I got and I never use the smartcard even though I have several USB readers.

---

<div class="post-metadata">

### Author: ![Duke\_of\_York](https://avatars.discourse-cdn.com/v4/letter/d/f6c823/32.png) [@Duke\_of\_York](https://boards.straightdope.com/u/Duke_of_York)
#### Post date: [October 16, 2013, 1:07am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/32 "2013-10-16T01:07:00Z")

</div>

I’ve used ROBOFORM for a long time now. I also have it on my phone. The security seems high, plus it’s easy to use.

---

<div class="post-metadata">

### Author: ![dstarfire](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dstarfire/32/5762_2.png) [@dstarfire](https://boards.straightdope.com/u/dstarfire)
#### Post date: [October 16, 2013, 6:05am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/33 "2013-10-16T06:05:36Z")

</div>

For making unique passwords across multiple sites that are still easy to remember, the trick is to use a formula that includes the url in some (preferably unrecognizable) form.

You start with a word that’s special to you, add in a number (so you can vary your password for places that expire passwords every so often), include some letters from the url (along with some sort of subtitution algorithm (e.g. replace vowels with c, uncommon letters (x,z,w) with e, etc.) to make it non obvious, and figure out a pattern to shuffle the order.

---

<div class="post-metadata">

### Author: ![EatTheSun](https://avatars.discourse-cdn.com/v4/letter/e/b487fb/32.png) [@EatTheSun](https://boards.straightdope.com/u/EatTheSun)
#### Post date: [October 16, 2013, 10:13am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/34 "2013-10-16T10:13:26Z")

</div>

I’ll also throw LastPass into the ring of contenders for multi-platform password managers. I’ve used it for years, and it has a very hardy random password generator.

---

<div class="post-metadata">

### Author: ![j\_sum1](https://avatars.discourse-cdn.com/v4/letter/j/8baadc/32.png) [@j\_sum1](https://boards.straightdope.com/u/j_sum1)
#### Post date: [October 16, 2013, 12:24pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/35 "2013-10-16T12:24:54Z")

</div>

I go low tech. I have a simple file that contains mnemonics that help me remember what passwords I have used for which locations.  
I can write, “John Ford 2nd”. No one except me knows that I am referring to the middle name of a friend I haven’t seen since primary school, the number plate of the car we had when I was 10 and the stuffed zebra I gave my niece on her second birthday.

Elements of the passwords can be repeated if necessary while still maintaining unique passwords for each purpose. I could write, “blue car stripes harpoon” and be referring to two of the same elements by a different memory device.

I could print off this file and leave it lying around because no one can get into my head to interpret its contents.

And of course all of my high security passwords such as for banking contain a sequence that is memorised and never even referred to. Mercifully there are few of these to recall.  
If the truth be known, I actually have a harder time remembering usernames than passwords. Most sites require both to be entered and I have a difficult time remembering which variant I used.

The other one that is difficult are four-digit PINs. Between bank cards, loyalty cards, photocopier access codes, building alarm codes, frequent flyer cards and whatever else comes up there isn’t a lot of scope. It is not that I have difficulty recalling a four digit sequence. The problem is remembering which one was used where. And of course I do not want to double up if I can help it.

J.

---

<div class="post-metadata">

### Author: ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)
#### Post date: [October 16, 2013, 5:09pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/36 "2013-10-16T17:09:32Z")

</div>

[Here’s](http://www.ccc.de/en/updates/2013/ccc-breaks-apple-touchid) a group of folks that broke the new iPhone fingerprint ID system quite quickly.

Also, some [people](http://slashdot.org/story/13/09/15/1222208/german-data-protection-expert-warns-against-using-iphone5s-fingerprint-function) are warning about the _increased_ privacy risks associated with biometric ID systems.

One of the core problems with biometric ID is that the algorithms have to be fuzzy. Not everything lines up perfectly each time, not all features are going to be clear, etc. You can’t go very far in reducing false positives without significantly increasing false negatives. This makes them exploitable. Fuzzy and security don’t go together.

---

<div class="post-metadata">

### Author: ![HipGnosis](https://avatars.discourse-cdn.com/v4/letter/h/76d3ee/32.png) [@HipGnosis](https://boards.straightdope.com/u/HipGnosis)
#### Post date: [October 16, 2013, 11:44pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/37 "2013-10-16T23:44:27Z")

</div>

> [@Cartoonacy](#):
>
> Simpler than that. Biometric devices scan your fingerprint (palm, retina,etc.) and convert the scan to a string of data, which is your “password.” Someone who gets a copy of your data string can bypass the biometric scanner and feed the data directly to the password-checking software. Your security is broken, and you can’t set a new “password.”

The Co I work for just put in timeclocks w/ finger scanners.  
Users had to scan 2 fingers - the second is a backup in case the first finger becomes un-readable by dirt, bandaid or the unthinkable.

---

<div class="post-metadata">

### Author: ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)
#### Post date: [November 4, 2013, 7:22pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/38 "2013-11-04T19:22:26Z")

</div>

> [@bob\_2](#):
>
> I simply do not see the need for 30 passwords, and it seems to me that keeping them all in a safe with a single lock, rather defeats the object.

I don’t mean to pick on bob++ but here is one of the reasons you don’t want to use the same password: [hackers release Adobe encrypted passwords](http://www.businessinsider.com/hackers-take-38-million-adobe-passwords-2013-10).

Here’s the appropriate [xkcd comic](http://xkcd.com/1286/) that tipped me off to this story.

---

<div class="post-metadata">

### Author: ![GusNSpot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gusnspot/32/436_2.png) [@GusNSpot](https://boards.straightdope.com/u/GusNSpot)
#### Post date: [November 4, 2013, 7:46pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/39 "2013-11-04T19:46:12Z")

</div>

But, but, but I don’t have any Adobe passwords do I?  
I don’t use any encryption.

??? What should I fear?

---

<div class="post-metadata">

### Author: ![yabob](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/yabob/32/2821_2.png) [@yabob](https://boards.straightdope.com/u/yabob)
#### Post date: [November 4, 2013, 8:06pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/40 "2013-11-04T20:06:35Z")

</div>

A password vault does seem like the best, if not ideal, approach. I’ve used [KeePass](http://keepass.info/) for quite a while now. It has versions on several platforms, including mobile devices, and the vault is a simple file that you can copy to anywhere you want to use it, making it easy to sync. For a lot of things, I let it generate a random password. If it’s not a site I’m going to use frequently, I don’t mind having to open the password vault to get my password. If I am going to use it frequently, I’ll actually look at the password rather than just pasting it from the vault, and eventually memorize it.

[Previous page](https://boards.straightdope.com/t/passwords-alternatives/671214.md?page=1)

[Next page](https://boards.straightdope.com/t/passwords-alternatives/671214.md?page=3)
