# Passwords & alternatives?

**URL:** https://boards.straightdope.com/t/passwords-alternatives/671214
**Category:** Factual Questions
**Created:** [October 14, 2013, 2:25pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214 "2013-10-14T14:25:26Z")
**Posts on this page:** 12
**Page:** 3

<div class="post-metadata">

### Author: ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)
#### Post date: [November 4, 2013, 9:40pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/41 "2013-11-04T21:40:53Z")

</div>

> [@GusNSpot](#):
>
> ??? What should I fear?

Any site that stores your passwords could be hacked in the same way as Adobe.

---

<div class="post-metadata">

### Author: ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)
#### Post date: [November 5, 2013, 12:04am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/42 "2013-11-05T00:04:41Z")

</div>

I go lo-tech.

My password vault is a manila folder, which sits among a stack of other manila folders on an end-table in my kitchen (not particularly near my computer). Each record consists of a separate sheet of paper, showing the site, its URL to log in (not always the home page, which one can sometimes bypass), log-in name, password, security questions and my (not-always-for-real) answers, and other details I need to know about using the site.

Hackable only if someone physically breaks into my apartment AND knows what he’s looking for and where to look for it.

---

<div class="post-metadata">

### Author: ![Ximenean](https://avatars.discourse-cdn.com/v4/letter/x/aca169/32.png) [@Ximenean](https://boards.straightdope.com/u/Ximenean)
#### Post date: [November 5, 2013, 12:22am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/43 "2013-11-05T00:22:23Z")

</div>

That doesn’t seem like an good trade-off between security and ease-of-use. In fact it sounds rather inconvenient and not especially secure. I think I’ll stick with KeyPass.

---

<div class="post-metadata">

### Author: ![GusNSpot](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gusnspot/32/436_2.png) [@GusNSpot](https://boards.straightdope.com/u/GusNSpot)
#### Post date: [November 5, 2013, 6:58am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/44 "2013-11-05T06:58:12Z")

</div>

Never seen a hacker be able to use a computer to get into a manila folder.  
YMMV

---

<div class="post-metadata">

### Author: ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)
#### Post date: [November 5, 2013, 7:21am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/45 "2013-11-05T07:21:32Z")

</div>

> [@Deeg](#):
>
> I don’t mean to pick on bob++ but here is one of the reasons you don’t want to use the same password: [hackers release Adobe encrypted passwords](http://www.businessinsider.com/hackers-take-38-million-adobe-passwords-2013-10).

Right - accounts are being hacked right now because people used similar or related passwords on multiple sites. And the bad guys are only getting better at guessing similar passwords.

If you’ve ever re-used passwords in multiple places, or similar passwords, or related passwords, please go change them now. It will come back to bite you (or your friends) one day if you don’t.

---

<div class="post-metadata">

### Author: ![Nava](https://avatars.discourse-cdn.com/v4/letter/n/da6949/32.png) [@Nava](https://boards.straightdope.com/u/Nava)
#### Post date: [November 5, 2013, 11:13am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/46 "2013-11-05T11:13:34Z")

</div>

> [@sailor](#):
>
> I think the main use of the Smartcard ID is for filing taxes and voting. When you vote they take your card and put it in a slot and it registers that you voted. I almost felt like arguing whether that was necessary or could be required to vote but I thought better of it.

I’ve been “at the table” a couple of times; the purpose is to avoid having two people vote under the same ID. We didn’t have any fancy card readers, tho, just old fashioned paper and pens.

---

<div class="post-metadata">

### Author: ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)
#### Post date: [November 5, 2013, 11:35am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/47 "2013-11-05T11:35:14Z")

</div>

> [@GusNSpot](#):
>
> Never seen a hacker be able to use a computer to get into a manila folder.

But the “manilla folder” end is not the problem end of the system these days. Unless you are particularly famous or wealthy, it’s not worth the effort to hack into your computer to get just your passwords any more than it’s worth the effort to break into your house to steal your manila folder. It’s the other end that’s getting compromised, because getting hundreds of thousands of passwords is worth the hackers’ time and risk of getting caught.

You protect against the other end getting its hashes leaked by having very long and random passwords that are hard infer from hashes, and having unique passwords for each site so one site’s leak can’t be used to compromise your accounts on other sites. That’s what password managers facilitate.

---

<div class="post-metadata">

### Author: ![shijinn](https://avatars.discourse-cdn.com/v4/letter/s/cc9497/32.png) [@shijinn](https://boards.straightdope.com/u/shijinn)
#### Post date: [November 5, 2013, 11:38am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/48 "2013-11-05T11:38:51Z")

</div>

but the reason for having a manila folder in the first place is because you have many long, unique and random passwords.

---

<div class="post-metadata">

### Author: ![leahcim](https://avatars.discourse-cdn.com/v4/letter/l/b4bc9f/32.png) [@leahcim](https://boards.straightdope.com/u/leahcim)
#### Post date: [November 5, 2013, 11:59am UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/49 "2013-11-05T11:59:45Z")

</div>

> [@shijinn](#):
>
> but the reason for having a manila folder in the first place is because you have many long, unique and random passwords.

And a password vault can give you the same thing, only more so, because you aren’t even limited by the the “has to be simple enough that I can read it and type it in given a small number of tries without fat-fingering it”. I argue that the attack vector of “someone hacking into my computer and stealing my password vault” that the manila folder is meant to avoid is uncommon enough that it’s not worth the additional complexity in defending against the more common attack vector.

(Additionally, the most common method for someone going the “steal passwords from your computer” route to use is to install a keylogger on your machine and record your keystrokes as you’re typing your password in. The manila folder doesn’t protect against that at all, while a password manager provides some protection because you’re not ever typing in your passwords via the keyboard.)

---

<div class="post-metadata">

### Author: ![campp](https://avatars.discourse-cdn.com/v4/letter/c/c5a1d2/32.png) [@campp](https://boards.straightdope.com/u/campp)
#### Post date: [November 5, 2013, 12:25pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/50 "2013-11-05T12:25:38Z")

</div>

Another vote for simple: Mine is a two page Excel doc, with a couple of hundred long non-repeating passwords. I have it well hidden in the excel files, and I keep a recent physical printout for emergencies, also well hidden.

---

<div class="post-metadata">

### Author: ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)
#### Post date: [November 5, 2013, 8:35pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/51 "2013-11-05T20:35:22Z")

</div>

If one is using unique, unguessable passwords then I think the storage medium makes little difference. As leahcim said, unless someone wants to target you directly, nobody is going to go into your house to look for passwords. I let my browser store most of the passwords. The issue then becomes convenience. Folders and Excel files don’t work for me because I need to access my passwords from multiple computers and locations.

---

<div class="post-metadata">

### Author: ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)
#### Post date: [November 5, 2013, 8:47pm UTC](https://boards.straightdope.com/t/passwords-alternatives/671214/52 "2013-11-05T20:47:45Z")

</div>

Bruce Schneier recommends [writing down your passwords](https://www.schneier.com/blog/archives/2005/06/write_down_your.html) on paper. Because people are better at securing pieces of paper than their computers.

Granted, that’s an old article. And for an active user, a good password manager + 2FA is probably better (and no less convenient). But a pencil and paper is still pretty good.

Letting your browser store passwords is not the worst idea in the world, but it’s [not very secure](http://www.digitaltrends.com/computing/lay-off-chrome-firefox-has-the-same-password-security-flaw/), especially on a laptop or shared computer.

[Previous page](https://boards.straightdope.com/t/passwords-alternatives/671214.md?page=2)
