If you need assistance, please send an email to forum at 4hv dot org. To ensure your email is not marked as spam, please include the phrase "4hv help" in the subject line. You can also find assistance via IRC, at irc.shadowworld.net, room #hvcomm.
Support 4hv.org!
Donate:
4hv.org is hosted on a dedicated server. Unfortunately, this server costs and we rely on the help of site members to keep 4hv.org running. Please consider donating. We will place your name on the thanks list and you'll be helping to keep 4hv.org alive and free for everyone. Members whose names appear in red bold have donated recently. Green bold denotes those who have recently donated to keep the server carbon neutral.
Special Thanks To:
Aaron Holmes
Aaron Wheeler
Adam Horden
Alan Scrimgeour
Andre
Andrew Haynes
Anonymous000
asabase
Austin Weil
barney
Barry
Bert Hickman
Bill Kukowski
Blitzorn
Brandon Paradelas
Bruce Bowling
BubeeMike
Byong Park
Cesiumsponge
Chris F.
Chris Hooper
Corey Worthington
Derek Woodroffe
Dalus
Dan Strother
Daniel Davis
Daniel Uhrenholt
datasheetarchive
Dave Billington
Dave Marshall
David F.
Dennis Rogers
drelectrix
Dr. John Gudenas
Dr. Spark
E.TexasTesla
eastvoltresearch
Eirik Taylor
Erik Dyakov
Erlend^SE
Finn Hammer
Firebug24k
GalliumMan
Gary Peterson
George Slade
GhostNull
Gordon Mcknight
Graham Armitage
Grant
GreySoul
Henry H
IamSmooth
In memory of Leo Powning
Jacob Cash
James Howells
James Pawson
Jeff Greenfield
Jeff Thomas
Jesse Frost
Jim Mitchell
jlr134
Joe Mastroianni
John Forcina
John Oberg
John Willcutt
Jon Newcomb
klugesmith
Leslie Wright
Lutz Hoffman
Mads Barnkob
Martin King
Mats Karlsson
Matt Gibson
Matthew Guidry
mbd
Michael D'Angelo
Mikkel
mileswaldron
mister_rf
Neil Foster
Nick de Smith
Nick Soroka
nicklenorp
Nik
Norman Stanley
Patrick Coleman
Paul Brodie
Paul Jordan
Paul Montgomery
Ped
Peter Krogen
Peter Terren
PhilGood
Richard Feldman
Robert Bush
Royce Bailey
Scott Fusare
Scott Newman
smiffy
Stella
Steven Busic
Steve Conner
Steve Jones
Steve Ward
Sulaiman
Thomas Coyle
Thomas A. Wallace
Thomas W
Timo
Torch
Ulf Jonsson
vasil
Vaxian
vladi mazzilli
wastehl
Weston
William Kim
William N.
William Stehl
Wesley Venis
The aforementioned have contributed financially to the continuing triumph of 4hv.org. They are deserving of my most heartfelt thanks.
LastPass and KeePass are both very good options for the criteria you listed. Strong crypto, browser autofill, and portable enough.
LastPass encrypts your passwords locally, uploads the hashes to its database, and syncs them over all your browsers. You use a single master password to decrypt them.
KeePass is just a local encrypted database file that you can save anywhere, like on a flash drive or cloud storage. Same master password situation. It's a little more work than with LastPass, but I tend to trust it more due to its FOSS nature.
Either one you choose, these are your best bet for convenience and security.
Registered Member #72
Joined: Thu Feb 09 2006, 08:29AM
Location: UK St. Albans
Posts: 1659
I still haven't been convinced how any of those is better than what I have, or had anybody point out any significant flaw in mine. It does not need a data base, anywhere, so there's nothing to sync. It will run on any browser, so can deliver a password at any time you might want one. There is nothing special in the algorithm, save for SHA-1, so no physical space for a backdoor to exist, and it's FOSS so you can see it doesn't. You can always replace SHA-1 with one of the SHA-2s if you don't like its age, available from the same Chris Veness moveable type guy (first hit on google for 'sha-2 javascript'). Perhaps I'll put it github or codereview to see if that flushes out any criticism.
Registered Member #103
Joined: Thu Feb 09 2006, 08:16PM
Location: Derby, UK
Posts: 845
Use the same password for everything, and remember it (never write it down)
AND
for every service that you sign up to, add some random characters to the end of your 'remembered' password. You can write these characters down, or even put them on post-it notes.
Then you only have to remember one password, and you can write the extra characters down because they will be useless to anyone without the rest of the password
Registered Member #2529
Joined: Thu Dec 10 2009, 02:43AM
Location:
Posts: 600
First let me say, perfect security doesn't exist.
Bruce Schneier who is an expert on passwords says you should basically always write down your passwords.
The main purpose of passwords is to avoid joe random on the internet from cracking your account- they don't have access to your written down passwords.
But still, security is a personal thing, if you need protection from people near to you, and you're worried about people breaking in and finding the passwords, then you should take additional steps.
The idea that Avalanche suggests, of using the same password for everything is about the worst advice conceivable. Many sites have atrocious security and crackers breaking into sites will often find a list of passwords that they can then go around the internet with. If you have reused your password, then they can log in, everywhere and create mayhem, particularly sites like Amazon are very problematic.
It's sometimes reasonable to divide sites into 'low security' and 'high security'. High security is sites like email, online stores etc. Low security is forums. Using the same password on low security sites is probably reasonable, but all high security sites must have long, very difficult to guess and completely unique passwords.
That's where tools like LastPass come in; that permits you to manage multiple high security sites with (reasonable, but never perfect) security.
Even using the same base password for everything is a bad idea. If that base is discovered, it's trivial for an attacker to bruteforce the remaining few characters and compromise any of your other accounts. The best kind of password is a long, completely unique, and unpredictable sequence of characters.
This site is powered by e107, which is released under the GNU GPL License. All work on this site, except where otherwise noted, is licensed under a Creative Commons Attribution-ShareAlike 2.5 License. By submitting any information to this site, you agree that anything submitted will be so licensed. Please read our Disclaimer and Policies page for information on your rights and responsibilities regarding this site.