Is my password management safe or complete garbage?

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Elganja

Platinum Member
May 21, 2007
2,143
24
81
I think this still belongs in off topic?

I want check in with the internet crowd on my crappy way of managing numerous logins. Like most of you, I have tons of logins/pws for various sensitive and inane crap on internet (banking, credit cards, insurance, forums, etc).

1. I decided to maintain a spreadsheet with manual entry for all these sites containing login/pw.
2. That spreadsheet is in cloud only (Google Drive), never offline.
3. My Google pw is very strong (maximum chars, symbols, numbers, etc).

This gives me the benefit of easily accessing my login/pw anywhere I go via my phone (which also has a screen lock). The risk is obviously that if my Google account is hacked, I am facked royally. And also, Google can do something with it too (company hacked or a malicious employee).

Google being the #1 tech company, I'd like to think they have the best security.

Is my method okay? As I'm typing it out, it just sounds risky. What's the best way then while maintaining easy access (via my phone preferably).

similar system for me, however anywhere i can use 2-step i do... e.g. google 2-step, apple id 2-step, financial institution 2-step, etc...

if google gets hacked, then the passwords are the last of my worries... lol
 

zinfamous

No Lifer
Jul 12, 2006
110,810
29,564
146
Sorry man but I have to go with "complete garbage". You don't want a single or central point of failure for anything that's important to you. Nothing inherently wrong with throwing some stuff up on google drive, but anything important needs to have secure copies in other places just in case. Online AND offline.

On top of that, you never ever want to be storing your list of logins or anything of equal importance in any sort of bare or unprotected format. This means if you're emailing yourself logins, or if you're storing a plain text file or word document or excel document in the cloud, you're exposing yourself to unnecessary risk.

You can easily add orders of magnitude more protection by simply placing said file inside a heavily encrypted file container. You can do this any number of ways - using a program like Veracrypt is one. Upload the encrypted file instead, and to more than one place.

IMO, something like this is really the bare minimum. Don't leave it up to a third party or up to luck for nothing bad to happen to you.

It's always a trade-off between security and convenience. You can save all your passwords in your browser, but then you're leaving yourself more vulnerable to any browser-level attacks. You can use a service like Lastpass, but then you're leaving yourself at the mercy of their security systems and practices. You can save all your logins in a plain text file, but then anyone that gains access to the device in which it resides can access your logins. You get the idea. If you don't want to compromise any convenience, then you will inevitably compromise some level of security. For me, prudent use of an encrypted volume backed up in a number of places that couldn't possibly all be compromised simultaneously makes the most sense.

This is what I do, but it is 100% secure because the text file is named: Ishtar 2_script.txt
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |