If you’ve sprouted out of a soft egg in the pitch dark abyssopelagic zone of the ocean and spent your time wrestling with atrocious angular fish – you know, the artistically ugly spawn crafted by the devil himself – for food, then you are one exceptional individual. Forget being crushed by the pressure of the watery depths, every other human would see nothing. Along with the spiky starfish that snooze under smooth stones miles above you, you’d also have a valid justification for knowing nothing about password managers.
Us normal people, on the other hand, know exactly what password managers are. They are acclaimed as software systems that store all of your usernames and passwords conveniently. You need to remember just a single password – a master password you create. Once a password manager is activated with the proper credentials, it will fill in the usernames and passwords automatically for any website for which your credentials are stored. In other words, you need not remember any of such credentials.
The Perfect Password Manager
Decades ago, when the internet was first becoming popular among the masses, many people used to keep their passwords not in a notebook safely hidden in a locked safe. No, that would have been a waste of precious seconds of their time. Gasp. Instead, many people would write their passwords on sticky notes… right on their desks near their computers. So, in the small (albeit still possible) chance hackers break into their houses, such malignant actors would have easy access to such sensitive information like bank account numbers and SSNs. Password managers are designed to prevent the slothful inclination of writing passwords on post-it-notes.
Therefore, the perfect password manager is constructed well enough as to allow a thief to gain access to your data should your desktop or, more likely, laptop land into the wrong hands. You better hope your device is off if it goes missing; or better yet, password-protected. As a reminder, in today’s age, a robust password is one that has the following criteria: 1) has 12+ characters, 2) has a numeric value, 3) has a lowercase letter, 4) has an uppercase letter, and 5) has a special character. Why all these pesky requirements? To reduce the chance of it being cracked by software via a brute force attack. Such an attack simply guesses a bunch of random combinations of letters and numbers in a short amount of time.
How I Manage My Passwords
By this point, you’ve probably assumed that I myself don’t use password managers for personal use. If that’s the case, you’re right. I never have and never will. I also don’t use the exact same password for every site that requires the creation of one. Presumably, many people did this back in the 1990s and early 2000s (aughts). Hopefully by now everyone knows not to use only a single password, just like practically everyone now knows not to inhabit homes built using asbestos and that smoking increases the risk of lung cancer.
So the question is, where do I store my passwords? In a Microsoft Excel file I named whywouldItellyou.xlsx. The file itself is encrypted with a strong password. The password to the Excel file is embedded in a PowerPoint file called myfavoritenonexistantgames.pptx. The font color of the “master password” is the same as the background of the slide it’s typed in. The myfavoritenonexistantgames.pptx file is attached to an AOL email I sent to myself with the subject line “My Little Pony.” The body of the email talks about homesteading as a woman with my five sisters. The password is in the body of the email in white font.
Here’s the kicker: I have never played with any My Little Pony toys, am not a woman, don’t homestead, and don’t have five sisters.
The details of the password-storing are inaccurate, but irrelevant. That said, the tactics themselves are representative of the manner in which I handle my passwords.
Where to Securely Store Passwords
I’ll break the tactics down. First, create a file that stores the passwords. Do not, I repeat, do NOT, name the file “passwords” or any name that makes the file’s intention obvious. Second, encrypt said file with a complex password. Third, create a second file with the password to the first file. Give this file a name to disguise its purpose like you did the first. Put text you find from any website into the second file. The website can be about anything – the solar system, Game of Thrones, IKEA, etc. Embed the password between the text in white font or whatever font matches the background color of the second file.
Fourth, send an email to yourself with the second file as an attachment. Possible email subjects to use: Things I Love About Uranus, My Favorite Game of Thrones Characters, Why I Love Shopping at IKEA, etc. Put text in the body that matches well with the subject. Or, alternatively, instead of emailing the second file to yourself, drag the file into a cloud service like Google Drive or Microsoft OneDrive.
Price of Security
I know what you’re thinking, this all seems so tedious. The price for the added security is a measly 10 minutes of your time. For me it was less time since I never used password managers in the first place. For as long as I had passwords – for about a decade and a half – I kept them in a file. Although, the first passwords I used for the file were rather weak by today’s standards. Back then, I simply remembered the passwords without creating a second file; or wrote them on a piece of paper, placing the paper in a location not near my laptop. I hadn’t come up with the elaborate scheme explained above until last year.
That password managers advertise that they are, well, password managers, make it obvious for anyone with malicious intent that they are linked to confidential data. You want to minimize the chance of personal data leakage.
As an analogy, compare a ten-story apartment complex to a neighborhood of residential houses without garages. For the former, burglars would have great difficulty identifying which car regularly parked in the parking area is associated with which room in the tall, multi-floor building. For the latter, it’s much easier to associate cars with living quarters, since owners park their cars near their houses. When said owners leave for a business trip or vacation, they are advertising that nobody is inhabiting the house. Considering the fact that many husbands and wives – particularly in poorer areas – share cars and children don’t drive, the analogy is not without flaws. Nonetheless, it’s adequate enough to drive the point.
You want to make it more of a hassle for anyone else to discover your passwords, not less. If it’s more inconvenient for you to deal with credentials, it’ll be more inconvenient for the deplorables as well.