Write it down somewhere. Just do it by hand.
Comment on "Anon" has problems with cybersecurity [Mod approved non-greentext]
Martineski@lemmy.dbzer0.com 5 months agoproceeds to generate password for each service and forget the master password
RecluseRamble@lemmy.dbzer0.com 5 months ago
Zachariah@lemmy.world 5 months ago
Yes, and the master should be a paraphrase not a password.
RecluseRamble@lemmy.dbzer0.com 5 months ago
That’s just recommended to emphasize length. If your password is as long as a passphrase it’s likely more secure (harder to remember though).
Zachariah@lemmy.world 5 months ago
But if the point is to remember it, then you should use the security from length of series of 5+ random words. It’s easier to remember, write down, and type. All great characteristics of a master passphrase.
XTL@sopuli.xyz 5 months ago
Also, you don’t need to write it down correctly, if you remember what’s the missing or different or fake bit. And you can write down a few decoy ones next to it. Or have it in two different places. Lots of room for obfuscation along with some good old fashioned physical security on where you store the note. And the backup note off-site, if you’re that kind of person.
Hell, just make some extra decoy ones just for fun and practice.
lurch@sh.itjust.works 5 months ago
just make the password a little story you can remember, e,g. “Carl+Lenny:go2a bar&spend$$$”
MeDuViNoX@sh.itjust.works 5 months ago
Hell naw, my last password was: Xé7&//sgn385d$@+îñccv72RtY¾ff°¥∆§
BubbleMonkey@slrpnk.net 5 months ago
My strategy for this is to have a second password manager available on a couple old devices, accessed with biometrics (fingerprint in this case), and only the master password saved within it.
I considered saving it within the main manager itself, since I have devices where I can use biometrics rather than password, but that feels like a bad idea.
Has definitely been a life saver
JackbyDev@programming.dev 5 months ago
Print out your recovery kit or master password and put it with your other documents (like birth certificate).
SkaveRat@discuss.tchncs.de 5 months ago
just use a password manager for the password manager password
Martineski@lemmy.dbzer0.com 5 months ago
Image
ichbinjasokreativ@lemmy.world 5 months ago
Or use a hardware key to unlock it. And then loose that hardware key. Does keepassxc support fingerprints yet?