We launched new forums in March 2019—join us there. In a hurry for help with your website? Get Help Now!
    • 10913
    • 66 Posts
    So how do you manage passwords? This question popped to my mind as I’m trying to find a suitable password management software for a company usage. So this means it has to be collaborative.

    For my personal usage I have 1Password set up on two machines with DropBox syncing enabled. I’ve been using 1Password for couple of years now and because of that I use quite complex passwords. And this is the reason I’ve been given a password paranoid stamp at work smiley

    For the task in hand I’ve discovered basically only one suitable software, [urlhttp://cpassman.org/]cPassMan[/url] or Collaborative Password Manager. Because of the limitations all Windows based software are out but on the other hand web based are ok. CPassMan is nice but doesn’t quite fit our needs so I’m thinking creating a 3pc for Revo and using it as the base for our password manager. If I have the time...

    Now I’d like to hear your thoughts about password management software in personal, corporate or both usages.
      The sun always shines for tough guys.
      • 16702 ☆ A M B ☆
      • 536 Posts
      Last Of The Romans Reply #2, 16 years, 1 month ago
        palma non sine pulvere
        • 1343 ☆ A M B ☆
        • 2,213 Posts
        lastpass.com should do the trick
          Patrick | Server Wrangler
          About Me: Website | Tweets |  MODX Hosting
          • 10913
          • 66 Posts
          Lastpass could do the trick. I’m a bit paranoid on trusting the "cloud". For us it’s really not that important to share outside our network. But this is definitely a good alternative to point to.

          Keepass is really nice software. I did use it couple of years ago, when my primary machine was Debian. I did use it maybe 2 or 3 years. But it just doesn’t cut in this situation.
          The main reason for switching from keepass to 1Password for me was the Apple-like interface. Keepass on Mac ain’t that pretty. I’m not saying it was pretty on linux but it did fit right in with my wm. And I did get 1Password in a macheist bundle as a side product so why not use it.
            The sun always shines for tough guys.
            • 34162
            • 1 Posts
            1. Use combinations of letters, numbers, and (when applicable) special characters.
            2. Mix upper case and lower case when passwords are case-sensitive.
            3. Keep them to about 8 characters on average.
            4. Don’t use regular words or phrases. The more straightforward the password, the easier it will be to hack.
            5. Don’t use numbers associated with your identity (such as birthdays, phone numbers, social security).
              • 2200
              • 1 Posts
              Quote from: skyvia at Aug 17, 2010, 10:26 PM

              1. Use combinations of letters, numbers, and (when applicable) special characters.
              2. Mix upper case and lower case when passwords are case-sensitive.
              3. Keep them to about 8 characters on average.
              4. Don’t use regular words or phrases. The more straightforward the password, the easier it will be to hack.
              5. Don’t use numbers associated with your identity (such as birthdays, phone numbers, social security).

              This is the best method to manage a password. I too use my password as above with a combination with case sensitive. I keep my password upto 10 characters. I secured these passwords by encrypted and protected by a password.

              [admin note: link removed]
                • 10913
                • 66 Posts
                Quote from: arvel789 at Aug 19, 2010, 07:19 AM

                Quote from: skyvia at Aug 17, 2010, 10:26 PM

                1. Use combinations of letters, numbers, and (when applicable) special characters.
                2. Mix upper case and lower case when passwords are case-sensitive.
                3. Keep them to about 8 characters on average.
                4. Don’t use regular words or phrases. The more straightforward the password, the easier it will be to hack.
                5. Don’t use numbers associated with your identity (such as birthdays, phone numbers, social security).

                This is the best method to manage a password. I too use my password as above with a combination with case sensitive. I keep my password upto 10 characters. I secured these passwords by encrypted and protected by a password.

                Although this info in nice it’s not what I asked. My password generation software does these kind of thing automagically based on my preferences. So I know how to generate this stuff.

                I wanted to know how and where do you manage and store these generated password.

                Well here’s a little update in my process. Decided to go with cpassman. I can store the data in our local server and update the code and user experience if needed. I’ve upgraded it’s password generation script to a better one already. In overall cpassman seems to be quite nice.
                  The sun always shines for tough guys.
                  • 4028
                  • 5 Posts
                  Does anyone else have any suggestions? I’ve been using an Excel sheet that’s encrypted and kept in svn, but it’s getting very cumbersome.
                    Brian R Cline
                    BRCline Consulting
                    Niagara Falls,Ontario,Canada
                    http://www.brcline.com
                    • 4971
                    • 964 Posts
                    Has anybody used clipperz?
                    they say it is zero knowledge tech!!
                      Website: www.mercologia.com
                      MODX Revo Tutorials:  www.modxperience.com

                      MODX Professional Partner
                      • 20407
                      • 82 Posts
                      I’ve been using LastPass for a few months and am quite happy with it. It allows you to share passwords with selected other LP users (the feature the OP was looking for). Everything’s encrypted and no one at LastPass can access your passwords (see http://lastpass.com/whylastpass_technology.php).

                      The only vulnerabilities I can see are: 1) a keylogger could theoretically get your master password and gain access to all your passwords, and 2) laziness on the user’s part, because LP makes it so easy to have everything happen automatically, including remembering your master password (you can turn this off and also require the master password to be retyped for certain sites).

                      As an aside, does anyone know how common keylogging malware actually is?