• AceOnTrack@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    13
    arrow-down
    22
    ·
    2 days ago

    People aren’t lazy, we just don’t give a shit about cybersecurity, it’s not as big of a deal as IT makes it.

    I use an Excel worksheet for my passwords.

    At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.

    For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.

    I ain’t remembering all that.

    I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It’s even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.

        • mountainRadish@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          4 minutes ago

          At least password protect it. If your company allows it then install a password manager it is waaah easier and even enters the password for you and it is FREEE and open source

    • Godnroc@lemmy.world
      link
      fedilink
      English
      arrow-up
      27
      arrow-down
      3
      ·
      2 days ago

      And I’m sure the person who steals that file will really appreciate the effort you put in.

      I’ve literally searched networks for files with the word “password” in the title to find documents just… sitting on a network drive anyone could access.

      At the very least, go get KeePass! It’s free, can run without installation, and can even type for you.

          • AceOnTrack@lemmy.blahaj.zone
            link
            fedilink
            arrow-up
            2
            arrow-down
            3
            ·
            2 days ago

            Ok but consider this:

            Keepass requires to type a master log in, and is therefore a password I don’t care to remember, and would add to my excel password sheet, defeating the purpose of keepass in the first place.

            I don’t think you understand the amount of apathy the average worker has for their company.

            I use keepass at home, and set it to use a password and a key file because I actually care.

            I genuinely don’t care if someone hacks into my office account to do… Whatever. Worst that can happen to me is getting sent to some on the clock cybersecurity awareness program where I’ll be nodding off on my chair doing no work while an IT nerd rambles on about… Whatever it is they ramble about in these things, I never paid attention.

    • baines@lemmy.cafe
      link
      fedilink
      English
      arrow-up
      9
      ·
      2 days ago

      savages?

      real men use a plain text fill named notmypasswords to throw off hackers

    • wonderingwanderer@sopuli.xyz
      link
      fedilink
      arrow-up
      4
      arrow-down
      2
      ·
      2 days ago

      Dude just get keepassXC… it literally creates an encrypted vault for your passwords and it’s all stored entirely locally on your device.

      The only potential inconvenience might be that it doesn’t integrate with browser/apps as far as I know, but you can copy/paste from it and it can even generate random strings for you to use when creating new passwords.

      Literally just one password to remember, to open the vault, and all the rest can be stored securely. Two passwords if you use a different one for your desktop login, but that’s still manageable.

          • doubleaught@lemmy.today
            link
            fedilink
            arrow-up
            2
            ·
            19 hours ago

            Exactly, massive IT failure. Unique passwords are required and should be used everywhere. Yet without a way to generate or access them, you end up with this dude, and I don’t blame them one bit!

            Passkeys are actually better for situations like this. (And others, I’m just not a universal fan for every possible use case.)

            • wonderingwanderer@sopuli.xyz
              link
              fedilink
              arrow-up
              1
              ·
              18 hours ago

              Passkeys are actually better for situations like this

              Is that like when you have a really long unique string of random characters stored on a flash drive and you use it to unlock your computer instead of a password?

              I think those can be beneficial cause if there’s a data breach and all your passwords are compromised, they wouldn’t get your passkey, right? It would require physical access to the USB.

              But the downside is then you have your passkey on a USB, and if someone gets their hands on it they can copy it and use it.

              So I think a hybrid approach is best (when it’s not overkill), and have your passkey on an encrypted, password-protected flash drive so that it requires both physical access and knowledge of the password.

              But unless you’re in government, healthcare, or deep in some industry where absolute confidentiality is supremely critical, it’s probably overkill

        • Zarobi@aussie.zone
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 days ago

          Yeah, some company I.T. policies ban password managers, which is extremely dumb… But also like, what’s there to do about it? Not my decision and we still gotta work.

          I think I remember at some point putting my passwords inside an encrypted 7zip archive that itself had a password. No idea how secure that truly was, but it made me feel better.

          • helpImTrappedOnline@lemmy.world
            link
            fedilink
            arrow-up
            3
            ·
            2 days ago

            They might allow the browser’s built in manager. Good chance if they’re a Microsoft shill, edge’s built in would be better than nothing…although it’s Microsoft so a text file might be better.

            IT probably bans them because they can’t access the data. Keepass files are some kind of container, you can store any file with in it. Great when you want save a txt doc with 2fa recovery codes or something and also not a bad way to send a payload that’s impossible to scan. “I’m going on vacation, please use this keypass file for vendor XYZ, open the file within for the vendors contact info”.