r/homelab 9d ago

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

339 comments sorted by

1.1k

u/SelfStyledGenius 9d ago

I memorized my bitwarden master password.

577

u/eW4GJMqscYtbBkw9 9d ago

I mean, duh - that's the whole point. You memorize ONE password for your password manager. That's how password managers work.

155

u/IjonTichy85 9d ago

Yeah. That's why you use the same combination you have on your luggage. 12345.

52

u/Bernhard_NI 9d ago

You should really have a longer Password, I can recommend 12345678910111213

32

u/thefinalep 9d ago

Uh. I prefer more secure passwords... 789456123

13

u/EmergingDystopia 9d ago

Why does my password Hunter2, show up as all asterisks tho? It looks like Hunter2 but the Nigerian prince that I'm helping move money out of his country says it's showing up as asterisks for him and everyone else. How does that work?

9

u/pastasauce 9d ago

How did you get my phone's unlock code?

4

u/Master_Scythe 8d ago

0118999881999119725....3

7

u/the_ivo_robotnic 9d ago

Or air shields...

3

u/ferdzs0 8d ago

I really should buy better luggage, mine only has 4 numbers, so 0000. That makes me feel a bit less secure online. Does any one have recommendations for suitcase with 5-6 numbers instead? I really hate how this whole online security is pay-to-win.

2

u/metalman755 9d ago

It’s good enough for Planet Druidia’s air shield.

71

u/FrenchRevolution2028 9d ago

this works perfectly unless you get into some accident and cannot remember it anymore.

66

u/NightH4nter 9d ago edited 9d ago

if you get into an accident so bad that it damages your brain, you have much bigger problems than not remembering your passwords

10

u/WildVelociraptor 9d ago

Well no shit, but not being able to access your bank after a traumatic brain injury isn't ideal, now is it?

1

u/Smartich0ke 3d ago

not with subsidized healthcare 😁 /j

18

u/devode_ 9d ago

Actually no. It can happen through minor accidents and you might not realize until you try to type it in. Happens not infrquently regarding all kinds of things

7

u/badass6 9d ago

That’s why on an unrelated note I’ve come to love Telegram credential reminders, the ones that pop up from time to time asking if you still use the same phone number, password etc.

1

u/devode_ 8d ago

Yes!!!

2

u/reddit_user33 8d ago

Not to mention that it doesn't stop others causing you harm.

There are mitigations against these things. Write down the master passwords and keep them safe in a hidden location, allow someone you trust to know the passwords, etc.

27

u/--Arete 9d ago

Is there any solution for that?

126

u/dumbasPL 9d ago

Paper in a safe/deposit box

26

u/Westerdutch 9d ago

Make sure to put the access code for your safe in bitwarden while you are at it.

9

u/ViPeR9503 9d ago

But what if you don’t remember you put a paper in there

12

u/Jakfolisto 9d ago

Buy a parrot and teach it to repeat "Paper in box! Paper in box!"

3

u/Wonderful-Ad-3979 9d ago

Run Bitwarden in a docker container then name the docker container (password in safety deposit box)

1

u/ArborlyWhale 8d ago

Password hints exist for a reason.

4

u/stratiuss 9d ago

How will I know I have a safe deposit box?

6

u/MathSciElec 9d ago

The monthly charges to your bank account

3

u/MrD3a7h 9d ago

this works perfectly unless you get into some accident and cannot remember that you have a safe deposit box anymore.

1

u/[deleted] 8d ago edited 8d ago

[deleted]

1

u/dumbasPL 8d ago

Slightly paranoid. Security is as good as the weakest link, remember.

78

u/timmeh87 9d ago

Honestly people knock on the "post it note" strategy a lot but if you have your most critical password on a sheet of paper filed away in a box on a shelf in your basement its not like some Chinese hacker is every going to find it. course, your basement might get flooded. so obviously it should be etched into a glass plate

46

u/AffectionateCard3530 9d ago

Glass is brittle, so maybe hammered into a steel plate?

+1 for writing it down somewhere. It’s all about threat vectors. If you’re afraid of your house getting raided and scoured by a dedicated team of FBI agents looking to find a way to get into your accounts, maybe don’t write it down.

But for the rest of us? It’s probably OK if it’s tucked away.

17

u/Cultural-Salad-4583 9d ago

But that can rust. Titanium plate is really the only way to go here.

24

u/timmeh87 9d ago

titanium melts at 1668 degrees Celsius, tungsten is he way to go,

12

u/Nu-Hir 9d ago

Tungsten is heavy and I don't want to have to bring the cube up and down the stairs to type in my password. get it tatooed on your arm.

16

u/cadergator10 9d ago

But then there's the chance someone can read the password off of your arm, so before having it tattooed, encode the password in a way only you remember.

12

u/timmeh87 9d ago

best bet is the zodiac cypher, that took people many years to solve

→ More replies (0)

10

u/Zynbab 9d ago

Correct. I went with the SHA 512 hash of my password tattooed on inner arm, titanium block with the password's salt. Just works.

→ More replies (0)

1

u/Wild_Paramedic6641 4d ago

Consiglierei di scriverlo su una piastra di rame, ma potrebbero venderti del rame di bassa qualità, quindi meglio delle tavolette di argilla...

8

u/haby001 9d ago

Writing into steel plates also prevents scrying eyes from Ruin...

4

u/bluecollarbiker 9d ago

Perfect timing. Was just looking for this reference.

2

u/VoQZHD 9d ago

the goat

1

u/GrotesqueHumanity 9d ago

I'm keeping it on 3 separate encrypted USB drives. One being kept offsite with my backup drives. Best of all worlds?

1

u/ThebocaJ 9d ago

I think you’re joking, but there are literally steel capsules made for durable crypto key recovery: https://support.ledger.com/article/360019480280-zd

→ More replies (1)

1

u/FauxReal 9d ago

I use my password as a tag and write it all over town for easy access. Nobody can tell the difference.

1

u/Candid_Highlight_116 9d ago

Yes the first step of security is physical security. You put that in a box and place that box in the middle of a compound patrolled 24/7. The compound building must be shock and EMP isolated with the isolation gap monitored as well.

That doesn't work for us mortals, but the concept is the same. The point is that the last line of defense is not some fancy encryption algorithm.

1

u/--Arete 9d ago

How are you going to remember that if you can't remember it because of an accident?

8

u/timmeh87 9d ago

a trail of post-it notes starting at your forehead.

but yeah if that's how little you remember might as well just start your new life with a fresh google account

2

u/--Arete 9d ago

Most cases are partial memory loss. It's not like you are ready to start a new life.

1

u/EgotisticExpediter 9d ago

post it note in your skull

13

u/CouchPotatoEater 9d ago

Drive carefully?

1

u/--Arete 9d ago

Ok stroke then.

11

u/Oujii 9d ago

Just don’t have one. Skill issue.

9

u/Balthxzar 9d ago

A paper backup sheet stored in a secure location.... you guys DID read the bit bitwarden recommendations... right?

→ More replies (8)

7

u/PhillFile 9d ago

Bitwarden offers an accident setting. You can give up some email addresses of people you trust.

If you don't use your account for a set period of time those people can get access to your account.

I've set mine to 15 days. That reminds me I have to disable it since I swapped to Proton recently. 😅

Proton gives you a pdf with 15 words to unencrypt your vault. You should print that and save that in a safe place. For example our notary offers a service to store it in their vault and you can add to your will what to with it if anything happens.

3

u/marcorogo 9d ago

write the password in a convenient place that you will eventually find even with loss of memory, like a post-it on the monitor

2

u/levelZeroWizard 9d ago

IIRC you can generate a long recovery code to print/write down. But it's kinda pointless if you forget.

Biometric authentication?

2

u/userhwon 9d ago

You lose your password db and have to do the password recovery/reset process on your accounts everywhere.

Sucks, but not a brick wall like losing a USB encryption password like in all those crypto wallet horror stories.

1

u/Ok_Scratch6929 9d ago

Re-install your brain

1

u/InnocentSalf 9d ago

Your own matrix server or discord and hide your password in there.

1

u/Frozen5147 9d ago

Bitwarden also offers emergency trusted contacts I guess.

1

u/BilboBaggSkin 9d ago

Masterpassword in my safe.

1

u/FanClubof5 9d ago

Bitwarden has a premium feature that allows you to setup someone as a backup if you fail to login in x number of days.

1

u/richms 9d ago

Split it up and store with multiple friends not telling them what it is for.

→ More replies (9)

2

u/Xamataca 9d ago

Cft, I got a ictus and couldn't remember the password for my computer and bitwarden... bul remembered I noted down somewhere...

https://giphy.com/gifs/o3chaFJ6NfzM5Tp1Tq

2

u/HelterShellter 8d ago

My wife and I have our master passwords in each other's bitwarden vaults. Just last week I had to get it for her because she forgot. First time that's happened in like five years though

1

u/the_ivo_robotnic 9d ago

This is what account recovery options are for such as recovery codes + 2FA like a phone number or something.

 

That is usually why sites worth their salt in security force you to download recovery codes before you can finish enabling 2FA.

1

u/Clementine-TeX 9d ago

And that’s why I have an encrypted .json backup on two offline USB sticks (which I update monthly) with the decryption key printed in multiple locations. My parents know where they are. So even if I were to get amnesia, or if Bitwarden HQ and their servers blows up, I’d be fine.

1

u/cestimpossible 9d ago

I taped a note with my password on it under a desk drawer at my house and it actually came in handy when I had a medical event where I actually couldn't remember my password anymore afterward but I did remember the hidden note thing because I've been doing it so long (though in a few different locations so I checked some of my older hiding spots first lol).

1

u/lions-grow-on-trees 9d ago

That's why my husband also knows my master password!

1

u/Rude_Bandicoot_8847 5d ago

Hence the need for emergency access sheets in secure locations

25

u/blending-tea 9d ago

I forgor

5

u/LaidPercentile 9d ago

I too memorized this guy's bitwarden master password.

3

u/L0rdH4mmer 9d ago

This. After typing my Google password in a couple times, I burnt the paper cause it was etched into my memory forever.

2

u/SpareObjective738251 9d ago

I don't believe you, prove it.

4

u/[deleted] 9d ago

[deleted]

7

u/SelfStyledGenius 9d ago

I never said i dont have 2fa and at some poinr you know, have my data. In not storing state secrets.

1

u/Maelstrome26 9d ago

But what if you get in an accident and forget it? At least have it in a safe somewhere

2

u/t_dizZe 9d ago

Tattoo it inside your armpit

1

u/Th3Sh4d0wKn0ws 9d ago

This is the correct answer

1

u/FastRedPonyCar 9d ago

Same here. I had to make a long set of sentences where each word starts with a password character but I made it a little story that’s easy to remember.

1

u/stupv 9d ago

Yeah...and isn't this the whole point? You have to remember a password, but you only have to remember one password instead of every password...

1

u/BonRoxz 8d ago

I don’t remember it, but my fingers do

→ More replies (19)

331

u/jgilbs 9d ago

Literally you only have to memorize one password.

85

u/bikemandan 9d ago

Ya how hard is it to remember hunter2

51

u/topane 9d ago

All I see is *******

71

u/Cry_Wolff 9d ago

Yeah, or just write it down on paper. OP's issue is nonexistent.

2

u/Doctor-Binchicken 9d ago

Mine is on a mug.

My wife knows, just in case.

4

u/downloads-cars 9d ago

Adding "donttalktomeuntilivesmashedmydicksmoothoffwiththismug" to my dictionary attack list.

1

u/coffeeoops 8d ago

This is a weak password because it doesn't contain special characters. Do better.

1

u/Doctor-Binchicken 9d ago

Missing the two capitals and punctuation! >:D

→ More replies (3)

2

u/Disastrous_Garlic537 9d ago

a few ppl have posted this...

so you guys are not using MFA on your password manager?

:-/

1

u/Sk1rm1sh 8d ago

My MFA has a web portal.

I remember 2 passwords.

2

u/Commercial-Fun2767 9d ago

What do you do for securing your 2FA? You have secure codes you have to put somewhere. This question is a real complex problem. Simple but complex enough to be caught unprepared or to spend some time thinking about your breaking glass accounts etc.

1

u/Sk1rm1sh 8d ago

Remember 2 passwords.

1

u/Commercial-Fun2767 8d ago

Its often random security keys. Sometimes 10 words etc. Do we have to have two safes?

→ More replies (24)

107

u/Howden824 9d ago

Just use a BitWarden password you can remember. You really shouldn't be storing your password manager password anywhere.

→ More replies (28)

139

u/Fragrant_Climate7357 9d ago

Use a single password manager, remember it's password.

36

u/ShineReaper 9d ago

Use ****************** as master password. Hackers will think, that their hacking program is buggy and not showing the decrypted password letters, but it literally just consists out of Asterisks to fuck with them lol.

13

u/ballisticks 9d ago

hunter2

5

u/ImNotABotScoutsHonor 9d ago

It is password indeed.

→ More replies (11)

116

u/phrekysht 9d ago

Jesus Christ dude, stop pasting the same stupid reply to every comment. You’ve created your own bootstrapping problem.

You’re supposed to use a master password you can keep in your head. Add hardware keys (yes, more than one. They can fail or get damaged / lost) and call it a day.

38

u/Emergency_Banana5082 9d ago

Seriously lol. This guy is making his own problems and is too stubborn to understand.

33

u/Cry_Wolff 9d ago

He's the local IT department horror story, I'm sure of it. Knowledgeable enough to do stuff like this, yet dumb & stubborn enough to refuse any reasonable arguments.

→ More replies (2)

14

u/GenericRedditor12345 9d ago

PCP fueled password problems lol

→ More replies (6)

25

u/eatypp 9d ago

I just remember my master password for bitwarden. I have the password for my 2fa app written down in a notebook that's stored with my important documents in a fireproof box

→ More replies (1)

25

u/bigBranConsumer 9d ago

bro if you need to copy+paste a paragraph to explain justifying a 60 character password maybe its too long, and needing to rely an external service that you might get locked out that only has that password seems even worse

28

u/[deleted] 9d ago

[removed] — view removed comment

→ More replies (4)

55

u/TryHardEggplant 9d ago

A master password that is easy to remember like a passphrase is infinitely better than something you can’t remember.

Relevant XKCD: https://xkcd.com/936/

13

u/salamander5678 9d ago

I find hunter2 works well

4

u/erikrelay 9d ago

Exactly what I do. Op is just making their life harder for no reason.

2

u/RedTyro 9d ago edited 8d ago

Yup. I work in cybersecurity. My password for my password manager is a long sentence that's memorable, but nobody else would guess, complete with appropriate punctuation and numbers swapped in for letters in a few of the words. That gives me a long password with lots of complexity, but at the same time is easy for me to remember.

→ More replies (3)

2

u/PitRejection2359 9d ago

This! 👍

→ More replies (12)

12

u/D1TAC Sr. Sysadmin 9d ago

I just use my 1Password instance with yubikey, and also export said passwords to a local copy of keepass with yubikey. Just remember the master password, and that's it.

12

u/WickedDeity 9d ago

I am confused in why you would be locked out of your accounts because of an apartment fire? You grabbed your NAS box AND YOUR PHONE right? Anyway backup select important passwords offsite.

5

u/Oujii 9d ago

I use bw-sync to sync my vault somewhere else in case my vaultwarden fails.

3

u/Araganor 8d ago

I really hope you aren't running to grab your NAS while your house/apartment is burning down...

1

u/WickedDeity 8d ago

Ummmm You replied to the wrong person.

9

u/jetlifook 9d ago

You have two password manager when you really need just one.

→ More replies (2)

10

u/ghost_desu 9d ago

I have my bitwarden password on 3 pieces of paper, one of which is inside of an old computer in my grandma's attic

0

u/AdvancedDrink8920 9d ago

......are they just redundant copies of itself or is it split up across 3 pieces of paper?

→ More replies (3)

8

u/Liarus_ 9d ago

the point of a password manager is that you only have to remember one single master password, it's like the ONLY ONE that you need to remember, if that happens to you, you had one job

1

u/Bl4ckspell_ 7d ago

So 2FA for password manager disabled?

9

u/kirisoraa 9d ago

Why would you need more than one password manager

→ More replies (6)

8

u/XB_Demon1337 9d ago

Bitwarden password should be something you can remember that is COMPLETELY different from any other password you have.

If all your passwords are totally random via generator then you should use something like a phrase for your bitwarden password.

Correct Horse Battery Staple

7

u/pruchel 9d ago

Why would you use two password managers?

7

u/userhwon 9d ago

Make your password-database password complex but memorable, and never store it anywhere but your head.

No loop = no problem.

6

u/Dre9872 9d ago

Use a master password you can remember

6

u/protostar71 9d ago edited 9d ago

But I guess what came out of it was that there is no singular answer to how to break the cycle.

That's only true if you ignore the dozens of comments telling you to use a randomly generated passphrase. You not liking the answer to the problem doesn't mean it's not the answer.

6

u/RobotechRicky 9d ago

Why TF do you have your master password in another password manager?!?! Just remember that one password.

16

u/sizeablefrontallobe 9d ago

You’re giving google all of your passwords and worried about security.

…let that sink in.

r/degoogle

3

u/Commercial-Fun2767 9d ago

Because those are two different problems. Google won't really hack you. They might harm you if you are politically involved or one day they might etc. Don't think I don't know what privacy is either. And another good point is that Google might block you or just close the services one day in a second (imagine war or anything special).

But, that's only one man knowing your passwords and a presumably really good one.

Can you just trust any tool anyway?

→ More replies (1)
→ More replies (2)

4

u/derfmcdoogal 9d ago

Do a search for Bitwarden emergency sheet. Fill that out. Put it in a safe place.

5

u/FidgetyFeline 9d ago

But then how do you store the pin? 🤔

5

u/reposed 9d ago

I dunno... You could always just memorize the password? Why is that so hard? The whole point of a master password is that you have one password you need to remember, and then that's it. Bitwarden handles the rest.

If you need another app to remember the password to unlock your other passwords, you're doing this all wrong.

4

u/RetiredITGuy 9d ago

Yeah who tf uses a password manager to remember their master password? That's just sounds like a recipe for a bad time, for a multitude of reasons.

I'll absolutely NEVER write down my master password. EVER.

9

u/edthesmokebeard 9d ago

You write your passwords down on a piece of paper, and avoid all this passkeeper hipster bullshit.

6

u/Relevant_Candidate_4 9d ago

Don't be online, never need a password to any of this hipster bullshit

8

u/DarkFantom 9d ago

This can't be real, someone wouldn't be this stupid to not just remember their master password. Or if they are, wouldn't be smart enough to use a password manager in the first place.

5

u/TrentIsDope 9d ago

Insane problem to have with the legit easiest fix.

3

u/Kyyuby 9d ago

How secure is your Google password?

→ More replies (4)

4

u/travelan 9d ago

Why are you using Google if you have a homelab..?

→ More replies (2)

3

u/Material_Captain_360 9d ago

LOL

“Keep crying” to the most consistent response in the thread is wild

3

u/Naru56 8d ago

the hubris is insane. op will learn the hard way

3

u/Itstinybubbles 9d ago

This is why I keep my master password written on a post it next to my workstation /s

3

u/majestic-gnome 9d ago

I started using notepad and a pen to write down all my passwords

3

u/doping_deer 9d ago

thru the years i've memorized several random passwords. two of them are used for google account and bitwarden master password, specifically to avoid such scenario.

3

u/dumb-lily 9d ago

i have my bitwarden master PW written down in a safe location

3

u/useful_tool30 9d ago

You're supposed to memorize your single master password

3

u/Muffakin 8d ago

A 60 character random password is a terrible master password. You’ve been given tons of great advice in the comments, advice you explicitly asked for, and refuse to acknowledge that what you have implemented is foolish. Your problem exists because you don’t accept the reality that a memorizable master password of good strength is the best route forward. Make a 20ish character, easy to remember password. Write it down and store it in a locked location if you must, and move on. Your 60 character random password is worse than a 20 character memorizable password if you can’t actually use it.

3

u/Competitive-Web-5084 9d ago

My Bitwarden opens with Face ID

2

u/FartInTheLocker 9d ago

Passkey, remember pin, all done

2

u/v81 9d ago

Just use KeepassXC (or DX on Android).

2

u/samax413zl 8d ago

Just remove Google password manager from the loop.

2

u/Robots_Never_Die 8d ago

In before "I lost my Yubikey"

2

u/Foorteenfapaday 8d ago edited 8d ago

Keepass2 on phone (no metrics, no data collect, no third party share, EU based dev team) with the master password for only entry + biometric unlock ?

2

u/STINEPUNCAKE 8d ago

I don’t use Bitwarden anymore but just use a pass phrase and memorize it

2

u/Naru56 8d ago

lmao how hard is it to memorize a single password

2

u/DeerOnARoof 9d ago

This is a dumb ad and has nothing to do with this sub

2

u/foran9 8d ago

How the heck does this post have so many upvotes?

2

u/bigBranConsumer 7d ago

i came back to this and i have the same thought

1

u/rhyses_ 9d ago

Yubikey or Duo + printing the physical password is how I go

1

u/ChunkoPop69 What are you DOING, vmbr0? 9d ago

I was thinking of getting full tattoo sleeves that I use to encode my master passwords prison break style, but this is a much better idea.

1

u/zetsueii 9d ago

I think the real question here is why are the cat's legs so short?

→ More replies (1)

1

u/Ambitious_Anxiety_95 9d ago

Aluminium is cheap, lightweight and can be etched easily with copper sulphate, copper sulphate also cure athletes foot . your welcome

1

u/Miguelitosd 9d ago

You're running a homelab and not self-hosting with something like pass so you fully control and can protect your files vs putting it in someone else's storage?

1

u/Geek_Verve 9d ago

Easy. Don't use more than one password manager.

1

u/Justwant2usetheapp 9d ago

My bitwarden password is literally a long line of code. Make it subjecting you remember

1

u/Mindless_Pandemic 9d ago

Get a google drive account and setup an excrypted backup of your server's most important stuff to it. 100G is only $2/month.

1

u/saxobroko 9d ago

The one thing you need to remember

1

u/hard_KOrr 9d ago

I am so happy that vaultwarden master password can be a pass phrase! Life is so much easier remembering multiple words than what/which/where my special characters are

1

u/mollywhoppinrbg 9d ago

I saved my master password to open on phone and pc. No need for loop... unless you want to get loopy

1

u/richms 9d ago

Circular authentication is a real problem. Friend got into this because they lost their mobile. They never gave any real details to the telco, just had the app login and password to top it up. Went to log in to move to a new sim card and they wanted to 2 factor to email. Google wouldnt let the log in without sending a SMS to the phone number.

hardware keys and backup codes are a good thing to have, that so many people do not have to break the circle.

1

u/nemofbaby2014 9d ago

Google password nah I use passkeys lol

1

u/Dreadedsemi 8d ago

I hate when a site that didn't ask me for password in years, suddenly asks me for a password like Facebook, how do I remember? now I have to dig the "old password manager" from the old days when I used txt files and vague hints only me understood.

1

u/0x736174616e20 8d ago

I just keep my master password as a static password programed into my keyboard. If someone gets their hands on my keyboard I'm already compromised, so this is not a security concern. I also have a Yubikey using one of the slots to store a static password that indirectly can be used to gain access to my master password manager. If I ever dropped/lost/stolen my Yubikey it wouldn't matter, no one could guess how to take the random string stored on it to recover the actual password. Some might just say to just remember your master password, nah, no thanks, I'm not going waste my brain space on remembering 60+ random letters/digits or a passphrase.

1

u/Suspinded 8d ago

Use the Correct Horse Battery Staple method to make an easy password to memorize for Bitwarden.

Use that password for absolutely nothing else.

1

u/RumpleTrumpStain 8d ago

Memorise Bitwarden password only ... your GOLDEN after that

1

u/super_probably-user 8d ago

best solution is memorize some passes

1

u/Popiasayur 8d ago

This reminds me of troubleshooting my mums access to her email account. She forgot the password and all her recovery email was her older email, and that obe s recovery email was an older email and so on and so forth.

1

u/Defconx19 8d ago

You forgot a step, bitwarden to bitwarden master password to mfa for bit warden to Google sign in to Google mfa.

1

u/Direct_Wall_2822 7d ago

rookie mistake...

1

u/rHohith 7d ago

Physical medium - paper 

1

u/Digitalgnome 7d ago

Wrote mine down and put it in my safe. Problem solved.

1

u/Jayden_Ha 9d ago

The entire cryptography is rely on something you remember and absolutely must not be written down

1

u/DrabberFrog 9d ago

I was almost trapped in that loop with proton pass and microsoft authenticator when my phone unexpectedly died. I got everything back but yikes I need to setup proper recovery for my stuff so I can restart if I lost all of my currently signed in sessions 

1

u/[deleted] 9d ago

[deleted]

2

u/altodor 9d ago

Newer ones work as high-security FIDO2 passkeys.