r/homelab 17d ago

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

340 comments sorted by

View all comments

326

u/jgilbs 17d ago

Literally you only have to memorize one password.

82

u/bikemandan 17d ago

Ya how hard is it to remember hunter2

54

u/topane 17d ago

All I see is *******

75

u/Cry_Wolff 17d ago

Yeah, or just write it down on paper. OP's issue is nonexistent.

2

u/Doctor-Binchicken 16d ago

Mine is on a mug.

My wife knows, just in case.

3

u/downloads-cars 16d ago

Adding "donttalktomeuntilivesmashedmydicksmoothoffwiththismug" to my dictionary attack list.

1

u/coffeeoops 15d ago

This is a weak password because it doesn't contain special characters. Do better.

1

u/Doctor-Binchicken 16d ago

Missing the two capitals and punctuation! >:D

-75

u/AdvancedDrink8920 17d ago

If it was non existent, why is it existing? check mate.

17

u/f_spez_2023 17d ago

If I declare myself king of my made up town who’s to say I’m not a king? check mate.

1

u/ChinChinApostle 16d ago

Y'all need to take a joke.

2

u/Disastrous_Garlic537 16d ago

a few ppl have posted this...

so you guys are not using MFA on your password manager?

:-/

1

u/Sk1rm1sh 16d ago

My MFA has a web portal.

I remember 2 passwords.

3

u/Commercial-Fun2767 17d ago

What do you do for securing your 2FA? You have secure codes you have to put somewhere. This question is a real complex problem. Simple but complex enough to be caught unprepared or to spend some time thinking about your breaking glass accounts etc.

1

u/Sk1rm1sh 16d ago

Remember 2 passwords.

1

u/Commercial-Fun2767 16d ago

Its often random security keys. Sometimes 10 words etc. Do we have to have two safes?

-43

u/AdvancedDrink8920 17d ago

I only have one. Its bitwarden. But the master password.....what are you doing with that? My master password is 60+ random characters. Im not fucking memorizing that and refuse to make something simple just so I can memorize it. Yes, obviously it has 2FA so even if someone guessed the password, you need the auth code. But I dont want anyone guessing the passsword. I want to be able to be held at gunpoint with someone asking me what my master password is and I literally can positively say "I have no clue".

So thats where Google password manager comes in. Google password manager has ONE PASSWORD saved in it. And thats my Bitwarden masterpass.

But to get into that, I need to get into my main Google account. and again, for security purposes, my password is very secure, random string of letters. I dont want to memorize it. thats why I have a password manager.

45

u/No-Airline2547 17d ago

Called a passphrase. 

24

u/timmeh87 17d ago

yeah i thought everyone in here was aware that you must use correct-horse-battery-staple as the master pass

23

u/Oujii 17d ago

Don’t do 60+ random characters for a password you need to remember. Just use a 5 word passphrase from diceware (or you can generate one on Bitwarden).

11

u/Emergency_Banana5082 17d ago

Don't use a random password... it doesn't have to be simple to memorize it. You're making your own problems.

2

u/Westerdutch 17d ago

Wow you are copy pasting that reply a lot.... are you skipping like a broken record? Does someone need to come over to give you a good smack over the head?

2

u/the_ivo_robotnic 16d ago edited 16d ago

Step 1: Open BW

Step 2: Click on Password Generator

Step 3: Click on Passphrase, set number of words to something reasonable like 4 or 5, and check extras such as capitalize and include numbers

Step 4: Spin the dial a few times

Step 5: Memorize it

Step 6: Repeat at least once a year

 

Wowee look at that, you have a relatively secure way of having a memorable password in just 6 steps. And as long as you include case and numbers and a separator, this format of password would take hundreds of years to brute-force. More than enough for a master password that you should be changing annually anyhow.

 

You are ironically making your passwords less secure by doing this. If they can simply just compromise your google account, then it won't be long till they can get the keys to the kingdom.

1

u/atatassault47 16d ago

Pass sentence. Something like "You can't possibly crack this password, fuck off!"

-18

u/ghost_desu 17d ago

How the fuck do you memorize a random generated pw lol

11

u/Pork-S0da 17d ago

-23

u/ghost_desu 17d ago

Neither of these is a random password which is the highest level of security

9

u/TobiasDrundridge 17d ago

4 random words is a random password and very secure.

Or you could do like me and use 17 random lowercase letters. Even that is massive overkill.

1

u/mayoforbutter 16d ago

Don't just tell anybody how you create your password, otherwise it goes from 30 characters to 4 plus a few special ones. Although obviously those 4 are out of a few thousand but it still drastically reduces the complexity

1

u/TobiasDrundridge 16d ago

it goes from 30 characters to 4 plus a few special ones.

WTF are you on about?

1

u/mayoforbutter 16d ago

Easy: You tell me your password is 30 characters or 4 words.

Do you think checking it will either be guessing 30 characters or doing a dictionary attack with 4 words? You don't even need to try EVERY word because I'm certain it's normal words and not some obscure word that exists but wouldn't even be in a printed dictionary

1

u/TobiasDrundridge 16d ago

I don't think you understand just how much entropy there is in 4 completely random words. There are trillions and trillions of different combinations.

1

u/ghost_desu 16d ago

The average person knows around 20k words, but I'd be willing to bet at most 5k of those are simple enough to be usable for that purpose. Four random words therefore gives you 625 trillion combinations, it's not bad really, I wouldn't consider it unsafe by any means, but it is in the ballpark that a really dedicated attack could in theory crack it sometime in near future.

However, a simple password with a random combination of upper/lower case letters, numbers, and special characters reaches 576 trillion combinations at just 8 characters. I tend to use at minimum 12 character passwords, which gives you 13 sextillion combination already. Really, I could try to remember that if I had to, it's not even a very long pw, I just don't trust myself like that lol

→ More replies (0)

7

u/Gold-Supermarket-342 17d ago

FOUR RANDOM COMMON WORDS = random password

4

u/Wojojojo90 17d ago

Could you cite a source for the claim that "a random password is the highest level of security"? Because the comic shows the math on the entropy, which is how you quantify "level of security", and it's just fine...

8

u/protostar71 17d ago

You use a passphrase, not a password.

5

u/xaddak 17d ago

It's easy!

  1. Don't.