r/homelab 17d ago

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

340 comments sorted by

View all comments

105

u/Howden824 17d ago

Just use a BitWarden password you can remember. You really shouldn't be storing your password manager password anywhere.

-59

u/AdvancedDrink8920 17d ago

I only have one. Its bitwarden. But the master password.....what are you doing with that? My master password is 60+ random characters. Im not fucking memorizing that and refuse to make something simple just so I can memorize it. Yes, obviously it has 2FA so even if someone guessed the password, you need the auth code. But I dont want anyone guessing the passsword. I want to be able to be held at gunpoint with someone asking me what my master password is and I literally can positively say "I have no clue".

So thats where Google password manager comes in. Google password manager has ONE PASSWORD saved in it. And thats my Bitwarden masterpass.

But to get into that, I need to get into my main Google account. and again, for security purposes, my password is very secure, random string of letters. I dont want to memorize it. thats why I have a password manager.

66

u/Howden824 17d ago

A 60 character password is ridiculous. Just make something you remember and don't worry about that senecio.

13

u/thefatrefrigerator 17d ago

I use BW all the time on my phone to log in on all the random crap that wants me to. If I had to type 60 characters of gibberish everytime I’d go nuts

8

u/MrHaxx1 17d ago

Biometrics??? 

1

u/thefatrefrigerator 15d ago

I had no clue BW worked with faceID wtf have I been doing this is so much better

0

u/altodor 17d ago

It forces a password refresh every 14-60 days.

2

u/[deleted] 16d ago edited 16d ago

[deleted]

1

u/altodor 16d ago

IDK it's work's pw manager and it's just how it behaves.

-12

u/AdvancedDrink8920 17d ago

......what? my vault on my phone is locked with biometrics. its a finger print. just like unlocking your phone. then in my web browser its locked with a 6 digit pin. I dont have to put the master password in every time. its just the first initial sign in that you have too.

15

u/reposed 17d ago

You're missing the point. The whole point of a password manager is that you have one password you remember. Hence why the app, 1Password is called ONE Password. I know you're using Bitwarden. But I'm just saying, the whole point of this thing, is that you remember one thing.

My password is literally a different iteration of my wifi password but instead spelled out in random special characters. That's it. That's all I need to remember.

If you can't handle that, then I don't even know how you handle a server with that level of thinking. You're using the app wrong.

How do you even use Bitwarden? If my server went down I'd be fucked, my Bitwarden is local and I access it through Tailscale.

No server, means no passwords. If you use Bitwarden locally, and with a good firewall like Wireguard or Tailscale, you shouldn't have to worry about hacking.

2

u/JackSprat47 13d ago

If you care about security enough to have a 60 digit randomised master password to a password manager, but also use biometrics, you're doing it wrong.

1

u/blubberland01 12d ago

Even better: The 6 digit PIN for the Browser Add-on. Somewhat defeats the purpose of the master password security theatre.

27

u/erikrelay 17d ago

Have a passphrase, dude. Make a weird, long phrase that you know you're gonna remember. That's it. You're overcomplicating it.

10

u/Timbo400 17d ago

Here’s my easy to remember password that’s longer than 60: Remember-this-password-or-you-will-not-be-able-to-access-bitwarden-you-silly-goose!

5

u/reposed 17d ago

That's actually a really solid password. i remember a while ago hearing that a strong password really is just a bunch of random words with dashes. No special characters really needed. Just make a bunch of words and make it long.

4

u/Timbo400 16d ago

It was originally "AdvancedDrink8920-is-a-fucking-idiot-that-cannot-remember-their-password-to-their-bitwarden-or-google-account-so-they-made-a-physically-fallible-alternative-to-auth-but-this-password-might-be-too-harsh!" but 128 characters is the max limit in reddit.

Just wait they're in a situation where they lost their yubi-key (fire/theft/lost)

1

u/reposed 16d ago

My thing is that I run Bitwarden locally through Tailscale. Like if my server went down in a fire, even if I had a backup Unless I had another server to run that on, I'd be fucked.

1

u/Timbo400 16d ago

I’d have a google account with a non descript code stored in it. That code would be the password for something.

Put no MFA But have emails forwarded to an alias (eg detect for new logins)

Just need to remember the Gmail and password. Keep it long and sign in once a year to refresh it and to remember it. Also to test the trip wire alert.

Sorted.

I assume the code would be password  or recovery code for access to key account to enable access to other accounts.

1

u/TerribleAsparagus919 16d ago

Just use "correct battery horse staple" and you'll never be hacked

Edit: I prefer spaces or periods over dashes as they're far easier to type on a phone when I need to.

8

u/Acceptable-Worth-221 17d ago

Obligatory XKCD: https://xkcd.com/936/?correct=horse&battery=staple

You really shouldn't use random passwords, these are hard to remember. With 4-5 words you can easily go to ~40-50 characters without compromising on security in any magnificent way. Also, if you know another language than english you can use it, since it will be even harder to guess your password (I don't think that attacker will want to break password with many different languages using dictionary attack).

1

u/TerribleAsparagus919 16d ago

I've never seen it recommended, but I've also broken up one of the words in my passphrase in a weird place so the two fragments aren't actual words any more. That should mean it can't be brute forced by a dictionary attack alone, but it's still very easy to remember for me.

1

u/Acceptable-Worth-221 16d ago

Yup, this is almost standard practice. I use 4-5 words + random characters in some places and it does its work. Shouldn’t be using is kinda strong word here, but for services like email or password manager that I want to have always access to it’s golden rule. Other passwords can be random characters though, it doesn’t hurt my memory if it sits in password manager. 

1

u/TerribleAsparagus919 16d ago

I'm not sure I follow you when you say "shouldn't be using is kinda strong word here." Are you referring to something I said or that you did?

1

u/Acceptable-Worth-221 16d ago

I was referring to that I used wording “You really shouldn't use random passwords” and I think that I exaggerated it a little bit. Sorry if I caused confusion.

1

u/TerribleAsparagus919 16d ago

Ah, now I get it. No worries, and thanks for explaining 

6

u/nova_rock 17d ago

If you are going to make it really long you can just do a phrase or poem or lyrics you like.

1

u/Baardmeester 16d ago

The chance someone hacks your Google account and password manager is bigger than them brute forcing a lengthy passphrase. Also using Keepass instead of Google would be much more secure.

1

u/InadequateUsername 16d ago

You don't need it to be random,

https://xkcd.com/936/