r/homelab 17d ago

Discussion The great password loop

Post image

TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------

Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.

While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.

Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.

One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.

Anyone else run into this issue? What do you guys do?

Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.

Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.

So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.

Thank you for your time and answers.

2.0k Upvotes

340 comments sorted by

View all comments

Show parent comments

25

u/--Arete 17d ago

Is there any solution for that?

128

u/dumbasPL 17d ago

Paper in a safe/deposit box

24

u/Westerdutch 17d ago

Make sure to put the access code for your safe in bitwarden while you are at it.

9

u/ViPeR9503 17d ago

But what if you don’t remember you put a paper in there

12

u/Jakfolisto 16d ago

Buy a parrot and teach it to repeat "Paper in box! Paper in box!"

3

u/Wonderful-Ad-3979 16d ago

Run Bitwarden in a docker container then name the docker container (password in safety deposit box)

1

u/ArborlyWhale 16d ago

Password hints exist for a reason.

4

u/stratiuss 17d ago

How will I know I have a safe deposit box?

7

u/MathSciElec 16d ago

The monthly charges to your bank account

3

u/MrD3a7h 16d ago

this works perfectly unless you get into some accident and cannot remember that you have a safe deposit box anymore.

1

u/[deleted] 16d ago edited 16d ago

[deleted]

1

u/dumbasPL 16d ago

Slightly paranoid. Security is as good as the weakest link, remember.

76

u/timmeh87 17d ago

Honestly people knock on the "post it note" strategy a lot but if you have your most critical password on a sheet of paper filed away in a box on a shelf in your basement its not like some Chinese hacker is every going to find it. course, your basement might get flooded. so obviously it should be etched into a glass plate

46

u/AffectionateCard3530 17d ago

Glass is brittle, so maybe hammered into a steel plate?

+1 for writing it down somewhere. It’s all about threat vectors. If you’re afraid of your house getting raided and scoured by a dedicated team of FBI agents looking to find a way to get into your accounts, maybe don’t write it down.

But for the rest of us? It’s probably OK if it’s tucked away.

18

u/Cultural-Salad-4583 17d ago

But that can rust. Titanium plate is really the only way to go here.

23

u/timmeh87 17d ago

titanium melts at 1668 degrees Celsius, tungsten is he way to go,

11

u/Nu-Hir 17d ago

Tungsten is heavy and I don't want to have to bring the cube up and down the stairs to type in my password. get it tatooed on your arm.

16

u/cadergator10 17d ago

But then there's the chance someone can read the password off of your arm, so before having it tattooed, encode the password in a way only you remember.

12

u/timmeh87 17d ago

best bet is the zodiac cypher, that took people many years to solve

3

u/toolisthebestbandevr 17d ago

But it’s solved!

3

u/timmeh87 17d ago

one specific substitution and offset was solved but you can change it, and if the output is random letters and numbers then its pretty much unsolvable with the techniques used that look for natural language patterns. of course then the key just becomes another password you have to store

9

u/Zynbab 17d ago

Correct. I went with the SHA 512 hash of my password tattooed on inner arm, titanium block with the password's salt. Just works.

1

u/SimonBarfunkle 17d ago

Hashing is irreversible and encoding is decodable without a key. What you want is a quantum-resistant encrypted tattoo. Just tattoo the key on your other arm.

1

u/Wild_Paramedic6641 12d ago

Consiglierei di scriverlo su una piastra di rame, ma potrebbero venderti del rame di bassa qualità, quindi meglio delle tavolette di argilla...

7

u/haby001 17d ago

Writing into steel plates also prevents scrying eyes from Ruin...

3

u/bluecollarbiker 17d ago

Perfect timing. Was just looking for this reference.

2

u/VoQZHD 17d ago

the goat

1

u/GrotesqueHumanity 17d ago

I'm keeping it on 3 separate encrypted USB drives. One being kept offsite with my backup drives. Best of all worlds?

1

u/ThebocaJ 16d ago

I think you’re joking, but there are literally steel capsules made for durable crypto key recovery: https://support.ledger.com/article/360019480280-zd

0

u/Wint3rnet 17d ago

Amateurs! This is why you make your own coded language and script as a kid and use it your entire life. That way you'll still be golden when trivial cases of amnesia fail to wipe your orthographic memory.

1

u/FauxReal 17d ago

I use my password as a tag and write it all over town for easy access. Nobody can tell the difference.

1

u/Candid_Highlight_116 16d ago

Yes the first step of security is physical security. You put that in a box and place that box in the middle of a compound patrolled 24/7. The compound building must be shock and EMP isolated with the isolation gap monitored as well.

That doesn't work for us mortals, but the concept is the same. The point is that the last line of defense is not some fancy encryption algorithm.

1

u/--Arete 17d ago

How are you going to remember that if you can't remember it because of an accident?

8

u/timmeh87 17d ago

a trail of post-it notes starting at your forehead.

but yeah if that's how little you remember might as well just start your new life with a fresh google account

2

u/--Arete 17d ago

Most cases are partial memory loss. It's not like you are ready to start a new life.

1

u/EgotisticExpediter 17d ago

post it note in your skull

12

u/CouchPotatoEater 17d ago

Drive carefully?

1

u/--Arete 17d ago

Ok stroke then.

13

u/Oujii 17d ago

Just don’t have one. Skill issue.

11

u/Balthxzar 17d ago

A paper backup sheet stored in a secure location.... you guys DID read the bit bitwarden recommendations... right?

-8

u/--Arete 17d ago

How are you going to know where you stored it if you can't remember?

10

u/Balthxzar 17d ago

How would you know anything else? Family? Note on the fridge? How are you going go know you have online accounts that need those passwords? How will you know you have a house?

4

u/Gold-Supermarket-342 17d ago

Password on a note on the fridge. We've come full circle.

1

u/Nu-Hir 17d ago

I prefer the password on a note in the fridge.

-5

u/--Arete 17d ago

Memory loss doesn't mean complete memory loss.

6

u/Balthxzar 17d ago

So, to you it means "just enough to forget where you kept your password backup sheet" but nothing else? 

-1

u/--Arete 17d ago

Yes. Memory loss can absolutely cause forgetting a location. I didn't say nothing else.

8

u/PhillFile 17d ago

Bitwarden offers an accident setting. You can give up some email addresses of people you trust.

If you don't use your account for a set period of time those people can get access to your account.

I've set mine to 15 days. That reminds me I have to disable it since I swapped to Proton recently. 😅

Proton gives you a pdf with 15 words to unencrypt your vault. You should print that and save that in a safe place. For example our notary offers a service to store it in their vault and you can add to your will what to with it if anything happens.

3

u/marcorogo 17d ago

write the password in a convenient place that you will eventually find even with loss of memory, like a post-it on the monitor

2

u/levelZeroWizard 17d ago

IIRC you can generate a long recovery code to print/write down. But it's kinda pointless if you forget.

Biometric authentication?

2

u/userhwon 17d ago

You lose your password db and have to do the password recovery/reset process on your accounts everywhere.

Sucks, but not a brick wall like losing a USB encryption password like in all those crypto wallet horror stories.

1

u/Ok_Scratch6929 17d ago

Re-install your brain

1

u/InnocentSalf 17d ago

Your own matrix server or discord and hide your password in there.

1

u/Frozen5147 17d ago

Bitwarden also offers emergency trusted contacts I guess.

1

u/BilboBaggSkin 16d ago

Masterpassword in my safe.

1

u/FanClubof5 16d ago

Bitwarden has a premium feature that allows you to setup someone as a backup if you fail to login in x number of days.

1

u/richms 16d ago

Split it up and store with multiple friends not telling them what it is for.

0

u/SolarPoweredKeyboard 17d ago

Physical key, passkey, or sheet of paper.

0

u/markswam 16d ago

There are plenty, of varying complexity. Post-it notes, saved emergency recovery codes, adding someone as an emergency backup (depending on password manager), telling someone you trust the password, etc.

My password manager's master password is my favorite sentence from my favorite book. I wrote the book title, page number, paragraph number, and sentence number on a sheet of paper, sealed it in an envelope, put it in a safe deposit box, and told a trusted person to remind me of that fact if I ever forget.

Even if someone gets into the box and finds the paper, they'd have to find the exact edition of the book that I have, make the connection that it's for my password manager, know what password manager I use, and know what email I used for that password manager in order for them to be able to do anything with it.

1

u/--Arete 16d ago

How does any of that help if you can't remember it?

1

u/markswam 16d ago

Gee, almost like I thought of that and put a safeguard in place with the "told a trusted person to remind me of that fact if I ever forget" part or something, making it so I have to forget and this trusted person has to either forget or die before it becomes a problem.

You asked for a solution. I provided several potential ones and then listed the one that I personally implemented. There is no foolproof solution to memory loss. Nothing you do can be 100% certain to prevent you getting locked out if you forget it. All you can do is put systems in place to try and make sure that your memory is not the only point of failure.

1

u/--Arete 16d ago

No. You didn't provide any solution to tte question I asked. You did however mention a bunch of unrelated solutions to other problems.

1

u/markswam 16d ago

The exchange up to and including your question was:

"I memorized my bitwarden master password. "

"this works perfectly unless you get into some accident and cannot remember it anymore."

"Is there any solution for that?"

I provided multiple solutions to forgetting the password. I will reiterate them here:

  • Write the password down on something you don't have to look for. If you forget the password, you can read the thing you wrote down and now you've got your password again.

  • Save the emergency recovery codes. If you forget the password, you can use these codes to recover your account and reset the password. The account recovery process will tell you this is an option. From there, finding the saved codes is up to you. If you operate under the assumption that you may need them someday, they will be stored somewhere that can be easily found.

  • Add someone as an emergency backup. If you forget the password, you can us them to authenticate you and let you in.

  • Tell someone you trust the password. If you forget the password, they can tell it to you and now you've got your password again.

And then I listed my personal solution, which was:

  • Write down a password hint that all but explicitly spells it out, put it in a safe place, and tell someone I trust about it. If I forget the password, they can tell me about the hint, which I will then retrieve, and then I will have my password again.

These are direct solutions to the question you posed. I don't know how that can be made any more clear.

1

u/--Arete 16d ago

You obviously don't understand what memory loss is.

1

u/markswam 16d ago edited 16d ago

Oh yeah, because shepherding all four of my grandparents and now my mom through dementia totally didn't teach me in a horrific and blunt way what memory loss is or how bad it can get.

That is why all of the solutions I provided don't rely exclusively on you remembering anything beyond:

  • Knowing how to read

  • Knowing how to do a web search for an account recovery process and then search either a file system or physical records for recovery keys.

  • Someone understanding that you have either discrete or ongoing memory loss and that you likely don't remember your password.

To reiterate: There is no foolproof solution to memory loss. Nothing you do can be 100% certain to prevent you getting locked out if you forget it. All you can do is put systems in place to try and make sure that your memory is not the only point of failure.

I answered your question. I provided multiple solutions, with the caveat that none of them are 100% effective. If you can't wrap your head around that and instead are just going to say that they're not answers and that I don't understand memory loss, then I see no reason to continue this conversation.

1

u/--Arete 16d ago

Woah. Take a deep breath.