A PasswordCard is a credit card-sized card you keep in your wallet, which lets you pick very secure passwords for all your websites, without having to remember them! You just keep them with you, and even if your wallet does get stolen, the thief will still not know your actual passwords.

A very cute idea, well implemented.

Your PasswordCard has a unique grid of random letters and digits on it. The rows have different colors, and the columns different symbols. All you do is remember a combination of a symbol and a color, and then read the letters and digits from there. It couldn’t be simpler!

A chain is only as strong as its weakest link. It’s far safer to pick secure passwords and write them down, than it is to remember simple and easy to guess passwords. You already protect your wallet very well, and even if it does get stolen the thief will still not know which of the many thousands of possibilities on the card is your password.

  • ShortN0te@lemmy.ml
    link
    fedilink
    arrow-up
    28
    ·
    11 months ago

    Defeats the purpose of a password manager for me. Why:

    • You still need to remember for every account a secret (color, grid combination)
    • Long passwords are impractical
    • Password entry is not easy, it is manual

    Users are likely to end up using short passwords and are likely to use the same password for multiple accounts.

    Not saying it has no use, but not as a replacement for your password manager.

    • SmoothLiquidation@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 months ago

      It could possibly be used as a key for your password manager, but overall impractical. Just use Bitwarden with a strong password that you can remember.

      • ShortN0te@lemmy.ml
        link
        fedilink
        arrow-up
        7
        ·
        11 months ago

        Master passwords is the one thing i would find it somewhat useful. But even then, when you encrypt something with a password you would want a passphrase instead for more entropy. So even here it falls short.

  • Fake4000@lemmy.world
    link
    fedilink
    English
    arrow-up
    28
    arrow-down
    1
    ·
    11 months ago

    Why not use something like Keepass? Just one password to remember.

    Am I missing something?

    • Amju Wolf@pawb.social
      link
      fedilink
      arrow-up
      18
      arrow-down
      1
      ·
      11 months ago

      It’s good for people who don’t trust, can’t or don’t want to use password managers. It’s also way simpler for a regular person (who’d otherwise write the password down anyway) while still being quite secure.

      It’d also be great for choosing your password manager master password without risking that you forget it and without writing it down outright.

      I like it, clever and practical.

      • jet@hackertalks.comOP
        link
        fedilink
        English
        arrow-up
        8
        ·
        11 months ago

        one of my good friends, reuses the same simple, short, password on everything… her facebook got compromised and she STILL wont change her password… its maddening.

        I’m thinking of trying to get her to use a password manager, or at least a card like this…

      • drasticpotatoes@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        4
        ·
        11 months ago

        I would also add that I like the mobility of not needing to log in somehow to access my passwords. If I am on a friend’s computer, for instance, all I need to do is visit a website with my current password generator.

    • KISSmyOS@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      11 months ago

      With this method, you don’t need access to an electronic device that’s tied to your password manager, don’t need to trust a cloud provider, don’t need to set up your own cloud.

    • BearOfaTime@lemm.ee
      link
      fedilink
      arrow-up
      6
      arrow-down
      1
      ·
      edit-2
      11 months ago

      I think this would be useful for people who only have a few passwords, or don’t use tech heavily.

      Hell, maybe it could be useful for my day-to-day passwords, since I have probably 100+ in Bitwarden.

      I’m not getting my elder family members to use Bitwarden.

          • SmoothLiquidation@lemmy.world
            link
            fedilink
            English
            arrow-up
            4
            ·
            11 months ago

            She is in her 80’s. I mostly just explained WHY she would need one, and promised once she was done with the transition, things would be easier. Her old password method was a weathered old piece of paper with everything scribbled down on it, with lots of old pet names and other animals with random numbers attached.

            Now she is very happy with being able to have all of her passwords ready either on her computer, phone, or iPad, and she feels a lot more secure with the long random passwords.

            • BearOfaTime@lemm.ee
              link
              fedilink
              arrow-up
              5
              arrow-down
              2
              ·
              11 months ago

              Wow, 80s! I’m seriously impressed, by both of you. She must be something else to be willing to try something so foreign to her, and you clearly knew how to present it to her.

    • jet@hackertalks.comOP
      link
      fedilink
      English
      arrow-up
      5
      ·
      11 months ago

      No, your not missing anything. Its a interesting option, thats all.

      Where do you keep your KeepAss master password? Perhaps a password card could be a interesting way to keep/secure the master vault password for a password manager.

      • 🅿🅸🆇🅴🅻@lemmy.world
        link
        fedilink
        arrow-up
        7
        ·
        edit-2
        11 months ago

        Where do you keep your KeepAss master password?

        In my head. If you use a long passphrase, it’s easy to remember, easy to type, and secure.

        The pregenerated book of codes is used since ancient times and it is interesting, but I would much prefer to educate people to use passphases instead.

        And everybody has a phone with them at all times, you can have Keepass on it. It doesn’t use the cloud, it’s local, and if you need to sync the password database file automatically with your PC it’s safe to keep it in the cloud, it’s encrypted and only decrypted locally. But I myself use a self-hosted instance of Nextcloud.

      • Fake4000@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 months ago

        It’s an interesting concept, but I love to carry a wallet as thin as possible.

        I’m not George Costanza :)

  • dracs@programming.dev
    link
    fedilink
    English
    arrow-up
    18
    ·
    11 months ago

    This feels like a weaker version of GRC’s Off The Grid system. https://www.grc.com/offthegrid.htm

    It doesn’t require you to remember something different per website. It’s designed so that you can turn any site name (E.g. Amazon) into a secure password which is unique to you. If you really need a completely offline solution, I don’t think it gets too much better than that.

    • RvTV95XBeo@sh.itjust.works
      link
      fedilink
      arrow-up
      7
      ·
      11 months ago

      All of these systems are great until you run into “password must be 9-11 characters and contain two symbols from a hidden list of acceptable symbols, which we will not expose to the user but instead only inform you you’ve chosen the wrong symbol”. I can’t see myself relying on a system like this for more than providing a secure password to my digital password manager.

    • PeWu@lemmy.ml
      link
      fedilink
      arrow-up
      5
      ·
      11 months ago

      That is quite a nice read. I think I’ll try using this system, as it looks fun. Thanks for that idea.

      • dracs@programming.dev
        link
        fedilink
        English
        arrow-up
        5
        ·
        11 months ago

        I’ve never really had a use case for it myself. I’m happy using Bitwarden at present. It’s certainly a fun read and a good solution for anyone in need of a completely offline solution.

        I really like how easy it is to customise it so that even if someone got a copy of your square, they wouldn’t necessarily be able to get your passwords. Changing your starting row or column or adding a few characters at the start of the domain will completely change the output. I’d imagine you’d need both the square and multiple passwords to even attempt to brute force a solution back out of it.

  • TaviRider@reddthat.com
    link
    fedilink
    arrow-up
    17
    ·
    11 months ago

    This is a terrible idea. It’s negligibly better than writing down the passwords, because it’s trivially easy to try every password represented on this card. Once someone has the card, your entropy is just two characters, which is the two characters you memorize for the site. In effect, you have a 2 character password.

    • jet@hackertalks.comOP
      link
      fedilink
      English
      arrow-up
      7
      ·
      11 months ago

      https://github.com/LordDarkHelmet/PasswordCardWordListGenerator

      I see what you’re saying. But it’s just a tool. You can use the card for any mapping pattern you like. This GitHub link has a nice animated image, I’ve tried to include it here in line, that shows different options you could use. Giving you more than just a two character password of entropy

      • tpyo@lemmy.world
        link
        fedilink
        arrow-up
        4
        ·
        11 months ago

        It’s an interesting idea. I’m not here really to give my input either way, but I just wanted to note on my client, the animation is a static image and when tap on it I get this message:

        It’s not an issue, but it ends up opening the in-app browser and from there plays as a video

        Also, the app has some info it includes when trying to open files, not sure if it’s useful:

        It’s not a big deal at all and if you don’t care I apologize for wasting your time. But people here seem to like puzzling out little issues on the fediverse.

        Thanks again for the original post, though! It’s a fun approach

  • Turbo@lemmy.ml
    link
    fedilink
    arrow-up
    11
    ·
    11 months ago

    Cute idea, but 8 characters is not a good length. Neat if more symbols and longer length card could be generated.

    Length of 8 and only a-Z plus numbers 0-9?

    That could be cracked in an offline attack in minutes…

  • Dr_Evil@sh.itjust.works
    link
    fedilink
    arrow-up
    5
    ·
    11 months ago

    Seems like this is recommending the use of 8 character passwords… Even with upper/lower case letters, numbers, and special characters can’t an 8 character password technically still be brute forced in like 10 minutes?

    • jet@hackertalks.comOP
      link
      fedilink
      English
      arrow-up
      4
      ·
      edit-2
      11 months ago

      Yes, if you were using this as a key for a encrypted vaults with nuclear secrets, 8 wouldn’t be sufficient.

      But if your using this with online services that implement rate limiting, (or TPM, or Hardware security key), the rate limiting makes this sufficiently complex.

      So Bitwarden (rate limiting), hardware security key (something you have), and knowing how to read your password card (something you know). Gets you pretty far in terms of usable security.

      Nothing is stopping you from using 16, 32, 64 characters, you just have to come up with a system you like to read the card

      • Dr_Evil@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        11 months ago

        Fair enough, all good points! Assuming you are using the 8 character columns as unique passwords, I guess this also promotes the use of different passwords for different accounts which is also a good practice!

  • jet@hackertalks.comOP
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 months ago

    If you like this idea, you can roll your own, but if you use this website, make sure you use a incognito browser so the data doesnt stay on your hard drive after you print it. (tor browser for bonus points)

  • PlasmaDistortion@lemm.ee
    link
    fedilink
    English
    arrow-up
    4
    ·
    11 months ago

    As with many things, this is already a thing. My wife’s old bank had these that you had to use in combination with your password or ATM pin. It worked pretty well, until someone lost the card.

  • ExLisper@linux.community
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    5
    ·
    11 months ago

    Better idea: memorize lyrics to a song, for each website choose a different starting word, use 4 consecutive words as password. You only have to remembered one number per page, you don’t need to print anything and you can have longer passwords.

    YouDownNeverGonna

    • Feenwolf@lemmy.ca
      link
      fedilink
      arrow-up
      7
      ·
      11 months ago

      Pretty easy to crack things like that, do you ever check how good your password is?

      • Gooey0210@sh.itjust.works
        link
        fedilink
        arrow-up
        2
        ·
        11 months ago

        Spell the words with mistakes + add numbers and symbols with a rule, capitalize with a rule too

        But lyrics of a song is an really obvious target to get to a dictionary(if it’s a dictionary attack)

        More interesting would be encrypting name of the service, maybe with you login or something

        So “gooey” + “lemmy”, let’s say we take three first letters and three last

        “goommy”

        Create a dictionary in your head only you know:

        go out out mom mom yes (for an example I used short words)

        Make mistakes that you would:

        go oud oud mam mam yess

        Add some numbers and symbols, capitalize

        gO Oud Oud mAm mAm yEss (o, a, e are capitalized)

        You get the point

        • Nik282000@lemmy.ca
          link
          fedilink
          arrow-up
          1
          arrow-down
          1
          ·
          11 months ago

          Or just use a god damned pw manager. As soon as you have to memorize a system corners will be cut. 16 random characters will never be beaten by a mangled string.

          • Gooey0210@sh.itjust.works
            link
            fedilink
            arrow-up
            2
            ·
            11 months ago

            Yeah, but most of the password managers are a security risk too

            I would actually be happy to see a good airgapped password manager working with qr codes, or NFC, or something like that

            Maybe as an app for an old phone, or a raspberry pi zero

      • ExLisper@linux.community
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        3
        ·
        11 months ago

        Crack how? With 4-5 words you’re going to have a pretty long password so bruteforce is out. Do you mean that if you will have one of my password you will have the rest? That’s because I gave you obvious example as a joke. What if my password is TakePicturesOfYou. What other password are possible? How will you crack them?

        • burgermeister@lemm.ee
          link
          fedilink
          arrow-up
          3
          ·
          11 months ago

          Take the lyrics of the top 1000 popular english songs, and do a rolling hash of 5 words at a time. To account for capitalization, you would have to multiplely the dataset a few times but I bet you most passwords created in this manner would be easily cracked using this method.

          • ExLisper@linux.community
            link
            fedilink
            English
            arrow-up
            3
            arrow-down
            1
            ·
            11 months ago

            That’s not easy. I mean it’s not that hard computationally but you’re talking about very specific attack requiring some dedicated tools. Real life you would have two scenarios:

            1. You trying to break into my specific account like gmail. This will not help you because they will rate limit you, use captcha and eventually just block you.
            2. You have a leaked list of thousands/millions password hashes and my password is among them. Hackers would just use existing rainbow tables. They will not think ‘hey, maybe some of those passwords use song lyrics, let’s check’.

            This would be bad pretty much only in the very specific scenario of hackers trying to hack my specific account and having leaked hashes of password for this account.

            Still I wouldn’t really use this method. I’m just saying it’s better method than some printed card generating short alphanumeric password.

        • Nik282000@lemmy.ca
          link
          fedilink
          arrow-up
          1
          ·
          11 months ago

          Crackers use words and phases, they don’t just start at 00000000 and head for zzzzzzzz. It’s easier to crack a 16 char phrase of mangled words than 16 random chars.

  • take6056@feddit.nl
    link
    fedilink
    arrow-up
    2
    ·
    11 months ago

    Seems like they at least could’ve made the page have a no-cache header so you don’t have to wipe the cache & history by hand.

    • jet@hackertalks.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 months ago

      True. They could have also implemented it all in client side JavaScript so the server isn’t involved. But it’s still useful as it is

  • drasticpotatoes@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    2
    ·
    11 months ago

    I currently use LessPass to generate my passwords. This seems like a similar solution but even easier because you no longer need to access a website or install an app or extension. Thanks for sharing this.