Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Malware, Spam, Pop-ups and The Most Likely Domains to Find Them | Main | Security Issues with VoIP »

Different Passwords for Differrent Sites without the Hassle

Google engineer HongHai Shen advocates in a blog post to use strong passwords and to use different passwords for different sites. Easier said than done without the right tools, but there is a way to do this without having to remember all those passwords.

I use PasswordSafe, a free and easy to use program to manage an encrypted list of passwords and accesses with a single master password. Yes, if someone cracked the got access to your file and cracked the one master password you'd be screwed but it's the best solution I've found to manage all the passwords I need to track of a bunch of applications, databases, networks and other devices. From the PasswordSafe site:

Using Password Safe you can organize your passwords using your own customizable references--for example, by user ID, category, web site, or location. You can choose to store all your passwords in a single encrypted master password list (an encrypted password database), or use multiple databases to further organize your passwords (work and home, for example). And with its intuitive interface you will be up and running in minutes.

This is a bit counter to HongHai Shen's advice:


Also, if you need to write your passwords down, keep them away from your computer

But I think he is more concerned with leaving around unencrpyted passwords.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/752

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net