A PasswordCard is a credit card-sized card you keep in your wallet, which lets you pick very secure passwords for all your websites, without having to remember them! You just keep them with you, and even if your wallet does get stolen, the thief will still not know your actual passwords.

A very cute idea, well implemented.

Your PasswordCard has a unique grid of random letters and digits on it. The rows have different colors, and the columns different symbols. All you do is remember a combination of a symbol and a color, and then read the letters and digits from there. It couldn’t be simpler!

A chain is only as strong as its weakest link. It’s far safer to pick secure passwords and write them down, than it is to remember simple and easy to guess passwords. You already protect your wallet very well, and even if it does get stolen the thief will still not know which of the many thousands of possibilities on the card is your password.

28 points

Defeats the purpose of a password manager for me. Why:

  • You still need to remember for every account a secret (color, grid combination)
  • Long passwords are impractical
  • Password entry is not easy, it is manual

Users are likely to end up using short passwords and are likely to use the same password for multiple accounts.

Not saying it has no use, but not as a replacement for your password manager.

permalink
report
reply
5 points

It could possibly be used as a key for your password manager, but overall impractical. Just use Bitwarden with a strong password that you can remember.

permalink
report
parent
reply
7 points

Master passwords is the one thing i would find it somewhat useful. But even then, when you encrypt something with a password you would want a passphrase instead for more entropy. So even here it falls short.

permalink
report
parent
reply
2 points

Use OnlyKey for master passwords

permalink
report
parent
reply
27 points

Why not use something like Keepass? Just one password to remember.

Am I missing something?

permalink
report
reply
17 points

It’s good for people who don’t trust, can’t or don’t want to use password managers. It’s also way simpler for a regular person (who’d otherwise write the password down anyway) while still being quite secure.

It’d also be great for choosing your password manager master password without risking that you forget it and without writing it down outright.

I like it, clever and practical.

permalink
report
parent
reply
8 points

one of my good friends, reuses the same simple, short, password on everything… her facebook got compromised and she STILL wont change her password… its maddening.

I’m thinking of trying to get her to use a password manager, or at least a card like this…

permalink
report
parent
reply
2 points

Hardware security key might be better.

permalink
report
parent
reply
4 points

I would also add that I like the mobility of not needing to log in somehow to access my passwords. If I am on a friend’s computer, for instance, all I need to do is visit a website with my current password generator.

permalink
report
parent
reply
6 points

With this method, you don’t need access to an electronic device that’s tied to your password manager, don’t need to trust a cloud provider, don’t need to set up your own cloud.

permalink
report
parent
reply
5 points

No, your not missing anything. Its a interesting option, thats all.

Where do you keep your KeepAss master password? Perhaps a password card could be a interesting way to keep/secure the master vault password for a password manager.

permalink
report
parent
reply
7 points
*

Where do you keep your KeepAss master password?

In my head. If you use a long passphrase, it’s easy to remember, easy to type, and secure.

The pregenerated book of codes is used since ancient times and it is interesting, but I would much prefer to educate people to use passphases instead.

And everybody has a phone with them at all times, you can have Keepass on it. It doesn’t use the cloud, it’s local, and if you need to sync the password database file automatically with your PC it’s safe to keep it in the cloud, it’s encrypted and only decrypted locally. But I myself use a self-hosted instance of Nextcloud.

permalink
report
parent
reply
5 points

It’s an interesting concept, but I love to carry a wallet as thin as possible.

I’m not George Costanza :)

permalink
report
parent
reply
3 points
*

Fair!

Just remember to never give your secret code to anyone. https://www.youtube.com/watch?v=aUVd4cFD5-s

permalink
report
parent
reply

I think this would be useful for people who only have a few passwords, or don’t use tech heavily.

Hell, maybe it could be useful for my day-to-day passwords, since I have probably 100+ in Bitwarden.

I’m not getting my elder family members to use Bitwarden.

permalink
report
parent
reply
3 points

I got my mom to use Bitwarden. There was a bit of effort setting her up, but now she is really happy with it.

permalink
report
parent
reply

Nice! Congrats!

How old is she? How did you market it to her?

permalink
report
parent
reply
18 points

This feels like a weaker version of GRC’s Off The Grid system. https://www.grc.com/offthegrid.htm

It doesn’t require you to remember something different per website. It’s designed so that you can turn any site name (E.g. Amazon) into a secure password which is unique to you. If you really need a completely offline solution, I don’t think it gets too much better than that.

permalink
report
reply
7 points

All of these systems are great until you run into “password must be 9-11 characters and contain two symbols from a hidden list of acceptable symbols, which we will not expose to the user but instead only inform you you’ve chosen the wrong symbol”. I can’t see myself relying on a system like this for more than providing a secure password to my digital password manager.

permalink
report
parent
reply
5 points

That is quite a nice read. I think I’ll try using this system, as it looks fun. Thanks for that idea.

permalink
report
parent
reply
5 points

I’ve never really had a use case for it myself. I’m happy using Bitwarden at present. It’s certainly a fun read and a good solution for anyone in need of a completely offline solution.

I really like how easy it is to customise it so that even if someone got a copy of your square, they wouldn’t necessarily be able to get your passwords. Changing your starting row or column or adding a few characters at the start of the domain will completely change the output. I’d imagine you’d need both the square and multiple passwords to even attempt to brute force a solution back out of it.

permalink
report
parent
reply
17 points

This is a terrible idea. It’s negligibly better than writing down the passwords, because it’s trivially easy to try every password represented on this card. Once someone has the card, your entropy is just two characters, which is the two characters you memorize for the site. In effect, you have a 2 character password.

permalink
report
reply
7 points

https://github.com/LordDarkHelmet/PasswordCardWordListGenerator

I see what you’re saying. But it’s just a tool. You can use the card for any mapping pattern you like. This GitHub link has a nice animated image, I’ve tried to include it here in line, that shows different options you could use. Giving you more than just a two character password of entropy

permalink
report
parent
reply
4 points

It’s an interesting idea. I’m not here really to give my input either way, but I just wanted to note on my client, the animation is a static image and when tap on it I get this message:

It’s not an issue, but it ends up opening the in-app browser and from there plays as a video

Also, the app has some info it includes when trying to open files, not sure if it’s useful:

It’s not a big deal at all and if you don’t care I apologize for wasting your time. But people here seem to like puzzling out little issues on the fediverse.

Thanks again for the original post, though! It’s a fun approach

permalink
report
parent
reply
2 points

Which client do you use?

permalink
report
parent
reply
11 points

Cute idea, but 8 characters is not a good length. Neat if more symbols and longer length card could be generated.

Length of 8 and only a-Z plus numbers 0-9?

That could be cracked in an offline attack in minutes…

permalink
report
reply
5 points

Then double it up and use 2 together

permalink
report
parent
reply
3 points

Sure, you could…

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 7.5K

    Monthly active users

  • 2.8K

    Posts

  • 75K

    Comments