Skip to Content
Password Management

Published 21/10/2018 – est. 4 minutes to read.

Don’t reuse your passwords

Let’s face it, most people reuse the same password for convenience, but with all the breaches over the last few years, this practice is becoming increasingly risky.  Taking this approach means that if someone gains access to or cracks your password for one account, they could log in to any of your accounts using the same password, stealing data and jeopardising your security and privacy.  Having a separate, well-crafted password for every site is considered the best way to secure data – but how the hell are we supposed to remember them all?

As Security professionals, we’re often asked about Password Managers.  NCSC wrote a good blog about their thoughts on Password Managers, which is well worth the read.  I don’t want to repeat the content in the NCSC Blog; therefore, this will be more direct and summarise the approach we adopt to help our Clients and readers manage password overload!

Which password management tools to use

So, browser-based password managers vs cloud-based vs locally installed Password Managers – for several reasons, locally installed password managers.

We use Password Managers for three main ‘use cases’:

  • Creating random ‘throwaway’ passwords for less important Websites
  • Storing login credentials for non-critical Applications
  • Storing API Keys for Cloud platforms such as AWS and Azure

There are a few decent Password Managers out there, but this blog will look at KeePass, as it is open source and therefore free to use.  KeePass is available on Windows, Linux, and Mac OS X, with ports available for Android and iPhone/iPad.

KeePass keeps every username and password pair in an encrypted database, protected by a single master password or key – meaning, in essence, that you only need to remember one password: the password for KeePass.  Other options for strengthening KeePass authentication include locking the database to a Windows account and Key Files.  The complete password database is encrypted with AES-256; not only the password fields but also your usernames, notes, and other sensitive data are encrypted. Once logged into KeePass, you can copy passwords from KeePass into the target Applications, websites, and Terminals.

So if your laptop is configured to best practices (e.g., CIS Benchmark or NCSC EUD Guidance) and the Password Manager is configured accordingly, there is little additional risk in using a password manager such as KeePass to store passwords and secrets for your less important accounts.  You will still need to use your old noggin to remember your critical passwords, but you can help by reducing the total number you need to remember!

And finally, don’t forget to enable MFA whenever it is available – have a look at our earlier blog on MFA to read why!

To evaluate your Multi-factor authentication (MFA), conduct a Cloud Security audit, or discuss our other services, connect directly with our technical team:

Telephone: 0161 706 0244
Email: info@cybersecurityspecialists.co.uk

 

Contact us

Related Pages

Cyber Essentials Icon.

Cyber Essentials

 

Learn more about Cyber Essentials

Cyber Essentials Plus Icon.

Cyber Essentials Plus

 

Learn more about Cyber Essentials Plus

CS360 ai icon.

CS360.ai Exposure Management Platform

 

Learn more about CS360.ai