Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #194213

Re: Password Manager opinions and recommendations

From rhkramer@gmail.com
Newsgroups linux.debian.user
Subject Re: Password Manager opinions and recommendations
Date 2018-03-27 15:00 +0200
Message-ID <vxWmK-43e-11@gated-at.bofh.it> (permalink)
References <vxgdP-5Um-11@gated-at.bofh.it> <vxRQ6-19a-7@gated-at.bofh.it> <vxWd3-3ZI-11@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tuesday, March 27, 2018 08:47:10 AM rhkramer@gmail.com wrote:
> On Tuesday, March 27, 2018 04:08:07 AM Joe wrote:
> > On Mon, 26 Mar 2018 17:38:33 -0400
> > 
> > rhkramer@gmail.com wrote:
> > > > > Yes, at least I think so, unless there is some standard for how
> > > > > to handle passwords (including changing them) on websites.  I
> > > > > suspect that there isn't. There may be some commonality in
> > > > > websites generated by a common website "generator" (one of those
> > > > > packages that help you create a website--I think they exist, but
> > > > > I've never used one--maybe Drupal is an example?
> > > > 
> > > > The standard exists. You change your password via the website. Then
> > > > you inform your password manager of the change.
> > > 
> > > Ok, but that's not the kind of standard I was hoping for--I was
> > > hoping for a (standard) programmatic way of changing the password on
> > > a website, which, being programmatic, could be initiated by the
> > > password manager.
> > 
> > Unless such a thing is a library function in JavaScript, then no
> > commercial website will contain it...
> > 
> > More seriously, I doubt that such a thing exists, it would be like the
> > backdoor in OpenSSL, an absolutely disastrous idea. Websites tend to
> > store password data (sometimes in plain text!) insecurely enough as it
> > is.
> 
> Good point, although I'd expect such a function to require authentication,
> presumably by entering the old password.
> 

Hmm, but on further (but little thought), I still would like such a function, 
maybe it could work something like this:

When you login to a site that requires authentication / a password (and you've 
fulfilled the captcha or equal), you could get a prompt something like: "Would 
you like to change the password?  (Maybe mentioning how old the password is, 
or how many times you've logged in using it).  If you answer yes to the 
prompt, the password manager starts a programmatic dialog to change the 
password, including entering the password, but (perhaps optionally, via a per 
site setting in your password manager) it requires additional authentication 
(from / with the site, not with password manager) which may include--well, 
something, maybe another captcha.  And it would only work on https:// pages or 
under similar encryption.



> > Also, many websites where security is a big issue do try to ensure that
> > logins can't be made by computer.
> 
> Oh, yeah, Captchas (and such)--how could I forget about those...

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-25 18:00 +0200
  Re: Password Manager opinions and recommendations likcoras <likcoras@riseup.net> - 2018-03-25 18:40 +0200
    Re: Password Manager opinions and recommendations Ben Finney <bignose@debian.org> - 2018-03-26 00:10 +0200
  Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 19:50 +0200
    Re: Password Manager opinions and recommendations Roberto C. Sánchez <roberto@debian.org> - 2018-03-25 20:10 +0200
      Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-25 20:50 +0200
        Re: Password Manager opinions and recommendations Ángel <debian-user@debian.16bits.net> - 2018-03-25 23:20 +0200
          Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 21:40 +0200
            Re: Password Manager opinions and recommendations Mark Fletcher <mark27q1@gmail.com> - 2018-03-27 04:50 +0200
  Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-26 02:40 +0200
    Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 04:00 +0200
      Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-26 22:00 +0200
        Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-26 23:40 +0200
          Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:10 +0200
            Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
              Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 15:00 +0200
        Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 03:10 +0200
          Re: Update: Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-27 03:40 +0200
          Re: Update: Re: Password Manager opinions and recommendations Kushal Kumaran <kushal@locationd.net> - 2018-03-27 07:00 +0200
            Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:40 +0200
          Re: Update: Re: Password Manager opinions and recommendations Joe <joe@jretrading.com> - 2018-03-27 10:00 +0200
            Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-27 14:50 +0200
          Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-27 13:20 +0200
            Re: Update: Re: Password Manager opinions and recommendations Richard Hector <richard@walnut.gen.nz> - 2018-03-28 04:30 +0200
              Re: Update: Re: Password Manager opinions and recommendations Brian <ad44@cityscape.co.uk> - 2018-03-28 12:40 +0200
          Re: Update: Re: Password Manager opinions and recommendations Tomaž Šolc <tomaz.solc@tablix.org> - 2018-03-30 14:00 +0200
            Re: Update: Re: Password Manager opinions and recommendations Curt <curty@free.fr> - 2018-03-30 14:50 +0200
              Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:10 +0200
                Re: Update: Re: Password Manager opinions and recommendations Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-03-31 01:00 +0200
            Storing "real" user data: was: Re: Update: Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 16:00 +0200
              Re: Storing "real" user data: was: Re: Update: Re: Password Manager  opinions and recommendations Greg Wooledge <wooledg@eeg.ccf.org> - 2018-03-30 16:20 +0200
              Re: Storing "real" user data: was: Re: Update: Re: Password Manager  opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 20:20 +0200
    Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 10:50 +0200
      Re: Password Manager opinions and recommendations rhkramer@gmail.com - 2018-03-30 15:20 +0200
        Re: Password Manager opinions and recommendations "der.hans" <deb-user@LuftHans.com> - 2018-03-30 21:00 +0200
          Re: Password Manager opinions and recommendations Andrew McGlashan <andrew.mcglashan@affinityvision.com.au> - 2018-03-31 03:50 +0200
            Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 15:10 +0200
              Re: Chaniging focus: security ouitside a password manager (was: Re:  Password Manager opinions and recommendations) <tomas@tuxteam.de> - 2018-04-02 15:20 +0200
                Re: Chaniging focus: security ouitside a password manager (was: Re: Password Manager opinions and recommendations) rhkramer@gmail.com - 2018-04-02 20:30 +0200
              Re: Chaniging focus: security ouitside a password manager (was: Re:  Password Manager opinions and recommendations) Roberto C. Sánchez <roberto@debian.org> - 2018-04-02 15:30 +0200
              Re: Chaniging focus: security ouitside a password manager likcoras <likcoras@riseup.net> - 2018-04-02 16:00 +0200
              Re: Chaniging focus: security ouitside a password manager Ben Finney <bignose@debian.org> - 2018-04-03 01:30 +0200
              Re: Chaniging focus: security ouitside a password manager (was: Re:  Password Manager opinions and recommendations) "der.hans" <deb-user@LuftHans.com> - 2018-04-03 02:10 +0200
              Re: Chaniging focus: security ouitside a password manager Richard Hector <richard@walnut.gen.nz> - 2018-04-03 08:00 +0200
                Re: Chaniging focus: security ouitside a password manager rhkramer@gmail.com - 2018-04-03 13:50 +0200
                Re: Chaniging focus: security ouitside a password manager Cindy-Sue Causey <butterflybytes@gmail.com> - 2018-04-03 18:30 +0200
              Re: Chaniging focus: security ouitside a password manager (was: Re:  Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 11:40 +0200
              Re: Chaniging focus: security ouitside a password manager (was: Re:  Password Manager opinions and recommendations) Brian <ad44@cityscape.co.uk> - 2018-04-03 21:10 +0200
  Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 03:40 +0200
    Re: Password Manager opinions and recommendations Abdullah Ramazanoglu <ar018@yahoo.com> - 2018-03-26 04:20 +0200
      Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 05:10 +0200
  Re: Password Manager opinions and recommendations Ben Caradoc-Davies <ben@transient.nz> - 2018-03-26 04:00 +0200

csiph-web