Go Back  British Expats > Living & Moving Abroad > USA > The Trailer Park
Reload this Page >

If you use transferwise change your password

If you use transferwise change your password

Thread Tools
 
Old Feb 27th 2017, 9:35 pm
  #16  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by jambey2510
It's more fun when you have 10 different passphrases memorised in your head, but after a while away from some sites, you'll forget which of those you used!!

I know a lot of people who use passphrase apps etc, but I wouldn't trust it myself at all!
I just have far too many to remember, you have a choice or pen and paper or electronic. I keep a reasonably up to date list at the bank.

I prefer lasspass, dashlane or roboforms

Last edited by mrken30; Feb 27th 2017 at 9:41 pm.
mrken30 is offline  
Old Feb 28th 2017, 12:12 am
  #17  
Bob
BE Site Lead
 
Bob's Avatar
 
Joined: Aug 2004
Location: MA, USA
Posts: 92,172
Bob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by mrken30
Dropbox has had security issues in the past, it's not a security focused product

https://www.theguardian.com/technolo...8m-data-breach

There is an update for keepass

The automatic update feature in KeePass 2.33 and earlier allows man-in-the-middle attackers to execute arbitrary code by spoofing the version check response and supplying a crafted update.

https://web.nvd.nist.gov/view/vuln/s...pe=all&cves=on
Yes, but an encrypted file on DB isn't much use on it's own and Keepass is just an example of one run off a thumbdrive that's a standalone roll out without any web updating features if you want.
Bob is offline  
Old Feb 28th 2017, 12:43 am
  #18  
Lost in BE Cyberspace
 
Steerpike's Avatar
 
Joined: Nov 2007
Location: Bay Area, CA
Posts: 13,152
Steerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond repute
Default Re: If you use transferwise change your password

One strategy that can help, as long as you don't want full automation (paste-in of passwords), is to store a mnemonic in the password database for at least part of the pwd.

So imagine if your 'actual' password is abcd1234!@#$-xyx. You could replace abcd1234 with 'alphanumeric', and that's your mnemonic for abcd1234. So the password manager would store 'alphanumeric!@#$-xyz', and you translate in your head the 'alphanumeric' sub-string to 'abcd1234'. You can use this 'root' portion of the password in all your passwords.
Steerpike is offline  
Old Feb 28th 2017, 2:21 am
  #19  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by Bob
Yes, but an encrypted file on DB isn't much use on it's own and Keepass is just an example of one run off a thumbdrive that's a standalone roll out without any web updating features if you want.
I believe you can keep a local key file with keepass.
mrken30 is offline  
Old Feb 28th 2017, 5:09 am
  #20  
BE Enthusiast
 
Joined: Mar 2015
Location: Virginia
Posts: 352
scottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond repute
Default Re: If you use transferwise change your password

Email is the most important as others have mentioned, so at least for that make sure you don't store that password anywhere and also have Two Factor authentication. I use LastPass for password management and have Two Factor on that, as well as Google, Facebook, Twitter, Amazon and my bank.
scottyvisa is offline  
Old Feb 28th 2017, 3:33 pm
  #21  
Lost in BE Cyberspace
 
Steerpike's Avatar
 
Joined: Nov 2007
Location: Bay Area, CA
Posts: 13,152
Steerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond repute
Default Re: If you use transferwise change your password

What's the best way to incorporate a 2FA solution into a 'home user' situation?

I've implemented corporate 2FA solutions for 500+ users (cryptocard/safenet, I recall) using smartphone apps, and I've also incorporated the free Google Authenticator into a sophos firewall solution for a small business, but how do you implement a 2FA solution with a diverse set of 'hosts' such as my schwab bank site, my Visa site, my email provider, etc? Doesn't each 'host' have their own way of implementing the solution? is there a way to 'unify' this?
Steerpike is offline  
Old Feb 28th 2017, 3:44 pm
  #22  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by Steerpike
What's the best way to incorporate a 2FA solution into a 'home user' situation?

I've implemented corporate 2FA solutions for 500+ users (cryptocard/safenet, I recall) using smartphone apps, and I've also incorporated the free Google Authenticator into a sophos firewall solution for a small business, but how do you implement a 2FA solution with a diverse set of 'hosts' such as my schwab bank site, my Visa site, my email provider, etc? Doesn't each 'host' have their own way of implementing the solution? is there a way to 'unify' this?
For my banks/credit union I have a variety of solutions I have to use ranging from a smartphone app to a device in which I have to put my debit card in, enter a PIN and then it spews out a number.

It would be nice if everyone used the same app/ device but I don't think that will ever happen.
mrken30 is offline  
Old Feb 28th 2017, 4:26 pm
  #23  
Bob
BE Site Lead
 
Bob's Avatar
 
Joined: Aug 2004
Location: MA, USA
Posts: 92,172
Bob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond reputeBob has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by mrken30
I believe you can keep a local key file with keepass.
Yes, that's the default. The remote storage is a extra plugin you have to set up, so for a casual user it might not be done.
Bob is offline  
Old Feb 28th 2017, 4:32 pm
  #24  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

One thing that has got harder with passwords if entering the symbols on smartphones, especially when you are using 16 char plus passwords
mrken30 is offline  
Old Feb 28th 2017, 6:00 pm
  #25  
Lost in BE Cyberspace
 
Steerpike's Avatar
 
Joined: Nov 2007
Location: Bay Area, CA
Posts: 13,152
Steerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by mrken30
One thing that has got harder with passwords if entering the symbols on smartphones, especially when you are using 16 char plus passwords
What secure sites do you need to access from your smartphone? Only thing I use is my bank's check deposit service, rarely (cant use laptop, must be mobile phone). I do use email on my phone of course, and for that I blindly allow saved passwords. I do have a pin on the phone, and I've just started using the (fairly reliable) fingerprint reader (new Samsung S7).

Last edited by Steerpike; Feb 28th 2017 at 6:07 pm.
Steerpike is offline  
Old Feb 28th 2017, 6:19 pm
  #26  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by Steerpike
What secure sites do you need to access from your smartphone? Only thing I use is my bank's check deposit service, rarely (cant use laptop, must be mobile phone). I do use email on my phone of course, and for that I blindly allow saved passwords. I do have a pin on the phone, and I've just started using the (fairly reliable) fingerprint reader (new Samsung S7).
Groupon, insurance, amazon, netflix, expedia (sometimes), banking, expensify.

I could use a laptop, but a phone is more convenient and lighter.
mrken30 is offline  
Old Mar 1st 2017, 12:42 am
  #27  
BE Enthusiast
 
Joined: Mar 2015
Location: Virginia
Posts: 352
scottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by Steerpike
What's the best way to incorporate a 2FA solution into a 'home user' situation?

I've implemented corporate 2FA solutions for 500+ users (cryptocard/safenet, I recall) using smartphone apps, and I've also incorporated the free Google Authenticator into a sophos firewall solution for a small business, but how do you implement a 2FA solution with a diverse set of 'hosts' such as my schwab bank site, my Visa site, my email provider, etc? Doesn't each 'host' have their own way of implementing the solution? is there a way to 'unify' this?
Yes you need your provider to have 2FA as an option of course, most that do are compatible with the Google Authenticator App. If your email provider doesn't have this as an option, switch to one that does, Gmail, Yahoo and Outlook all do. One of my deciding factors in switching from PNC to my current bank was their lack of 2FA, my current bank does have it. Amazon offers it too, and since I make most of my purchases from them and they have a lot of my personal data I use it. Not sure if Transfer Wise offers it directly, but I use my Google login for it, so I get 2FA through that. If a site offers login via Google or Facebook, I normally go for that option. Even if they don't have 2FA, many sites with offer some kind of alert system that will text or email you if your account is logged into from an unrecognised location. This happened last week to me with Facebook, someone tried to access it in Canada and they alerted me, I was able to block the access and change my password.
scottyvisa is offline  
Old Mar 1st 2017, 1:02 am
  #28  
Lost in BE Cyberspace
Thread Starter
 
mrken30's Avatar
 
Joined: Jul 2008
Location: Portlandia Metro
Posts: 7,425
mrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond reputemrken30 has a reputation beyond repute
Default Re: If you use transferwise change your password

I used to find google/ms authenticator anoying as I didn't always have my phone ready at hand. After I put the app on my watch, much more useful. I can also now use 2FA on my phone much more easily.
mrken30 is offline  
Old Mar 1st 2017, 1:03 am
  #29  
Lost in BE Cyberspace
 
Steerpike's Avatar
 
Joined: Nov 2007
Location: Bay Area, CA
Posts: 13,152
Steerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond reputeSteerpike has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by scottyvisa
Yes you need your provider to have 2FA as an option of course, most that do are compatible with the Google Authenticator App. If your email provider doesn't have this as an option, switch to one that does, Gmail, Yahoo and Outlook all do.
When you say 'outlook', do you mean office 365 (or does that include Office 365)? I use that (essentially, exchange hosted by microsoft) for both my personal and business accounts.

Originally Posted by scottyvisa
One of my deciding factors in switching from PNC to my current bank was their lack of 2FA, my current bank does have it. Amazon offers it too, and since I make most of my purchases from them and they have a lot of my personal data I use it. Not sure if Transfer Wise offers it directly, but I use my Google login for it, so I get 2FA through that. If a site offers login via Google or Facebook, I normally go for that option. Even if they don't have 2FA, many sites with offer some kind of alert system that will text or email you if your account is logged into from an unrecognised location. This happened last week to me with Facebook, someone tried to access it in Canada and they alerted me, I was able to block the access and change my password.
Isn't using your Facebook account to log into another web site also asking for trouble? I did look into that at one point, and felt that it was not a good thing - but I can't honestly recall why.
Steerpike is offline  
Old Mar 1st 2017, 6:24 am
  #30  
BE Enthusiast
 
Joined: Mar 2015
Location: Virginia
Posts: 352
scottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond reputescottyvisa has a reputation beyond repute
Default Re: If you use transferwise change your password

Originally Posted by Steerpike
When you say 'outlook', do you mean office 365 (or does that include Office 365)? I use that (essentially, exchange hosted by microsoft) for both my personal and business accounts.



Isn't using your Facebook account to log into another web site also asking for trouble? I did look into that at one point, and felt that it was not a good thing - but I can't honestly recall why.
I mean Outlook.com, Microsofts consumer email service, previously known as Hotmail. Office 365 does have some kind of built in 2FA, at least for the multi-user version. For your individual use, you can definitely add 2FA to your Microsoft account, which is presumably how you access your Office 365 tools?

I prefer using Google over FB, but I trust either of them with security more than most other web services. When you sign in using FB or Google, the site doesn't get your password, it just gets confirmation from them that it is indeed you. As long as you create a new password each time for a new service it doesn't really matter, but using Google or FB account to authenticate saves you having to do that without exposing your password to any potential hacks of that service.
scottyvisa is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.