<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" 
      xmlns:thr="http://purl.org/syndication/thread/1.0">
  <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html" />
  <link rel="self" type="application/atom+xml" href="http://ask-leo.com/atom.xml" />
  <id>tag:ask-leo.com,2009://3/tag:ask-leo.com,2009://3.3692-</id>
  <updated>2009-11-18T17:49:37Z</updated>
  <title>Comments for Are password safes secure?</title>
  
  <generator uri="http://www.sixapart.com/movabletype/">Movable Type 4.25</generator>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34544</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34544" />
    <title>Comment from Ken Crook on 2009-04-11</title>
    <author>
      <name>Ken Crook</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>After I had bought the new Norton AntiVirus 2009, I noticed another version of Norton AntiVirus that seemed to have a password vault included.  Has anyone seen this? Is the product any good?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-12T05:47:30Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34543</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34543" />
    <title>Comment from Glenn P. on 2009-04-08</title>
    <author>
      <name>Glenn P.</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>Does anyone know of a password keeper that uses Blowfish? I have just learned -- to my astonished dismay -- after years of contented usage, that the password manager which I *thought* used Blowfish, in fact uses nothing of the kind! Any suggestions for a new one?</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-08T12:20:19Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34542</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34542" />
    <title>Comment from dave on 2009-04-07</title>
    <author>
      <name>dave</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>i just tried out LAST PASS and i like it better than roboform. it really is awesome.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-08T03:34:59Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34541</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34541" />
    <title>Comment from Gord Campbell on 2009-04-07</title>
    <author>
      <name>Gord Campbell</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>If you use a password safe, one thing is guaranteed: one day, you will lose all your passwords.  My preference is a file folder that is in a stack of file folders near my computer, with all my passwords written on the inside of the folder.  And the really essential ones, on a slip of paper in my wallet when I travel, with hints as to what they are the password to, not the actual web site name.<br />
<div class="leocomment">As long as you back up regularly, there's no need to ever lose your password safe or its contents. Paper by the desk is notoriously unsecure.<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">08-Apr-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-08T00:30:53Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34540</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34540" />
    <title>Comment from Gigi on 2009-04-07</title>
    <author>
      <name>Gigi</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>I think the best solution is the Wand facility from Opera browser, it's already integrated in the browser (no aditional problems with another, separate program like Roboform) and the data is very well encripted. Online sites like Gator or CloakPass are the absolute worst solution, it would be safer to put your passwords on a billboard and hope nobody reads them.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-07T20:57:50Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34539</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34539" />
    <title>Comment from Richard on 2009-04-07</title>
    <author>
      <name>Richard</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>Leo,</p>

<p>I've been using KeePass password safe for a few weeks now.  But I've always wondered if I am vulnerable to being hacked while KeePass is opened.  In other words, is it important for me to keep the password safe locked when not in use, or can I leave it unlocked and on my taskbar?  It's kind of a hassle to have to key in my master password every time I want to use the safe.  But, my assumption is that while unlocked, I am vulnerable to any sort of online attack.  Please advise. <br />
<div class="leocomment">It's as safe as any information on your computer. If your computer is infected with a keylogger, for example, where you store your passwords won't matter - the keylogger will capture your entry. I've not heard of any malware that actively hunts for password safes, though.<br /><br />
Bottom line: a password safe is <strong>part</strong> of a strategy to stay safe, but it's no replacement for making sure that you don't get infected. Once infected, all bets are off.<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">08-Apr-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-07T18:38:23Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34538</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34538" />
    <title>Comment from Yoshi on 2009-04-07</title>
    <author>
      <name>Yoshi</name>
      <uri>http://unspecified</uri>
    </author>
    <content type="html" xml:lang="en" xml:base="http://unspecified">
      <![CDATA[<p>CloakPass.com is interesting because it's a totally different approach. It doesn't store your passwords in a vault that can be stolen or hacked... it doesn't store them online... It stores them in your own brain. It's not a web tool and it allows you to have passwords like %43kjl6^^@#K and not have to even type it in... It's a totally new approach to password management. www.cloakpass.com..... it's not a plugin.... so you can use it for ANYTHING (except logging into windows its self)<br />
<div class="leocomment">Since you didn't say what CloakPass <strong>is</strong> I went and looked. It's something you install in Windows that, on demand, lets you type in a plain text password that you would remember and converts what you type on the fly to more obscure characters. On the surface, an interesting idea.<br /><br />
It does mean that you <strong>must</strong> have CloakPass installed to login to anything for which you chose to use it. They make it easy(ish) to "mail yourself" (as they put it) the program, but it requires .NET framework, so you're not going to use it from other platforms like Linux or Mac.<br /><br />
The idea is interesting, but I'm not at all convinced of its practicality for the average user.<br />
<div class="leocommentsig">- Leo<br /><span class="leocommentdate">08-Apr-2009</span></div></div></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-07T17:07:40Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34537</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34537" />
    <title>Comment from Dave on 2009-04-07</title>
    <author>
      <name>Dave</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>If you don't want to even chance someone hacking your computer for passwords, try cloakpass.com as nothing is stored and you can easily scramble your simple passwords.  It's free.</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-07T16:38:17Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34536</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34536" />
    <title>Comment from rammolo on 2009-04-01</title>
    <author>
      <name>rammolo</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>You can check for your password strength here.</p>

<p><a href="http://www.microsoft.com/protect/yourself/password/checker.mspx"><a href="http://www.microsoft.com/protect/yourself/password/checker.mspx">http://www.microsoft.com/protect/yourself/password/checker.mspx</a></a></p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-02T00:20:48Z</published>
  </entry>

  <entry>
    <id>tag:ask-leo.com,2009://3.3692-comment:34535</id>
    <thr:in-reply-to ref="tag:ask-leo.com,2009://3.3692" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html"/>
    <link rel="alternate" type="text/html" href="http://ask-leo.com/are_password_safes_secure.html#c34535" />
    <title>Comment from Dave Hartley on 2009-04-01</title>
    <author>
      <name>Dave Hartley</name>
      <uri></uri>
    </author>
    <content type="html" xml:lang="en" xml:base="">
      <![CDATA[<p>One plug-in for Firefox which I've been playing with is PasswordMaker.  This uses a "master password", the web address of the site, your user name, and any other information you want to use to generate passwords on-the-fly using a hash algorithm.  I really like the idea of creating passwords like this -- no saved password lists in your browser, it just re-creates the password time after time.</p>

<p>Still haven't gone with it totally yet, though, for one very simple reason -- portability.  Even though they have a website that can generate the passwords if you're away from your computer, it just not as easy to use as the plug-in.  I'm still trying to work out a "best practice" for using it, but I think there's merit in the idea ...</p>]]>
      <p>A comment on: <a href="http://ask-leo.com/are_password_safes_secure.html">Are password safes secure?</a></p>
      <p>
        <a href="http://ask-leo.com">Tech Questions?</a>
        <a href="http://ask-leo.com">Get Answers!</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> ... by Leo Notenboom<br/>
        <a href="http://newsletter.ask-leo.com">Leo's Answers Newsletter</a> -
        <a href="http://ask-leo.com">Ask Leo!</a> in your inbox every week.
      </p>
      <p style="font-size: smaller">All content <a href="http://ask-leo.com/terms.html#copyright">Copyright &copy; 2009</a>.</p>
    </content>
    <published>2009-04-01T22:28:03Z</published>
  </entry>

</feed>
