Showing posts with label Passwords. Show all posts
Showing posts with label Passwords. Show all posts

Wednesday, January 8, 2014

Bits Blog: More Security, Fewer Passwords

Sunday, June 9, 2013

State of the Art: Remember All Those Passwords? No Need

Have these security pundits ever listened to themselves?

That advice is clearly unfollowable. I currently have account names and passwords for 87 Web sites (banks, airlines, blogs, shopping, e-mail, Facebook, Twitter). How is anyone — even a security professional — supposed to memorize 87 long, complex password strings, let alone remember which goes with which Web site?

So most people use the same password over and over again, and live with the guilt.

There are solutions. Most Mac and Windows Web browsers now offer to memorize passwords for you. But that feature doesn’t work on all Web sites, and is generally of little help when you pick up your phone or tablet. At that point, the only person you’ve locked out of all your online accounts is you.

The only decent solution is to install a dedicated password memorization program (like Roboform, KeePass, LastPass, 1Password, and so on). Last week, one of the best was just improved: Dashlane, now at 2.0. It’s attractive, effective, loaded with timesaving features and available for Mac, Windows, iPhone and Android — and it’s free.

Installation is quick. Dashlane works in Safari, Chrome, Internet Explorer and Firefox. It can import existing password “vaults” from rival programs.

Dashlane has two primary features. First, yes, it’s a password memorizer. Every time you type your account name and password into a Web page and press enter, Dashlane pops up, offering to memorize that information and fill it in the next time.

In fact, it also offers to log you in — not just to enter your password, but also to click “log in” for you. In effect, Dashlane has just removed the login blockade entirely. When you go to Facebook, Twitter or Gmail, you just click your bookmark, smile at the briefest flash of the login screen and arrive at the site.

Since Dashlane is now storing and auto-entering your passwords, you’re now free to follow the security experts’ advice. You can make up long, unguessable passwords — a different one for every Web site, since you don’t have to remember any of them. In fact, each time you sign up for a new account, Dashlane offers to make up such a password for you, and then, of course, to memorize it.

Dashlane’s second huge feature is even more amazing. It can also fill in other kinds of Web site forms: your name/address/phone number, and even your credit card information.

When you’re buying something online, and you click into the credit card number box, Dashlane displays pictures of your credit cards: Visa, MasterCard, American Express or whatever — even PayPal.

When you click the one you want to use, Dashlane instantly fills in the long card number, your name, the expiration date, even that accursed security code, in the right boxes. Every time you order something online, you save between 30 seconds and five minutes, depending on whether you have your card information memorized or have to go burrow through your wallet.

When you make a purchase, Dashlane even offers to store all the details in a digital receipt that you can call up later, along with a screenshot of the Web site where you shopped. This feature makes online shopping so frictionless, every dot-com retailer on earth ought to be promoting Dashlane as if its profits depended on it.

In fact, Dashlane can fill in all kinds of forms automatically: phone numbers, job titles, tax numbers and so on. If you’ve ever recorded multiple answers — you have two different Twitter accounts, say — two tidy buttons appear beneath the name box, bearing the account names. Click the one you want.

Unlike some rival programs, Dashlane doesn’t require you to associate one set of personal information to each “profile.” If you have three addresses, for example, you’re always offered those three when filling in a form. You don’t have to create three personalities’ worth of personal information.

So far, Dashlane probably seems designed for convenience, and that’s true. Behind the scenes, of course, its ultimate goal is security.

This article has been revised to reflect the following correction:

Correction: June 7, 2013

The State of the Art column on Thursday, about the password memorization program Dashlane, misspelled the name of a rival program. It is KeePass, not KeyPass.

Sunday, May 26, 2013

Wealth Matters: Forgotten in Estate Planning: Online Passwords

At 72, he said his concern was not about Facebook or e-mail. It was for their financial lives, which have migrated online, making paper account statements anachronistic. Now, when people die without disclosing their financial affairs to anyone, there is often no paper trail for heirs to follow.

“You’d never know someone else’s financial arrangements, but if it was paperwork you’d have a clue,” Mr. Ginsberg said. “I’m entirely comfortable doing absolutely everything online. But if I have to take over for my brother or my partner, I don’t have any of their information.”

In its annual Wealth and Worth study, released this week, U.S. Trust said 45 percent of the high-net-worth people it polled had not organized passwords and account information for their digital lives in a place where heirs or an executor would find them. (By contrast, the bank said that 87 percent knew the location of important documents and most had a will.)

Much has been written about how family members struggle to get access to the e-mail and social network accounts of loved ones who have died. They have sentimental value much the way photo albums and personal letters do. But far less attention has been paid to the logins, passwords and answers to security questions that will give access to an online financial life.

In an era when far fewer records are kept on paper, spouses and children may not even know that some accounts exist. Think of savings accounts that are only online, or a rollover retirement account that hasn’t been touched in years.

“It’s not only something that needs to be addressed with an individual dying,” Chris Heilmann, chief fiduciary executive at U.S. Trust, said. “If an individual becomes incapacitated, people typically plan for someone to have a durable power of attorney so someone can step in and handle your affairs. But now you’re finding the attorney has to deal with your digital issues. They have to access your computer; they have to pay bills for you.”

Sharing the combination of letters or numbers that give access to a person’s most important financial details is turning out to be a lot harder than telling loved ones that everything they need to know is in a safe deposit box. What can people do?

There are many Web sites and tools that allow people to upload their accounts and passwords in so-called digital vaults. They promise security and a one-stop shop for disparate digital lives. But they often go unused — just as there are a lot of lawyers around but not everyone has an estate plan.

People need to record their account information and passwords just as they need to make an appointment to draw up a will. And that seems to be the problem.

Joel Feldman, a retired garment manufacturer, said he had an estate plan but he had been reluctant to write down all of his logins and passwords and give them to his son. He also does not use a financial adviser, who would know some of that information.

“It does concern me,” Mr. Feldman said. “I keep saying I’m going to make a CD of my bank statements and put it in my safe deposit box, but I don’t do it.”

He said he figured that his son could probably find everything on his computer.

One reason people say they put off drawing up a list is that passwords are constantly changing. But that doesn’t seem to be the reality for many in retirement now. Mr. Feldman said he has only two or three different passwords because he would forget more than that.

Kieran Clifford, a retired vice president for finance from Lucent, said the password to his Gmail account was recently stolen. By combing through past e-mails, the hacker found a Fidelity statement, got the account number, and e-mailed his broker at a separate firm to transfer $250,000 to a bank in Hong Kong. Everything had the same password — his initials and date of birth.

Wednesday, July 18, 2012

No Passwords Stolen in Minecraft Security Breach

After a Minecraft security breach over the weekend, Mojang reports that no passwords or personal information has been lost. According to Minecraft creator Notch on Twitter, a “flaw in [the] Minecraft authorization system” was exploited by hackers, which let them “log in as anyone” and control other people’s characters.


The servers were taken offline over the weekend as a result, but Mojang developer Leonard Axelsson notes on Twitter that "The session servers are back up again and it's no longer possible to login as someone else." In an updated blog post on the company’s official site, Mojang’s Lisa Winters also reports that “things are back up and running perfectly!” She also confirms that the breach did not result in "any leak of passwords or personal information” and thanks fans for being patient while the servers were fixed.



Minecraft will be updated to version 1.3 next month, rebuilding Minecraft’s single-player framework and adding emerald ore, new stairs and more. Minecraft was most recently released on Xbox 360, where special Summer of Arcade skins are now available.