Wednesday, March 11, 2009

The horror of password management

I decided to take the dive and use 1Password for managing my passwords. I do have quite a few web logins (about 50+), though to be honest, they are mostly using the 3 password variants I have.

The first thing I did was to record all my accounts in it. It works, mostly. Except for websites that uses a virtual keyboards or login applets or flash.

That was vaguely disappointing.

Next, it is time to use strong unique passwords for all of them :)

Sadly, updating passwords work only in half the time. In most times, 1Password was unable to detect that I was performing a change password on the current website. Instead it prompts me to save the login, which totally screws up the login entry in 1Password.

I realized that 1Password works best for change password only when the page consists of 3 form fields: Current Password, New Password, and Confirm New Password. I forgot to check if the field name matters though.

I was unable to change password for some of my logins though. Those websites were horrible! Giving me 404 or 500 errors when I tried to changed my password! There were php errors, aspx errors, and even jsp! *shakes head*

So now that my passwords are all unique and strong, my 1Password becomes a single point of failure though. I hope I do not lose it... :)

blog comments powered by Disqus