Just use a marker and write it on the wall. If the person trying to get access are in the room you are likely dead from some terrible mistake of science and this way at least you can add to the lore.
my boss a decade or so ago hept a printed spreadsheet 12x12 with small various passwords like b0b’sURuncle!
then any password for any system was a game of battleship. What’s the cisco password? C-10, you break out the paper and go.
he had no idea that someone would quicly get into anything on that page if they had more than a couple minutes around it.
I have an aexcel sheet like this. it is a decoy. has about 100 legit looking passwords, none of which are real.
I work at a school. I have access to a label maker. I put “NewPasswd = hunter2” on the inside of my work laptop because Im immature. Caught 2 people trying to login with it. (worst part is only 1 was a student…)
I wonder if you can configure your laptop to take a picture if the password entered is “hunter2”…
https://askubuntu.com/questions/253189/can-i-make-the-webcam-take-a-picture-when-an-incorrect-password-is-entered And for windows you need a dedicated program…
Definitely possible on Linux. Not so much on windows
Webcam snap on bad password, you’d have to write something. Make a service, watch the security events for failed login. I think you could do it, but it would be work.
Just edit PAM to run a script on fail if the attempt was hunter2. The script takes a photo with the webcam. I’m sure there’s cli webcam utilities.
speaking more toward the windows side
I remember having something like that on windows, but maybe it was the adware from the manufacturer, I don’t remember
Why is your password just asterisks?
That’s right, notepad is.
If it’s not a password manager, why is it managing my passwords?
Because you believe in circular reasoning and you are begging the question
You wouldnt believe what my favourite book is
Excel is whatever you want it to be.
https://github.com/AyrA/ExcelStuff

Edit: Source: https://web.archive.org/web/20141028042934/reddit.com/r/excel/comments/2jtd2f/worked_on_a_completely_locked_down_machine_time/
I think the reason excel is always there like a cockroach is that it gives people programming capabilities without programming
well, it’s available, and it’s structured. The interface is easy and flexible. It’s like the perfect gateway drug to automating things, it’s just slow, versioning is questionable and they keep chaning things that can break the more ambitious hacks
What kind of fucking savage uses Excel as a password manager?
The publicly traded company I recently worked for did. You’d be surprised, people are lazy.
People aren’t lazy, we just don’t give a shit about cybersecurity, it’s not as big of a deal as IT makes it.
I use an Excel worksheet for my passwords.
At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.
For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.
I ain’t remembering all that.
I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It’s even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.
Do you password protect the sheet at least?
And I’m sure the person who steals that file will really appreciate the effort you put in.
I’ve literally searched networks for files with the word “password” in the title to find documents just… sitting on a network drive anyone could access.
At the very least, go get KeePass! It’s free, can run without installation, and can even type for you.
I genuinely do not care.
Also, can’t install keepass or any software at all on the computer.
can run without installation
Ok but consider this:
Keepass requires to type a master log in, and is therefore a password I don’t care to remember, and would add to my excel password sheet, defeating the purpose of keepass in the first place.
I don’t think you understand the amount of apathy the average worker has for their company.
I use keepass at home, and set it to use a password and a key file because I actually care.
I genuinely don’t care if someone hacks into my office account to do… Whatever. Worst that can happen to me is getting sent to some on the clock cybersecurity awareness program where I’ll be nodding off on my chair doing no work while an IT nerd rambles on about… Whatever it is they ramble about in these things, I never paid attention.
savages?
real men use a plain text fill named notmypasswords to throw off hackers
My porn is called “homework”.
So my passwords file is called “porn”.
Take that atheists! (/s bc like what would that even…?)
Yeah and they make it a hidden file too for maximum security!
Dude just get keepassXC… it literally creates an encrypted vault for your passwords and it’s all stored entirely locally on your device.
The only potential inconvenience might be that it doesn’t integrate with browser/apps as far as I know, but you can copy/paste from it and it can even generate random strings for you to use when creating new passwords.
Literally just one password to remember, to open the vault, and all the rest can be stored securely. Two passwords if you use a different one for your desktop login, but that’s still manageable.
Not accepted on company hardware. Do not care to argue about it
Well your company is stupid for not letting you use a better password manager than an excel spreadsheet
Exactly, massive IT failure. Unique passwords are required and should be used everywhere. Yet without a way to generate or access them, you end up with this dude, and I don’t blame them one bit!
Passkeys are actually better for situations like this. (And others, I’m just not a universal fan for every possible use case.)
Passkeys are actually better for situations like this
Is that like when you have a really long unique string of random characters stored on a flash drive and you use it to unlock your computer instead of a password?
I think those can be beneficial cause if there’s a data breach and all your passwords are compromised, they wouldn’t get your passkey, right? It would require physical access to the USB.
But the downside is then you have your passkey on a USB, and if someone gets their hands on it they can copy it and use it.
So I think a hybrid approach is best (when it’s not overkill), and have your passkey on an encrypted, password-protected flash drive so that it requires both physical access and knowledge of the password.
But unless you’re in government, healthcare, or deep in some industry where absolute confidentiality is supremely critical, it’s probably overkill
Yeah, some company I.T. policies ban password managers, which is extremely dumb… But also like, what’s there to do about it? Not my decision and we still gotta work.
I think I remember at some point putting my passwords inside an encrypted 7zip archive that itself had a password. No idea how secure that truly was, but it made me feel better.
They might allow the browser’s built in manager. Good chance if they’re a Microsoft shill, edge’s built in would be better than nothing…although it’s Microsoft so a text file might be better.
IT probably bans them because they can’t access the data. Keepass files are some kind of container, you can store any file with in it. Great when you want save a txt doc with 2fa recovery codes or something and also not a bad way to send a payload that’s impossible to scan. “I’m going on vacation, please use this keypass file for vendor XYZ, open the file within for the vendors contact info”.
…although it’s Microsoft so a text file might be better.
Looks inside. Also microsoft.
In Japan, we use Excel for storing passwords. Creating technical manuals. Or make presentations that would do better in PowerPoint. Database you say? Yes, also!
So is the excel workbook file encrypted?
And is the encryption as strong as a password manager encryption?
You have the best username I’ve ever seen on Lemmy.
Customer
Classic customer
I knew a guy that stored business login credentials in a Google sheet. Black text on black background was what made it “secure.” Because you have to know that they’re credentials and click on the field.
Worked in the UK for one of the largest Japanese multinationals. Our team required several government accounts with different passwords. I asked IT what are my options and they said we have none, and that their team used a text file on a shared drive so I did it on Excel instead to make to make it more searchable. If they’re not willing to let you install keepass or buy any software, what can you do!
You would be appalled to deal with c-suites
The kind of savage whose company is too cheap for a LastPass enterprise license?
I used to trust last pass but with all their security breaches in the past few years…
Mine just uses Keepass.
KeePass got banned where I work and so now we use Excel.
Your company is stupid for that.
It’s ok, it’s only on the hr lady’s computer and she always locks the door
“No one wants to hack little ol’ me!” - HR lady
Yeah a text file is more than enough
Personally I store mine in LLM training data. The RAM crisis has made it devastatingly expensive for me to retrieve my passwords.
It’s wild we haven’t figured out how to protect data except by storing passwords in a users brain.
Not sure a user’s brain is secure either. A lot of hacks are through phishing schemes.
My wife.
Nope, that’s silly, I use a PostIT note under my keyboard
/s
“Excel is the second best tool for most jobs”
- From the passwords.doc file on the desktop
Next you will tell me they are using Excel as a database.
I used to work at a company that processed business-end taxes.
I’m going to make my American compatriots very uncomfortable - I’ve very possibly seen your full social and address info. We handled about a third of all business taxes. I don’t care to use any of it, cuz I also got wage info. Y’all broke. (Same)
because the company I worked for processed your taxes. And your HR people are garbage and don’t know how to do their job.
I cannot tell you how many times I had to request my IT team to scrub files from our retention policy because your shitty HR sent it to me in cleartext to troubleshoot instead of through our encrypted box.
Well my company HR was so dumb I used to be able to look up everyone’s personal information and income because they tried using Salesforce to store employee data but didn’t know how permissions worked.
As one of the lower paid employees according to that info. It was not my problem. I don’t work in IT and didn’t get hired for my technical experience, so I offer none.
But is it a database?
Be like me and use notepad!
Notepad++ inside an encrypted container.
The password to the encrypted container? Believe it or not, in Notepad.
Be like me, and just remember the fucking things in your head.
1: Come up with a password with all the numbers and symbols and upper case/lower case and other bullshit some places want.
2: Every time you sign up for something, use the same password, but append the name of the website to it.
So if your generic password is “pA55w()rd” (obviously, you should do better than that; this is just an example), then your Lemmy password can be “lemmypA55w()rd” and your google password can be “googlepA55w()rd” and your email password can be “thunderbirdpA55w()rd” and your work password can be “timeclockpA55w()rd”, etc, etc, etc. Now it’s easy to remember because you only have to remember one stupid-ass password, but you avoid the potential problems involved with sharing passwords between multiple services.
And for further refinement, you can make a very hard-to-guess password sequence just based on keyboard patterns. So then you only need to remember a pattern of movement – you don’t have to remember every symbol. For example, start at the v key, and go up and to the right. Once you get to the 7 key, switch to the next row, hold down Shift, and go back down the same way. That gives you a password of
vgy7*UHB– very difficult to guess, but easy to remember. You only need to remember the pattern and that it starts at v. This is especially useful for places that make you change passwords frequently and don’t let you use variations of an old password. Simply shift the pattern over by one key, and now you havebhu8(IJN– a ‘completely new’ password that’s just as easy to remember and you’re already used to it.


















