FREEWARE SPOTLIGHT By Deanna McElveen You have a password book. You know the one. That ruffled little book with the cover falling off and marked-out p
[See the full post at: No Crappy Passwords — Secure passwords, no password book]
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
No Crappy Passwords — Secure passwords, no password book
Home » Forums » Newsletter and Homepage topics » No Crappy Passwords — Secure passwords, no password book
- This topic has 17 replies, 8 voices, and was last updated 2 years, 5 months ago by
Mariana.
AuthorTopicDeanna McElveen
AskWoody PlusOctober 17, 2022 at 2:44 am #2489308Viewing 9 reply threadsAuthorReplies-
Bob Bell
GuestOctober 17, 2022 at 8:05 am #2489418I think this is a reasonable alternative to password vaults, which I use regularly. I like that I don’t have to carry my password file around with me. However, just like my vault’s master password, doesn’t this mean that if my offset gets into the wrong hands, it could be used to create the same password that I used to secure my accounts, and then they can login as me?
-
db98445
AskWoody Lounger
-
-
Confucius
Guest -
Brian Perkinson
Guest -
Michael432
AskWoody_MVPOctober 17, 2022 at 1:57 pm #2489551When you have to change the password for an existing account, you would need to come up with a new nickname for the account. For example “capitalone” might morph into “capitaloneb”
Get up to speed on router security at RouterSecurity.org and Defensive Computing at DefensiveComputingChecklist.com
-
-
Michael432
AskWoody_MVPOctober 17, 2022 at 2:06 pm #2489553It is good that this software does not involve a browser extension. But …
- Recommending password software that only runs on Windows seems a bit off the mark these days.
- The term “offset” is not user friendly for non techies
- It is not able to limit the special characters that it creates. There are many places where certain special characters are not allowed.
- Trusting software with all your passwords. Are you kidding me?
- RTFM:” Version 10 will give different results for the same input due to a couple of changes under the hood if you have used a previous version.”
The software is somewhat similar to the formulas I wrote about here.
https://michaelhorowitz.com/BestPasswordAdvice.php
I think the formula system I wrote about is better, but reasonable people can disagree.Get up to speed on router security at RouterSecurity.org and Defensive Computing at DefensiveComputingChecklist.com
4 users thanked author for this post.
-
db98445
AskWoody LoungerOctober 17, 2022 at 2:13 pm #2489554Really good suggestions. Linux and Windows binaries are included, but the source is also available and will run on anything with a TCL interpreter. “Offset” is explained in the readme, but I don’t think it’s really necessary anyway. The special characters .. I think an option to use only Base64 or (gasp) HexDec would be a good idea.
-
-
grandma78633
AskWoody PlusOctober 17, 2022 at 2:41 pm #2489557I have used a simple, small encrypted file program, Secret! by LinkeSoft for well over 25 years. This is a “shareware” program with an extremely reasonable one time price. This program creates an encrypted file on your computer and/or your phone (2 separate programs that sync). You remember ONE password for the file and can save all your passwords. Since the desktop and phone versions can be manually sync’d I am never without my passwords. I back this up to both a USB drive and iDrive cloud backup and it is super simple to restore or move to a new computer.
I just checked the website and notice they are only showing the Windows and Android versions although I have had the iOS version on my phone ever since I started wearing hearing aids that only connect to iOS – – maybe 10 years. I have contacted them to ask about this.
I assume from your article, that NoCrappyPasswords does not work/sync to iPhone, so I would have to have a different solution when using my phone??
-
Michael432
AskWoody_MVPOctober 17, 2022 at 3:31 pm #2489559Some people want no part of password synching. For some, privacy is the issue, for others the objection is that complicated things break more often than simple things. There is no one right answer.
Are you backing up just the encrypted password file or the software too? You need both.
And, can you export your passwords? If not, you are putting all your trust in the software. As an old techie, I learned long ago that was sub-optimal.
Not to be overly critical, your approach is better than most
Get up to speed on router security at RouterSecurity.org and Defensive Computing at DefensiveComputingChecklist.com
-
db98445
AskWoody LoungerOctober 17, 2022 at 3:59 pm #2489563I made a small sqlite front end once, still use it, that stores logins, passwords, and notes, it works pretty well, actually, the db is encrypted / decrypted using a simple call to openssl without any additional hashing or anything, so in the worst case, I can just read the thing using a sqlite browser. It gets backed up to a couple of cloud services. I’m like you, I don’t like these things attached to other utils.
-
-
-
bbearren
AskWoody MVPOctober 17, 2022 at 4:41 pm #2489566I have a password protected Excel spreadsheet for usernames and passwords, and it’s not named “Passwords”. I can easily randomize a password in the cell, then save it. I’ve never seen a need for an extra piece of software just for usernames and passwords.
Always create a fresh drive image before making system changes/Windows updates; you may need to start over!We all have our own reasons for doing the things that we do with our systems; we don't need anyone's approval, and we don't all have to do the same things.We were all once "Average Users". -
Joel Albert
GuestOctober 19, 2022 at 2:30 pm #2490228AM i missing something> As described, it’s super easy to create a good password. But the account doesn’t explain how the password is easily inserted at the desired site (bank, e.g.). I’m inferring the user is expected to invoke the short program, retrieve the password, copy it, then paste it into the site. That doesn’t sound reasonable.
If that’s correct, a free password mgr such as LastPass could generate an effective and unique pwd and much more quickly enter it into the site’s pwd field.
(FYI: There are many times when pwd’s are not remembered by the site though the user has made the choice to do so)
Help me understand this? thnks
-
db98445
AskWoody Lounger
-
-
Alex5723
AskWoody PlusOctober 25, 2022 at 2:02 pm #2491947I believe the point of the thing is to make it so that you don’t ever have to file anything, eliminating the possibility of the password manager being compromised.
-
opti1
AskWoody PlusNovember 6, 2022 at 12:53 pm #2495859That is what passkeys (FIDO) brings.
The problem, at least for me, is how few sites (relatively speaking) support FIDO, like almost none of the ones that I most would want to support it do so. This comes up every time I see the Yubikeys go on sale somewhere and I go to https://2fa.directory/us/ to review their list.
If anyone knows of a better, more thorough, and\or more up to date list of sites that support FIDO\2FA I would love to hear about it.
-
-
grandma78633
AskWoody PlusOctober 25, 2022 at 2:27 pm #2491958I did check and was told there was not enough interest in the iOS version to continue to support it. It is saved in my iPhone Apps and will continue to work until there is a change in iOS that prevents it from working. I will pray that Auracast will be available in all hearing aids and phones by then and I will transition back to Android!!!
-
Mariana
Guest
Viewing 9 reply threads - This topic has 17 replies, 8 voices, and was last updated 2 years, 5 months ago by
-

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Steps to take before updating to 24H2
by
Susan Bradley
2 hours, 32 minutes ago -
Which Web browser is the most secure for 2025?
by
B. Livingston
2 hours, 33 minutes ago -
Replacing Skype
by
Peter Deegan
2 hours, 34 minutes ago -
FileOptimizer — Over 90 tools working together to squish your files
by
Deanna McElveen
3 minutes ago -
Excel Macro — ask for filename to be saved
by
nhsj
5 hours, 58 minutes ago -
Trying to backup Win 10 computer to iCloud
by
SheltieMom
1 day, 3 hours ago -
Windows 11 Insider Preview build 26200.5570 released to DEV
by
joep517
1 day, 16 hours ago -
Windows 11 Insider Preview build 26120.3941 (24H2) released to BETA
by
joep517
1 day, 18 hours ago -
Windows 11 Insider Preview Build 22635.5305 (23H2) released to BETA
by
joep517
1 day, 18 hours ago -
No April cumulative update for Win 11 23H2?
by
Peobody
6 hours, 40 minutes ago -
AugLoop.All (TEST Augmentation Loop MSIT)
by
LarryK
1 day, 19 hours ago -
Boot Sequence for Dell Optiplex 7070 Tower
by
Serge Carniol
2 days, 10 hours ago -
OTT Upgrade Windows 11 to 24H2 on Unsupported Hardware
by
bbearren
2 days, 13 hours ago -
Inetpub can be tricked
by
Susan Bradley
21 hours, 16 minutes ago -
How merge Outlook 2016 .pst file w/into newly created Outlook 2024 install .pst?
by
Tex265
1 day, 7 hours ago -
FBI 2024 Internet Crime Report
by
Alex5723
2 days, 17 hours ago -
Perplexity CEO says its browser will track everything users do online
by
Alex5723
2 hours, 40 minutes ago -
Login issues with Windows Hello
by
CWBillow
3 days, 4 hours ago -
How to get into a manual setup screen in 2024 Outlook classic?
by
Tex265
2 days, 16 hours ago -
Linux : ARMO rootkit “Curing”
by
Alex5723
3 days, 16 hours ago -
Employee monitoring app leaks 21 million screenshots in real time
by
Alex5723
3 days, 16 hours ago -
Google AI is now hallucinating idioms
by
Alex5723
3 days, 16 hours ago -
april update
by
69800
1 day, 21 hours ago -
Windows 11 Insider Preview build 27842 released to Canary
by
joep517
3 days, 17 hours ago -
Quick Fix for Slowing File Explorer
by
Drcard:))
3 days, 17 hours ago -
WuMgr not loading?
by
LHiggins
2 days, 13 hours ago -
Word crashes when accessing Help
by
CWBillow
3 hours, 56 minutes ago -
New Microsoft Nag — Danger! Danger! sign-in to your Microsoft Account
by
EricB
3 days, 17 hours ago -
Blank Inetpub folder
by
Susan Bradley
3 days, 15 hours ago -
Google : Extended Repair Program for Pixel 7a
by
Alex5723
4 days, 4 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.