You're Using a Password Manager Wrong

Поделиться
HTML-код
  • Опубликовано: 6 окт 2024
  • You're using a password manager wrong...
    Here's how to use one properly: • Harry Potter & the Pas...

Комментарии • 167

  • @BooksInSeconds
    @BooksInSeconds Год назад +182

    Whoa mannn.. something so simple yet so smart
    Genius stuff

  • @CorrosiveCitrus
    @CorrosiveCitrus Год назад +52

    Also known as adding pepper to the password, write down your pepper somewhere so you don't forget, and make sure it too is randomly generated for maximum security - - additionally use MFA/2FA where you can, always

    • @Sam10X
      @Sam10X  Год назад +7

      If you know, you know 😉

    • @YinYangTarotByJay
      @YinYangTarotByJay Год назад +2

      What’s 2FA And MFA?!

    • @CorrosiveCitrus
      @CorrosiveCitrus Год назад +6

      @@YinYangTarotByJay 2 factor, or multi-factor authorisation. It's where you require another factor than just something you know (ie a password), such as something you have (e.g. a time based code on a physical device)
      The most common 2FA set up is a password and a either a one time code sent via text or email, or a time-based code generated by an app on a mobile device. But there's plenty more, such as physical security keys like yubikey.

    • @Maniacguy2777
      @Maniacguy2777 8 месяцев назад +1

      Including cheese macaroni too.

    • @Jason_Lucero
      @Jason_Lucero 4 месяца назад

      U mean salt

  • @discord_and_entropy
    @discord_and_entropy Год назад +17

    perfect sync!!! THANK YOU

    • @Sam10X
      @Sam10X  Год назад +1

      You know it 😉

  • @Little.Twillight
    @Little.Twillight Год назад +22

    Its useful unless you are using autofill 😂😂

    • @Sam10X
      @Sam10X  Год назад +4

      Use what works…😂👌

  • @AnjoSoy
    @AnjoSoy Год назад +10

    Thats a great idea, thanks for sharing!

    • @Sam10X
      @Sam10X  Год назад

      Glad to hear it Marcos 🙏

    • @dreadeye452
      @dreadeye452 Год назад +1

      Bro write them down on a piece of paper

  • @truckn
    @truckn 9 месяцев назад +4

    *Never watched HP. But this method is brillant!*

    • @Sam10X
      @Sam10X  9 месяцев назад

      Love it! ⚡️

  • @morteza_nw
    @morteza_nw Год назад +9

    Useful...tanks allot

    • @Sam10X
      @Sam10X  Год назад

      Great to hear 👌

  • @aeronmarvelous3393
    @aeronmarvelous3393 Месяц назад

    Great idea! Thanks!

    • @Sam10X
      @Sam10X  29 дней назад +1

      You're welcome 🙌

  • @fuzzy-02
    @fuzzy-02 Год назад +4

    Basically have multiple a failsafe.
    Maybe a physical notebook.
    A password manager.
    Maybe an encoder/decoder for the combination of these two above.
    Listen, no locks are ever enough. What you are trading is your convenience for your security.
    You have 10 points, how you distribute them between convenience and security is up to you.

    • @Sam10X
      @Sam10X  Год назад

      So true, great points! 🙌

  • @benjaminblackburn
    @benjaminblackburn 9 месяцев назад

    simple and sweet. Thanks

    • @Sam10X
      @Sam10X  9 месяцев назад

      🙌

  • @10reubenl
    @10reubenl Год назад +2

    That’s clever!

    • @Sam10X
      @Sam10X  Год назад

      Glad you think so 🤓

  • @doge9455
    @doge9455 Год назад +5

    Thats genius

  • @AshKunDou
    @AshKunDou 2 года назад +1

    Haha because otherwise...haha! Love this method, makes so much sense!

    • @Sam10X
      @Sam10X  2 года назад +2

      Right?! Game changing stuff Ash!!

  • @rashawndiallo5228
    @rashawndiallo5228 Год назад +1

    Great advice

  • @girishkamath1992
    @girishkamath1992 11 месяцев назад +1

    Mind blown!
    Informative, useful, Harry Potter reference! Brilliant!!

    • @Sam10X
      @Sam10X  11 месяцев назад

      🤯 Love it!

  • @idlegus5831
    @idlegus5831 Год назад +3

    That is a neat method
    I think this would be better if the extension to the password included other characters or stuff. (like a mini password). Or that you have a select few to choose from, instead of 1.
    Either way, your method still makes the password longer, which makes it harder to crack. (which is good)

    • @Sam10X
      @Sam10X  Год назад +2

      Thanks bro, I agree, it can be as long and complex as you want, just a balance between convenience and security especially if you need to remember multiple!

    • @JohnSmith-kf1fc
      @JohnSmith-kf1fc Год назад

      ​@@Sam10X what if you had to remember just one but instead of being the last part of every password its an encryption code for the last 4, 6, 8 characters. you just remember "c4g8", c being the 3rd letter of the alphabet you add 3 to the corresponding number or letter, so a 3 becomes a 6 and a D becomes a G and etc. hows that sound?

    • @Sam10X
      @Sam10X  Год назад

      I think that sounds great, you’re transforming the characters in a consistent way! Only difficulty is it’s less convenient to use and you have to know/see what you’re changing from each time 🤔

  • @fefo112
    @fefo112 2 года назад +1

    Nice idea friend thanks

    • @Sam10X
      @Sam10X  2 года назад

      Game changer 👌

  • @CarlJohnson-gu8tn
    @CarlJohnson-gu8tn 10 месяцев назад

    this is genius, thanks

    • @Sam10X
      @Sam10X  10 месяцев назад

      🙌

  • @gorelowjeff5054
    @gorelowjeff5054 9 месяцев назад

    Smart!! Just subscribed

    • @Sam10X
      @Sam10X  9 месяцев назад

      Love it! ❤️

  • @geovannyl.2801
    @geovannyl.2801 Год назад

    EXCELLENT! Great idea!

    • @Sam10X
      @Sam10X  Год назад

      Haha yes! ✌️

  • @PictorialVibes
    @PictorialVibes Год назад

    Thank you for the great idea! Looks like we need to use a local "form-filler" to automate the secret "keyword" part!

    • @Sam10X
      @Sam10X  Год назад

      If you find it secure! 👌

  • @mukheshmattaparthi5634
    @mukheshmattaparthi5634 9 месяцев назад

    Nice trick man thanks

    • @Sam10X
      @Sam10X  9 месяцев назад

      🪄

  • @mesterfriend402
    @mesterfriend402 Год назад

    wow very genius although simple

    • @Sam10X
      @Sam10X  Год назад

      The best kind!

  • @arijanj
    @arijanj Год назад +27

    what if it gets leaked somewhere and now they know all your other horcruxes

    • @Sam10X
      @Sam10X  Год назад +11

      Good point. I think firstly you should have 2FA. Then more than one password needs to be leaked for someone to come to that conclusion because there’s no way to tell what part of the password your horcrux is i.e. how long, or location as it doesn’t have to be at the end or your password. And if your password manager itself is compromised you should probably change all your passwords anyway, so this gives you another layer of defence!

    • @globalprofits101
      @globalprofits101 8 месяцев назад +1

      Listen Harry Potter was never perfect 😂

  • @amangrewal490
    @amangrewal490 Год назад

    Thankyou very much, this is a great idea ❤😂😂

    • @Sam10X
      @Sam10X  Год назад

      You’re most welcome 👌

  • @whotfisjason7870
    @whotfisjason7870 8 месяцев назад

    I like this ALOT

    • @Sam10X
      @Sam10X  8 месяцев назад

      🙌

  • @matteroftim3
    @matteroftim3 11 дней назад

    defeats the whole purpose of having a pm.

  • @miiguelb07
    @miiguelb07 11 месяцев назад

    Omg, thats a great idea

    • @Sam10X
      @Sam10X  11 месяцев назад +1

      🙌

  • @Bloodycub666
    @Bloodycub666 9 месяцев назад

    this works for sure but if they break main frame server that store your passwords this no use

    • @Sam10X
      @Sam10X  9 месяцев назад

      Every bit helps…!

    • @Bloodycub666
      @Bloodycub666 9 месяцев назад +1

      @@Sam10X true

  • @nahidhasan8470
    @nahidhasan8470 4 месяца назад

    Actually it's very smart of you

    • @Sam10X
      @Sam10X  4 месяца назад

      🤓

  • @tp_exe
    @tp_exe Год назад

    thts a big brain move

    • @Sam10X
      @Sam10X  Год назад

      You know it 😉

  • @IdkG7
    @IdkG7 9 месяцев назад +2

    Bitwarden is end to end encrypted

    • @Sam10X
      @Sam10X  9 месяцев назад +1

      Just a little something extra for peace of mind 😉

  • @delomuvis4162
    @delomuvis4162 8 месяцев назад

    Where is the link to the full video?

    • @Sam10X
      @Sam10X  6 месяцев назад

      ruclips.net/video/GcUqb7oB8vg/видео.html

  • @GlorifiedGremlin
    @GlorifiedGremlin Год назад +2

    That's actually a really good way of fixing security flaws with password managers that sync to all devices. it's such a hassle to use offline secure password managers that don't sync between devices, but it's so much safer too

    • @Sam10X
      @Sam10X  Год назад

      Absolutely, helps us stay in control 🙌

  • @CarnisChampion
    @CarnisChampion Год назад

    This is upp my ally.

    • @Sam10X
      @Sam10X  Год назад +1

      Love it 🙌

  • @emerginggamer3925
    @emerginggamer3925 Год назад

    Great :)

  • @aiժeո
    @aiժeո 8 месяцев назад +1

    just use keepass...

    • @Sam10X
      @Sam10X  8 месяцев назад

      Different strokes for different folks 👍

    • @Crown42
      @Crown42 4 месяца назад +1

      Your right I use KeePass with a hardware two factor authentication and I have three copies of them in three different locations.

  • @dannid.8115
    @dannid.8115 Год назад

    How to stop password manager always asking to update your password? What do you used password mgr mostly?

    • @Sam10X
      @Sam10X  Год назад

      I’m not sure if I understand your question… the password manager shouldn’t be constantly asking you to update 🤔 and the password manager shown is Bitwarden

    • @dannid.8115
      @dannid.8115 Год назад +3

      @@Sam10X Yes I use bitwarden, example my password abcdefg written in bitwarden, then I log in, then I add my salting such as 1234, after log in success, bitwarden always ask, do you want to update the password. So Im looking password manager that support salting or how to turn off the bitwarden ask to update password.

    • @Sam10X
      @Sam10X  Год назад +2

      Ah yes, just go to settings > options, and uncheck “ask to update existing login”, see if that helps 👍

  • @chinmayadhiman3358
    @chinmayadhiman3358 Год назад

    Nice

  • @CAMohitShah
    @CAMohitShah 2 месяца назад

    Just got hacked and somehow saved my Facebook and Instagram account.
    I wish i could have found this video sooner

    • @ItzDelano
      @ItzDelano 2 месяца назад

      Did your password manager get hacked?

    • @CAMohitShah
      @CAMohitShah 2 месяца назад

      @@ItzDelano I am pretty sure hacker somehow hacked my Google Chrome passwordmanager
      Never going to use it again it is bad

    • @Sam10X
      @Sam10X  2 месяца назад

      That’s very unfortunate to hear…better late than never to improve security! 👌

  • @M-UltraInstinct
    @M-UltraInstinct Год назад +9

    Basically, you need to create your own password. It doesn't matter if you use a password generator or a manager.
    *There is a saying in the CIA, never store your passwords digitally and always change them monthly/weekly if it's weak and never change them at all if it's extremely strong* as you'll end up with a weaker password after changing it. Note that, you need to have an extremely strong password to not change it for years. *Generally, it's recommended that you change your most socially active accounts password after an year... basically the accounts which you use on websites or social media.*
    Extremely long or extremely short passwords are easier to hack considering you'll get more accurate hits, *so keep it balanced and less predictable to both humans who know you socially and computers which are good with algos, logic etc.* So never use numbers from your phone no, people you follow on social media, your favourite stars etc in your password.
    *Never enter your personal info, phone number, email, Google photos linked email etc anywhere.*
    *Btw, using your pendrive in a local printer shop is the best way to get a shit ton of malware...* that's where typical foreign Intelligence or hacker guys go for spreading/infecting.
    Cheers! 🥂

    • @Sam10X
      @Sam10X  Год назад

      Great things to keep in mind! Usually need to balance with convenience unless it’s super sensitive. Thanks for sharing 🙏

  • @illyshaieb
    @illyshaieb Год назад

    But they still have most of your password, so they can start with that and then run software to guess the rest?

    • @Sam10X
      @Sam10X  Год назад

      They could also just have your whole password otherwise? Haha and yes, they could keep guessing as they could have anyway, but they don’t know what they don’t know and it makes it all harder for them

    • @Blurro
      @Blurro Год назад

      the worst 'gotcha' to ever be thought

  • @felipegranda8254
    @felipegranda8254 10 месяцев назад

    Salty

    • @Sam10X
      @Sam10X  10 месяцев назад

      🧂

  • @aaron6841
    @aaron6841 2 года назад +5

    They will just brute force the one word on the end , that's why you use 2fa with the password manager and on the site

    • @Sam10X
      @Sam10X  Год назад +2

      Yes, need that 2FA!

    • @darklight6030
      @darklight6030 Год назад +5

      No one can brute force the all mighty 6969

    • @aaron6841
      @aaron6841 Год назад +4

      @@darklight6030 your right it's just not possible

    • @R26Roman
      @R26Roman Год назад +5

      How would they brute force the one missing word if they think they have the complete password 🤔

    • @aaron6841
      @aaron6841 Год назад +3

      @@R26Roman my point is brute forcing an extra word or 4-6 characters isnt going to make much difference.

  • @MrTomo89
    @MrTomo89 3 месяца назад

    Except password managers have zero knowledge and are encrypted

    • @Sam10X
      @Sam10X  2 месяца назад

      Just a little bit more peace of mind…

  • @michaelobrien9139
    @michaelobrien9139 Год назад +1

    This could link you to accounts in data breaches. Even though you’re not using the same password which is how this is usually done. If you change your name, email address, physical address. Using data analytics in theory run it through a keyword search and deduce this is the same person. This is how they catch criminals…

    • @grassytramtracks
      @grassytramtracks Год назад

      Perfect is the enemy of good, there is no such thing as 100% security, but improvements are worth making to protect yourself and mean that your account won't be the low hanging fruit

    • @Sam10X
      @Sam10X  Год назад

      Agree with both these points, this is probably more a quick win rather than solving for everything in the grander scheme of things. Great to highlight this though 👌

  • @waryth4475
    @waryth4475 Год назад +1

    This is just password salting and you just renamed it horcrux being a Harry Potter fanboy.

    • @Sam10X
      @Sam10X  Год назад

      🧙‍♂️🪄

  • @kimbapslayer1995
    @kimbapslayer1995 Год назад +2

    Lmfao. Stop misinforming people. If a hacker gets into a password manager, they get nothing but encrypted gibberish. Emails maybe.

    • @Sam10X
      @Sam10X  Год назад +1

      Fake news? 😂 it’s an extra layer of security and peace of mind regardless, and who knows if they can get it decrypted…

    • @kimbapslayer1995
      @kimbapslayer1995 Год назад

      @@Sam10X no one or group can decrypt military / bank AES - 256 encryption LoL. Trusted password managers have multiple layers. It would take a quantum super computer to break the encryption lol and would take many many many many many lifetimes.

    • @kimbapslayer1995
      @kimbapslayer1995 Год назад

      @@Sam10X also, 256 AES level encryption has never in history been cracked.

    • @Sam10X
      @Sam10X  Год назад

      Yeah that’s interesting, I agree 🤔 I think this is less about directly cracking the password itself, and more about hackers getting access to the stored passwords through other means

    • @Blurro
      @Blurro Год назад

      huh? sure if they get just the encrypted database itll be gibberish, but not if they actually enter in with the master key or whatever the actual user of it has

  • @mrmatt24
    @mrmatt24 Год назад

    I was about to dislike this, but I watched and actually seems like a good idea.

    • @Sam10X
      @Sam10X  Год назад

      Glad you stayed for a few extra seconds 🙌

  • @ravijaiswal6995
    @ravijaiswal6995 Год назад +1

    Love from india

  • @zachmendez8037
    @zachmendez8037 3 месяца назад

    💀💀💀💀💀💀💀🤣🤣🤣🤣🤣

    • @Sam10X
      @Sam10X  3 месяца назад

      😈

  • @gallateaclayman5005
    @gallateaclayman5005 10 месяцев назад

    😂😂 its for the rich people

    • @Sam10X
      @Sam10X  10 месяцев назад

      😂

  • @longluu1141
    @longluu1141 4 месяца назад

    Misinformation. Reported

  • @_Epictetus_
    @_Epictetus_ 8 месяцев назад

    This is useless, most sure limit your max character count🤦

    • @Sam10X
      @Sam10X  8 месяцев назад

      Unfortunately not too great for the character limited ones 🙁

  • @shutupcuh111
    @shutupcuh111 Год назад

    wtf

    • @Sam10X
      @Sam10X  Год назад

      😂

    • @MiVidaBellisima
      @MiVidaBellisima Год назад

      I was thinking wtf….. why didn’t I think of this!!!

  • @marttyd
    @marttyd 6 месяцев назад

    Too bad I don’t understand. Talks too fast.

    • @Sam10X
      @Sam10X  6 месяцев назад

      They need to add a half speed option...

  • @lumirpe
    @lumirpe Год назад

    Great

  • @ThiagoFernandes-h6t
    @ThiagoFernandes-h6t Месяц назад

    NIce trick. Do u use one horcrux for all websites? Or you memorize a horcrux for every website (too much horcrux to memorize lol)

    • @Sam10X
      @Sam10X  Месяц назад

      The idea is to just use the one, otherwise you end up basically having unique passwords to remember again - I’ve made another video that goes into more detail 👌

  • @filthypirate
    @filthypirate Год назад

    Genius stuff lol

    • @Sam10X
      @Sam10X  Год назад +1

      Big brain moves 🤓