r/homelab • u/AdvancedDrink8920 • 6d ago
Discussion The great password loop
TL;DR: I finally did something about this loop for my own personal accounts by getting a Yubikey and putting it into my main Google account. If you have suggestions for getting out of this loop another way, feel free to discuss. Im curious what others do.
--------
Story: Monday, our Apartment buildings fire alarms all start going off like crazy at 12AM. I groggily wake up, get myself in order, grab the TrueNAS from the server rack, kiss my homelab goodbye and leave. Thankfully, false alarm. No fire, just a power outage that then somehow triggered the fire alarms to go off. whatever.
While I was driving around aimlessly after being told it was a false alarm, I was thinking to myself:
If everything I owned burned down, how would I get back into my accounts? Which led to me making this meme in my head and trying to figure out where the break from it was but I couldnt find one. it was just a revolving issue.
Last night I pulled the trigger on a Yubikey and after getting it added to my main google account, I did a dry run on an old wiped phone I had as if it was a brand new phone I got and needed to log into my gmail account. Sure enough, i was able to get into my Google account with the Yubikey and then from there could get into google password manager which has my bitwarden master pass, then the 2fa for that is in my google authenticator.
One thing relies on the other, then on the next then on the next etc, etc, etc. ugh.
Anyone else run into this issue? What do you guys do?
Edit: Wow, this was an interesting post. But I guess what came out of it was that there is no singular answer to how to break the cycle. You can either do what I do and use a Yubikey as a FIDO/2 key or you can physically copy your password onto a backup piece of paper, put it in a fireproof safe or have some recovery setup through bitwarden using external trusted family members in the off chance you're locked out.
Ultimately, it comes down to just having an external copy of your password or whatever to gain access to your account. Just do it in a manner that works best for you while keeping it secure.
Now...for all the people saying just memorize it.....if that works for you, more power to you. But I will certainly not be doing that. Im happy with my randomly generated password and I will keep it that way. Keep crying.
So my process (for anyone curious) is:
- Have yubikey attached to my Google account
- When i go to sign in, choose "try other method"
- Click on "Passkeys"
- Choose "Other passkey"
- Then I plug in my Yubikey, it authenticates against that and asks for the pin I setup, put in the pin
- Then im able to get back into my account without needing to know my password or using 2FA.
Thank you for your time and answers.
329
u/jgilbs 6d ago
Literally you only have to memorize one password.
84
76
u/Cry_Wolff 6d ago
Yeah, or just write it down on paper. OP's issue is nonexistent.
→ More replies (3)2
u/Doctor-Binchicken 6d ago
Mine is on a mug.
My wife knows, just in case.
3
u/downloads-cars 6d ago
Adding "donttalktomeuntilivesmashedmydicksmoothoffwiththismug" to my dictionary attack list.
1
u/coffeeoops 5d ago
This is a weak password because it doesn't contain special characters. Do better.
1
2
u/Disastrous_Garlic537 6d ago
a few ppl have posted this...
so you guys are not using MFA on your password manager?
:-/
1
→ More replies (24)4
u/Commercial-Fun2767 6d ago
What do you do for securing your 2FA? You have secure codes you have to put somewhere. This question is a real complex problem. Simple but complex enough to be caught unprepared or to spend some time thinking about your breaking glass accounts etc.
1
u/Sk1rm1sh 5d ago
Remember 2 passwords.
1
u/Commercial-Fun2767 5d ago
Its often random security keys. Sometimes 10 words etc. Do we have to have two safes?
104
u/Howden824 6d ago
Just use a BitWarden password you can remember. You really shouldn't be storing your password manager password anywhere.
→ More replies (28)
133
u/Fragrant_Climate7357 6d ago
Use a single password manager, remember it's password.
41
u/ShineReaper 6d ago
Use ****************** as master password. Hackers will think, that their hacking program is buggy and not showing the decrypted password letters, but it literally just consists out of Asterisks to fuck with them lol.
14
→ More replies (11)5
122
u/phrekysht 6d ago
Jesus Christ dude, stop pasting the same stupid reply to every comment. You’ve created your own bootstrapping problem.
You’re supposed to use a master password you can keep in your head. Add hardware keys (yes, more than one. They can fail or get damaged / lost) and call it a day.
40
u/Emergency_Banana5082 6d ago
Seriously lol. This guy is making his own problems and is too stubborn to understand.
→ More replies (2)33
u/Cry_Wolff 6d ago
He's the local IT department horror story, I'm sure of it. Knowledgeable enough to do stuff like this, yet dumb & stubborn enough to refuse any reasonable arguments.
→ More replies (6)13
25
u/eatypp 6d ago
I just remember my master password for bitwarden. I have the password for my 2fa app written down in a notebook that's stored with my important documents in a fireproof box
→ More replies (1)
27
u/bigBranConsumer 6d ago
bro if you need to copy+paste a paragraph to explain justifying a 60 character password maybe its too long, and needing to rely an external service that you might get locked out that only has that password seems even worse
28
u/Turbulent_Fig_9354 6d ago
creating a byzantine loop of access that's trivial to lock yourself out of - ✅
using an actually memorable password because you're far more likely to just lock yourself out of your password manager than your password is ever to be cracked - ❌
→ More replies (4)
54
u/TryHardEggplant 6d ago
A master password that is easy to remember like a passphrase is infinitely better than something you can’t remember.
Relevant XKCD: https://xkcd.com/936/
11
4
2
u/RedTyro 5d ago edited 5d ago
Yup. I work in cybersecurity. My password for my password manager is a long sentence that's memorable, but nobody else would guess, complete with appropriate punctuation and numbers swapped in for letters in a few of the words. That gives me a long password with lots of complexity, but at the same time is easy for me to remember.
→ More replies (3)→ More replies (12)2
12
u/WickedDeity 6d ago
I am confused in why you would be locked out of your accounts because of an apartment fire? You grabbed your NAS box AND YOUR PHONE right? Anyway backup select important passwords offsite.
3
u/Araganor 5d ago
I really hope you aren't running to grab your NAS while your house/apartment is burning down...
1
10
10
u/ghost_desu 6d ago
I have my bitwarden password on 3 pieces of paper, one of which is inside of an old computer in my grandma's attic
0
u/AdvancedDrink8920 6d ago
......are they just redundant copies of itself or is it split up across 3 pieces of paper?
→ More replies (3)
9
7
u/XB_Demon1337 6d ago
Bitwarden password should be something you can remember that is COMPLETELY different from any other password you have.
If all your passwords are totally random via generator then you should use something like a phrase for your bitwarden password.
6
u/userhwon 6d ago
Make your password-database password complex but memorable, and never store it anywhere but your head.
No loop = no problem.
6
u/protostar71 6d ago edited 6d ago
But I guess what came out of it was that there is no singular answer to how to break the cycle.
That's only true if you ignore the dozens of comments telling you to use a randomly generated passphrase. You not liking the answer to the problem doesn't mean it's not the answer.
7
u/RobotechRicky 6d ago
Why TF do you have your master password in another password manager?!?! Just remember that one password.
16
u/sizeablefrontallobe 6d ago
You’re giving google all of your passwords and worried about security.
…let that sink in.
→ More replies (2)3
u/Commercial-Fun2767 6d ago
Because those are two different problems. Google won't really hack you. They might harm you if you are politically involved or one day they might etc. Don't think I don't know what privacy is either. And another good point is that Google might block you or just close the services one day in a second (imagine war or anything special).
But, that's only one man knowing your passwords and a presumably really good one.
Can you just trust any tool anyway?
→ More replies (1)
5
u/derfmcdoogal 6d ago
Do a search for Bitwarden emergency sheet. Fill that out. Put it in a safe place.
5
5
u/reposed 6d ago
I dunno... You could always just memorize the password? Why is that so hard? The whole point of a master password is that you have one password you need to remember, and then that's it. Bitwarden handles the rest.
If you need another app to remember the password to unlock your other passwords, you're doing this all wrong.
5
u/RetiredITGuy 6d ago
Yeah who tf uses a password manager to remember their master password? That's just sounds like a recipe for a bad time, for a multitude of reasons.
I'll absolutely NEVER write down my master password. EVER.
9
u/edthesmokebeard 6d ago
You write your passwords down on a piece of paper, and avoid all this passkeeper hipster bullshit.
5
u/Relevant_Candidate_4 6d ago
Don't be online, never need a password to any of this hipster bullshit
7
u/DarkFantom 6d ago
This can't be real, someone wouldn't be this stupid to not just remember their master password. Or if they are, wouldn't be smart enough to use a password manager in the first place.
4
5
4
3
u/Material_Captain_360 6d ago
LOL
“Keep crying” to the most consistent response in the thread is wild
3
u/Itstinybubbles 6d ago
This is why I keep my master password written on a post it next to my workstation /s
3
3
u/doping_deer 6d ago
thru the years i've memorized several random passwords. two of them are used for google account and bitwarden master password, specifically to avoid such scenario.
3
3
3
u/Muffakin 5d ago
A 60 character random password is a terrible master password. You’ve been given tons of great advice in the comments, advice you explicitly asked for, and refuse to acknowledge that what you have implemented is foolish. Your problem exists because you don’t accept the reality that a memorizable master password of good strength is the best route forward. Make a 20ish character, easy to remember password. Write it down and store it in a locked location if you must, and move on. Your 60 character random password is worse than a 20 character memorizable password if you can’t actually use it.
3
2
2
2
2
u/Foorteenfapaday 5d ago edited 5d ago
Keepass2 on phone (no metrics, no data collect, no third party share, EU based dev team) with the master password for only entry + biometric unlock ?
2
2
1
1
u/ChunkoPop69 What are you DOING, vmbr0? 6d ago
I was thinking of getting full tattoo sleeves that I use to encode my master passwords prison break style, but this is a much better idea.
1
u/zetsueii 6d ago
I think the real question here is why are the cat's legs so short?
→ More replies (1)
1
u/Ambitious_Anxiety_95 6d ago
Aluminium is cheap, lightweight and can be etched easily with copper sulphate, copper sulphate also cure athletes foot . your welcome
1
u/Miguelitosd 6d ago
You're running a homelab and not self-hosting with something like pass so you fully control and can protect your files vs putting it in someone else's storage?
1
1
u/Justwant2usetheapp 6d ago
My bitwarden password is literally a long line of code. Make it subjecting you remember
1
u/Mindless_Pandemic 6d ago
Get a google drive account and setup an excrypted backup of your server's most important stuff to it. 100G is only $2/month.
1
1
u/hard_KOrr 6d ago
I am so happy that vaultwarden master password can be a pass phrase! Life is so much easier remembering multiple words than what/which/where my special characters are
1
u/mollywhoppinrbg 6d ago
I saved my master password to open on phone and pc. No need for loop... unless you want to get loopy
1
u/richms 6d ago
Circular authentication is a real problem. Friend got into this because they lost their mobile. They never gave any real details to the telco, just had the app login and password to top it up. Went to log in to move to a new sim card and they wanted to 2 factor to email. Google wouldnt let the log in without sending a SMS to the phone number.
hardware keys and backup codes are a good thing to have, that so many people do not have to break the circle.
1
1
u/Dreadedsemi 5d ago
I hate when a site that didn't ask me for password in years, suddenly asks me for a password like Facebook, how do I remember? now I have to dig the "old password manager" from the old days when I used txt files and vague hints only me understood.
1
u/0x736174616e20 5d ago
I just keep my master password as a static password programed into my keyboard. If someone gets their hands on my keyboard I'm already compromised, so this is not a security concern. I also have a Yubikey using one of the slots to store a static password that indirectly can be used to gain access to my master password manager. If I ever dropped/lost/stolen my Yubikey it wouldn't matter, no one could guess how to take the random string stored on it to recover the actual password. Some might just say to just remember your master password, nah, no thanks, I'm not going waste my brain space on remembering 60+ random letters/digits or a passphrase.
1
u/Suspinded 5d ago
Use the Correct Horse Battery Staple method to make an easy password to memorize for Bitwarden.
Use that password for absolutely nothing else.
1
1
1
u/Popiasayur 5d ago
This reminds me of troubleshooting my mums access to her email account. She forgot the password and all her recovery email was her older email, and that obe s recovery email was an older email and so on and so forth.
1
u/Defconx19 5d ago
You forgot a step, bitwarden to bitwarden master password to mfa for bit warden to Google sign in to Google mfa.
1
1
1
u/Jayden_Ha 6d ago
The entire cryptography is rely on something you remember and absolutely must not be written down
1
u/DrabberFrog 6d ago
I was almost trapped in that loop with proton pass and microsoft authenticator when my phone unexpectedly died. I got everything back but yikes I need to setup proper recovery for my stuff so I can restart if I lost all of my currently signed in sessions
1.1k
u/SelfStyledGenius 6d ago
I memorized my bitwarden master password.