Thursday, January 26, 2012

Don't use unique passwords anymore, try KeePass 2


I use to manage my passwords in an excel file stored in an encrypted drive. Why write them? Because I manage like 20 username/password combination, plus credit/debit card PIN's, my Wife's and two suns Birthday..  a lot information to keep in my little brain :) . This approach  "protects" my data but its very very manual the process of updating passwords and entering them in each application/web site.  But after reading this post (and many other of course) about the dangerous of managing unique or common passwords, I decided to search a tool to make my life easier. 


I looked at KeePass 2, its an OpenSource tool that has many features. One great feature its the ability to automatically input username and password to the applications. There are two easy ways to do this:


1.- Select the application window.. then go to the keepass window, select the password entry and press "Ctrl + V".. yessss!!  like pasting any clipboard item. KeePass will input the data for you in the previous active window.


2.- For this option you need to know the application window name. You need to name the keepass entry like the application window. Once you are in the applicacion, just press hotkey "Ctrl + Alt + A" and keypass will look an entry with the same name as the application and paste the data for you.


Of course these two hotkeys can be changed for whatever keys combination you like. I use this tool with my mail accounts (hotmail, gmail), with my facebook and twitter accounts and with my Remote Desktop connections and applications.


What about security?  Well, the database its protected by an AES 256-bit encryption. This encryption is used by the NSA to protect TOP SECRET information, so you can be 99% sure that your data will be safe. To open the password database, you have three options to protect them (or all together): 


a) A master password
b) A key file that you can store in an USB or network
c) A windows user account


My recommendation?  Use almost two of them and do an effort to use the three to open the database, will be more difficult if some one tries to stole your passwords. 




The best of this great tool?  ITS FREE of charge!!  Try it and let me know other tips/features.