this post was submitted on 17 Feb 2026
10 points (85.7% liked)
cybersecurity
5915 readers
14 users here now
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Community Rules
- Be kind
- Limit promotional activities
- Non-cybersecurity posts should be redirected to other communities within infosec.pub.
Enjoy!
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
The prospect of putting all my passwords in one big juicy target has always made me nervous. I go to great lengths to just memorize everything, but damn if it doesn't take a toll.
I was the same way before, but you have to weigh the pros and cons of having proper, long, randomized, unique passwords for each site against the possibility that your database password might be compromised. I only have my password database locally, on removable drives.
So in order to access it, I have to plug in a USB drive (I have backups) which only happens for as long as I need the database, then I unplug it. I also use a keyfile, which is on separate drives, just in case. If anyone wants to access it, they'll need both the "something I know" (password) and "something I have" (keyfile) which is pretty unlikely.
Not advertising, but I use Keepass.
FWIW, I use Diceware for password generation; it's good at making memorable yet still random passphrases.