This video belongs to the openHPI course Digital Identities. Do you want to see more?
An error occurred while loading the video player, or it takes a long time to initialize. You can try clearing your browser cache. Please try again later and contact the helpdesk if the problem persists.
Scroll to current position
- 00:00Now, let's have a closer look at tools which help to deal with
- 00:05secure passwords: the so-called Password Manager,
- 00:08in our openHPI course about Digital Identities.
- 00:13You remember secure passwords need to be long, need to be complex,
- 00:18difficult to remember. One
- 00:22needs a secure password, such a secure password is needed for each account,
- 00:28for each identity. And if you think about your own situation, how
- 00:33many internet accounts, how many internet services you are using,
- 00:38then most of the users have more than 20 such internet accounts and identities.
- 00:45So, you can't remember all the passwords because
- 00:50taking one password for several accounts, we
- 00:54argued already that this should not be done.
- 00:58So, one possible solution to deal with, and to remember such passwords is
- 01:03to use technical support, technical support that's provided by so/called
- 01:10Password Manager or Password Safe.
- 01:15These password managers or password safes are services in the
- 01:18internet, or programs for your computer that manages
- 01:23and encrypts all the passwords with a single strong password.
- 01:29To get to this tool you need one very strong single password
- 01:34and then later on the system supports you and creates complex passwords,
- 01:42stores this complex password - what is for us humans difficult.
- 01:46So, with a password manager, with one single password the password manager stores
- 01:53all our password inputs to services
- 01:59and it creates
- 02:02passwords which are long and strong - what is difficult for humans to do.
- 02:09This service also automatically enters the password
- 02:14on the right website, on the right web service. So, when
- 02:19one registers with the help of a password manager
- 02:23with a new service, at that moment of registering a new digital identity
- 02:28is created. In this identity, the password is an important part.
- 02:32The system helps to create a secure password, the system remembers
- 02:38that exactly for this service this password was valid. So,
- 02:43all this help is given by the tool
- 02:48and they are very valuable.
- 02:52Password managers exist in two variants: in an offline variant and
- 02:58in an online variant.
- 03:02In the last few years, such password managers have been integrated
- 03:07in browsers. So, let's start with an
- 03:13offline password manager, and here I already show you one system
- 03:18that could be used. The idea is to use such a system here, for example, "KeePass"
- 03:23or "1Password" and to store it locally
- 03:28on your device in an encrypted form.
- 03:33Advantages: No third-party is involved, no third-party has access to
- 03:39this password manager and in this way also not to the passwords.
- 03:44The disadvantage is that the data is stored only locally on the user's device.
- 03:50So, if you want to use this service, for example,
- 03:55you have it created and registered with on your laptop and if you
- 03:58want to use the service with your smartphone,
- 04:02it is not possible, without some
- 04:07installations it's not possible to access your accounts.
- 04:13So, synchronization is needed, so that also with other devices
- 04:20that you have, you can access the services.
- 04:25Another disadvantage is if the hardware has defected,
- 04:29for example, if your laptop
- 04:32is broken or if a theft happens,
- 04:35then of course also your password manager is gone
- 04:42away or is no longer working. So, it's very important to run
- 04:47backups regularly, to not come in a situation that you
- 04:54are no longer able to
- 04:56log into any of the services.
- 05:04Here the "KeePass" - I recommend, that's an open-source
- 05:11software that's used. So, people have checked it, have seen it and
- 05:15many people trust this system. There are also commercial solutions,
- 05:21"1Password" is such a commercial solution. So, there are different
- 05:28possibilities and offers for such offline
- 05:34password manager.
- 05:38Here I want to give you an example
- 05:41with KeePass. So, you have to set a master password when
- 05:46you create a new database with this KeePass,
- 05:50and this master password that needs to be really strong,
- 05:56because this is the only password you have to remember
- 06:01in future, when you start to work with such a password manager, in this case
- 06:07with KeePass. Here you get a number
- 06:11for the evaluation of the strongest of your master keywords (master passwords). You
- 06:17see with the colour code, whether you are more in the secure area or whether
- 06:23you are not in the secure area. The number of bits
- 06:27which result from the letters and characters you use,
- 06:33can be seen when you choose a strong password.
- 06:36Then you have this KeePass installed, you have your password
- 06:43and now you want to register with a new service.
- 06:47A strong password is needed for establishing a digital
- 06:52identity with this new service and this is done by the keyword manager (Password Manager),
- 06:59in this case by KeePass. So, you can see here the system once the
- 07:06account is created and then the password manager creates a
- 07:11strong password for you. You can choose what kind of characters the password
- 07:17contains and then you can say "Yes create the password".
- 07:22This was the registering and then when you go back later
- 07:27to the service, you need to write the password. Here KeePass is helping you
- 07:33in finding the right password for that service
- 07:37in its database. So, for example, here
- 07:42for an openHPI account.
- 07:47The idea was that this is a software installed on your computer.
- 07:52Such Password Managers also exist as online services.
- 07:58Here the functionality of such a Password Manager is offered
- 08:03as an online service. So, the advantage is, the passwords are synchronized
- 08:09and available for all your devices, without taking any activity.
- 08:14And if your system, if your computer is stolen or if something is broken,
- 08:21it is no problem as the data is available in this online Password Manager.
- 08:28But there is also the other side, the disadvantages.
- 08:32This depends on the provider, what you know about the
- 08:36availability of the provider: If the provider is not stable or if
- 08:41it's not available all the time, then you cannot access your accounts,
- 08:47you cannot access and use the services you want to.
- 08:51Another disadvantage is, how secure is it to store all this very sensible data
- 08:58with such an external service, because the service provider has access
- 09:05to all the data stored in this.
- 09:08So, often commercial providers, for example, "LastPass", "Dashlane", etc,
- 09:15there are a number of such providers and here is the recommendation: you should not
- 09:22use a cost-free service because there is a probability
- 09:28that in those services people work with the data. Use only commercial providers you trust.
- 09:35To mention that such password manager functionality
- 09:42is also available with recent browsers,
- 09:46here, I can show a few:
- 09:49if you work with Firefox or with the Chrome browser or Safari browser,
- 09:54often such browser vendors offer password managing functionality in the browser.
- 10:02Sometimes they even support you in checking
- 10:06with a password leak database, so to check if the password
- 10:11you want to use if it is already leaked or if your password is leaked and
- 10:16available in such a leak database.
- 10:20Typically this password manager functionality within browsers,
- 10:26this is in the category of an offline password manager because
- 10:32this data is stored in your browser, on your device.
- 10:37Typically they are offline password managers
- 10:43but with synchronization functionality, provided for example,
- 10:49via "Sync" in Firefox, with " Google Account"
- 10:53in Chrome, and with "iCloud Keyring" when
- 11:00you use the Safari browser.
- 11:02But beware the master password for protecting your passwords
- 11:06is activated by default, otherwise, the browser cannot access and work.
- 11:12So this is a disadvantage of this very convenient
- 11:18functionality, password manager
- 11:21functionality within the browser. So, access to passwords is easy
- 11:27when the browser is accessible, but then
- 11:31it is available for everyone, for example, everyone who gets access to the browser
- 11:36also gets access to the data,
- 11:40the password data stored there.
- 11:43So meanwhile all popular browser vendors
- 11:46offer such password managing
- 11:49functionalities in their browser. Here, for example, it looks in that way: (in the browser)
- 11:56"Would you like Firefox to save this login for openHPI.de?"
- 12:02This is what you're shown if you register and then you can
- 12:05save or you can say don't save, and in this way later on
- 12:11if you decided to save the password, automatically when you
- 12:15go to this page, this password is put in the log in form,
- 12:22and you can easily access without the need to remember the password.
- 12:27But the availability of the browser gives also other people the
- 12:34access to this password data. Here is another example, check
- 12:40with the password leak is possible, this also comes from the Firefox browser.
- 12:46Here for example, when you
- 12:52connect to the Facebook
- 12:55account then you see
- 12:58a warning - "Vulnerable Password", because meanwhile, the browser has checked
- 13:03some leaked data, like in our
- 13:08in our openHPI ID Leak checker. And then it warns you that you should
- 13:15definitely change this password.
- 13:17Let's summarize what we have learned about
- 13:20the password manager: Password manager in general offers multiple advantages.
- 13:29They can form complex passwords, they can automatically generate
- 13:33complex passwords that we can never
- 13:38remember, they can integrate the right passwords
- 13:43in the right service that we want to use - automatically. The password
- 13:50manager remembers which passwords belong to which service.
- 13:57We need to secure the access to the password
- 14:04manager. We can do this with multiple factors.
- 14:09In any case, what is very important is when we
- 14:13decide to work with such password managers, first is that we really
- 14:17create and remember a master password
- 14:21which is really secure, because this master password which opens the password manager,
- 14:27gives access to all the other passwords
- 14:31that are stored there.
- 14:34When unauthorised people
- 14:36get access then, of course, it's very dangerous because they can use
- 14:43all the functionality of the password manager, they can automatically access
- 14:48all the services of the person who owns the password manager.
- 14:55So, definitely, you need to have this master password and you
- 15:00have to secure this master password. Then there is a question:
- 15:05for what kind, what type of password
- 15:08manager do you decide? For an online service or for an
- 15:13offline service? Both have their advantages, both have their disadvantages,
- 15:19we discussed this in detail.
- 15:22The recommendation, in any case, is think about such a tool and
- 15:28we recommend you to use such a tool.
To enable the transcript, please select a language in the video player settings menu.