Secret Stash
Total Page:16
File Type:pdf, Size:1020Kb
FeATures KeePassX user credentials. Besides usernames and their corresponding passwords, KeePassX additionally stores URLs, no- tices, and file attachments in its data- base. It uses the AES or Twofish algo- rithms with a 256-bit key to secure the database. To install KeePassX, use the Ubuntu Synaptic package manager. See the box titled “Installation” for alternative ap- proaches to installing the software on your system. The program launcher is listed in the Applications | Accessories menu section. Clicking the icon launches Keeping passwords secure with KeePassX the password safe, which comes up with a three-panel main window and menu and taskbars at the top. © Daniel Sroga, 123RF.com Sroga, Daniel © To populate KeePassX, either import a database or create a new one yourself. SECRET Importing a database makes sense if you worked with the program’s predecessor, KeePass or if you already use KeePassX on another system. KeePassX will also STASH import the KWallet or PwManager data- bases. Populating the Keyring For optimum security, a password has to be too long and complex for To create a new database, begin by click- normal humans to remember. If you want to wield effective passwords ing on the New Database icon. This takes you to a dialog box in which the without hurting your brain, manage your online logins with the program prompts you for the initial pass- word for the database. Your password KeePassX password manager. BY JAN RÄHM should be long and secure (see the “Se- cure Passwords” box). ost users have no trouble re- around this issue by using the same Alternatively, you can protect the data- membering the password for password every time. Needless to say, base with a Key File. To do so, select a Mtheir web mailer, and they can this approach isn’t very secure. Once an file, or let KeePassX create it for you by usually remember how to access a fre- attacker has discovered a password com- checking the Key Pass box and clicking quently used online forum or web store. bination, other accounts are totally Generate Key File. If you only protect the But if you don’t visit a site very often, open. database with a key file, anybody who you might not remember the spontane- A password manager like KeePassX [1] possesses the key will be able to access ous password you typed in when you provides a solution to the password any data you store. joined the site. Some people work problem (Figure 1). KeePassX saves cre- A combination of a long and complex dentials in a se- password and a key file is your best bet, cure manner – no although this does make it difficult to matter how rarely recreate the passwords if you acciden- you visit a website tally delete or damage the key file and or how complex don’t have a backup. the password After choosing a key, press OK to con- combination firm and create the new, almost totally might be. empty database. In fact, the database The KeePassX only contains two empty groups at this password man- point. You can create a new entry by se- ager is a Linux lecting Entries | Add New Entry in the and Mac OS port menu or by pressing Ctrl+Y. The entries of the KeePass appear in a box top right. program [2]. Both A dialog box asks you for details of the projects aim to se- entry. The drop-down menu lets you as- Figure 1: KeePassX keeps track of your online passwords. cure and manage sign the entry to a group. KeePassX will 24 ISSUE 06 UBUNTU USER KeePassX Features Figure 2: KeePassX asks for information to Figure 3: KeePassX can generate a password Figure 4: The Auto-Type feature removes the add a new password entry. for you automatically. need for typing usernames and passwords. then ask you for a title, the username, box. This selects the window for auto- word, to supply the credentials. Just the matching URL, and the password matic input. Another click on Tools and make sure you don’t use a shortcut that (Figure 2). Or, you can create the pass- Auto-Type: Customize Sequence tells you have already assigned, or one that word automatically by pressing the Gen- KeePassX to add the Auto-Type: {USER- you use frequently in some other pro- erate button (Figure 3). NAME}{TAB}{PASSWORD}{ENTER} gram. After retyping the password, you can line to the comment field (Figure 4). Now, when you press the keyboard add a comment to the entry and even at- Then you then click OK to save the shortcut in your browser or program, tach a file if necessary. This feature entry. you can watch the fields for both the means that KeePassX can quickly en- The next step is to define a global key- username and password automatically crypt small files such as text or images. board shortcut for the Auto-Type func- fill, allowing you to log in without too tion. To do so, go to Settings and select much typing. Auto-Type Preferences Advanced. This dialog in- The Tools drop-down (bottom of Figure cludes a Global Auto-Type Shortcut text Conclusions 2) provides an option that will help you box. Click the box and then press your KeePassX patiently waits as an icon in configure the KeyPassX Auto-Type func- preferred keyboard shortcut. the system tray until you need it for tion. According to the documentation, After entering the shortcut, you can something. We didn’t hear a single word Auto-Type only works on Linux systems simply press the keyboard shortcut in a from KeePassX, apart from the request to right now. The feature reduces the need web browser, or any other program that authenticate against the database. for typing and lets you associate the prompts you for a username and pass- The KeePassX password manager login with a keyboard shortcut. The ad- makes logging into websites and applica- vantage of Auto-Type is that you are Secure Passwords tions safe and enjoyable – with no need never exposed to keyloggers. Secure passwords tend to be fairly long for distress over long and complex pass- To use the Auto-Type feature, open the and include a variety of different charac- words. website on which you want to log. Now ters. However, they also tend to be less An auto-login feature that didn’t re- toggle back to KeePassX and the open di- than intuitive, and that makes them easy quire a password shortcut keyboard alog box. Click Tools and Auto-Type: Se- to forget. Thankfully, there is a work- would be the icing on the cake, but the lect target window to open a window around for this. shortcut key is easy to manage now that with a drop-down menu containing mul- You will definitely want to avoid pass- all of my credentials are stored centrally tiple entries. words that contain dictionary words. and available for cross-platform use. n Clicking the entry copies the target One practical approach is to start with a sentence you are familiar with, write the window information to the comment sentence down, and create a string from INFO it by using the first letter of each word, [1] KeePassX project: Installation including upper- and lower-case charac- http://www.keepassx.org/ ters. Prebuilt installation packages for [2] Keepass: http://keepass.info/ KeePassX are available from the project Add non-standard characters and num- website for a variety of Linux flavors, bers at the beginning and end – and Apple Mac OS X, and Microsoft Win- other easily remembered locations in dows. You can download the source the middle of the sentence. The longer Science journalist Jan Rähm writes code for the software from the same your password is, the more secure it is articles and broadcasts shows on place. Also, you can use the Ubuntu and the more time an attacker will need Linux, IT, and technology. package manager to install the program. to brute force it. AUTHOR UBUNTU USER ISSUE 06 25.