[Cryptography] Of writing down passwords

Kent Borg kentborg at borg.org
Thu Sep 25 08:21:45 EDT 2014


On 09/24/2014 02:15 PM, Bill Stewart wrote:
> (Well, maybe a password manager running on a device that's not used 
> for anything else could be similar, like that old Palm Pilot that's 
> really going to stay air-gapped.)

I used to use a Palm Pilot, but they were getting rare and thus my unit 
being closer to being a single-point-of-failure, so I my current scheme 
includes an off-brand Android phone that I have never put a SIM card 
into (it has two slots, too!), have never let connect to the internet. I 
do let the phone occasionally be an isolated wireless access point that 
I ssh over to backup its encrypted data...

The phone was pretty cheap from geekbuying.com, supposedly even water 
resistant. And with nearly no software installed on it and all radios 
turned off the idle time is stunning. I try not to charge it above 90% 
(preserve battery life that way?), yet it seems I have a month of idle 
capacity, though I tend to charge it every week to ten-days.

The rest of my password scheme is less solid, but this end of it is 
pretty good. Too bad entering a decent key on a phone screen is such a pain.

-kb



More information about the cryptography mailing list