• nilzen@lemmy.world
    link
    fedilink
    arrow-up
    8
    ·
    5 hours ago

    I have an aexcel sheet like this. it is a decoy. has about 100 legit looking passwords, none of which are real.

  • MidsizedSedan@lemmy.world
    link
    fedilink
    arrow-up
    12
    ·
    9 hours ago

    I work at a school. I have access to a label maker. I put “NewPasswd = hunter2” on the inside of my work laptop because Im immature. Caught 2 people trying to login with it. (worst part is only 1 was a student…)

  • PillowD@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    10 hours ago

    If you’re relying on Excels password, the cops can submit your xlsx file and a subpoena to MS and they will open it for them.

  • grandel@lemmy.ml
    link
    fedilink
    arrow-up
    5
    ·
    15 hours ago

    I’ll just write my password (which is the same for all my accounts) on a post-it and stick it to the monitor then.

    • purplemonkeymad@programming.dev
      link
      fedilink
      arrow-up
      2
      ·
      5 hours ago

      You mean you don’t write it on a piece of paper then place it in a room that is barricaded from the inside, but still accessible by a securius route through the building filled with environmental puzzles and enemies? The barricade should also be convenient to move from inside the room for fast return to your computer.

    • Dozzi92@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      11 hours ago

      Are you my mom? Are you going to call me when that post-it note disappears and ask me if, for some reason, I know what your password is?

    • hansolo@lemmy.today
      link
      fedilink
      arrow-up
      3
      ·
      11 hours ago

      I knew a guy that stored business login credentials in a Google sheet. Black text on black background was what made it “secure.” Because you have to know that they’re credentials and click on the field.

    • brewery@lemmy.world
      link
      fedilink
      arrow-up
      3
      ·
      12 hours ago

      Worked in the UK for one of the largest Japanese multinationals. Our team required several government accounts with different passwords. I asked IT what are my options and they said we have none, and that their team used a text file on a shared drive so I did it on Excel instead to make to make it more searchable. If they’re not willing to let you install keepass or buy any software, what can you do!

    • possessedfaxmachine@lemmy.world
      link
      fedilink
      arrow-up
      8
      ·
      17 hours ago

      In Japan, we use Excel for storing passwords. Creating technical manuals. Or make presentations that would do better in PowerPoint. Database you say? Yes, also!

      • AceOnTrack@lemmy.blahaj.zone
        link
        fedilink
        arrow-up
        12
        arrow-down
        18
        ·
        22 hours ago

        People aren’t lazy, we just don’t give a shit about cybersecurity, it’s not as big of a deal as IT makes it.

        I use an Excel worksheet for my passwords.

        At my workplace, I need to use a dozen different webapps/VMs, some of them only like once every 2 months.

        For some reason, each fucking app requires different password combinations with different rules, and their all have different password change times.

        I ain’t remembering all that.

        I used to keep a notepad with all my passwords in my desk drawer but I occasionally remote login on my machine nowadays, so I have a passwords.xls file on my desk. It’s even got some formulas that warns me when one is about to expire and needs to be changed, I put some effort into it.

        • Godnroc@lemmy.world
          link
          fedilink
          English
          arrow-up
          21
          arrow-down
          3
          ·
          20 hours ago

          And I’m sure the person who steals that file will really appreciate the effort you put in.

          I’ve literally searched networks for files with the word “password” in the title to find documents just… sitting on a network drive anyone could access.

          At the very least, go get KeePass! It’s free, can run without installation, and can even type for you.

        • baines@lemmy.cafe
          link
          fedilink
          English
          arrow-up
          8
          ·
          20 hours ago

          savages?

          real men use a plain text fill named notmypasswords to throw off hackers

        • wonderingwanderer@sopuli.xyz
          link
          fedilink
          arrow-up
          4
          arrow-down
          2
          ·
          18 hours ago

          Dude just get keepassXC… it literally creates an encrypted vault for your passwords and it’s all stored entirely locally on your device.

          The only potential inconvenience might be that it doesn’t integrate with browser/apps as far as I know, but you can copy/paste from it and it can even generate random strings for you to use when creating new passwords.

          Literally just one password to remember, to open the vault, and all the rest can be stored securely. Two passwords if you use a different one for your desktop login, but that’s still manageable.

            • Zarobi@aussie.zone
              link
              fedilink
              English
              arrow-up
              2
              ·
              13 hours ago

              Yeah, some company I.T. policies ban password managers, which is extremely dumb… But also like, what’s there to do about it? Not my decision and we still gotta work.

              I think I remember at some point putting my passwords inside an encrypted 7zip archive that itself had a password. No idea how secure that truly was, but it made me feel better.

              • helpImTrappedOnline@lemmy.world
                link
                fedilink
                arrow-up
                3
                ·
                12 hours ago

                They might allow the browser’s built in manager. Good chance if they’re a Microsoft shill, edge’s built in would be better than nothing…although it’s Microsoft so a text file might be better.

                IT probably bans them because they can’t access the data. Keepass files are some kind of container, you can store any file with in it. Great when you want save a txt doc with 2fa recovery codes or something and also not a bad way to send a payload that’s impossible to scan. “I’m going on vacation, please use this keypass file for vendor XYZ, open the file within for the vendors contact info”.

    • Prox@lemmy.world
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      1 day ago

      The kind of savage whose company is too cheap for a LastPass enterprise license?

  • Apathy Tree@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    20
    ·
    23 hours ago

    I used to work at a company that processed business-end taxes.

    I’m going to make my American compatriots very uncomfortable - I’ve very possibly seen your full social and address info. We handled about a third of all business taxes. I don’t care to use any of it, cuz I also got wage info. Y’all broke. (Same)

    because the company I worked for processed your taxes. And your HR people are garbage and don’t know how to do their job.

    I cannot tell you how many times I had to request my IT team to scrub files from our retention policy because your shitty HR sent it to me in cleartext to troubleshoot instead of through our encrypted box.

    • MeatPilot@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      21 hours ago

      Well my company HR was so dumb I used to be able to look up everyone’s personal information and income because they tried using Salesforce to store employee data but didn’t know how permissions worked.

      As one of the lower paid employees according to that info. It was not my problem. I don’t work in IT and didn’t get hired for my technical experience, so I offer none.

  • OwOarchist@pawb.social
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    17 hours ago

    Make sure to store it in a cloud-synced folder

    No need to remind people of that. Microslop will manage to get it on their cloud one way or another. Just need a few more dark patterns. Maybe have an update silently change the ‘Ctrl + S’ shortcut to be ‘save to OneDrive’ instead of just ‘save’.

  • HyperaGel@lemy.lol
    link
    fedilink
    English
    arrow-up
    6
    ·
    18 hours ago

    Bitwarden exported my passwords to a spreadsheet file when i decided to mitigate away from it.

    So for it has been my go-to with libreoffice until i find a better solution 😅