I recently tried out a decentralized private messaging tool, it didn’t ask for my personal information to register.

Instead, it only asked me to create a username and set a password, after which it provided me with a mnemonic passcode. (I had never used a mnemonic passcode before, but I learned that it’s a web3 or decentralized type of thing.)

On their FAQ page says “The Mnemonic Passcode is your ONLY SOURCE of backup in a scenario where your device breaks down or becomes unusable due to any reason. In such cases, all you need is your Mnemonic Phrase to recover all your account information. It must be copied, screen-shotted, or written down and kept in a safe and secret place until it is needed.”

Does Mnemonic Passcode more secure than usual password? Plus, is there any other ways to keep you mnemonic phrase?

  • æjinei@lemmy.world
    link
    fedilink
    English
    arrow-up
    32
    arrow-down
    2
    ·
    1 year ago

    I tend to add them to my password manager, which funnily enough also has a recovery phrase which I just keep written down somewhere safe.

    xkcd comic regarding your question of pass phrases vs passwords.

      • lnxtx@feddit.nl
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        They are generated on the server’s side, not by JS.

        Use with caution.

        • glibg10b@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 year ago

          Thanks, I’ll stop using it. I don’t want my passwords to end up in some wordlist

    • Campa@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      3
      ·
      1 year ago

      Lmao, aren’t you doing the same thing for another round? But password manager do makes everything easier, I wonder is it decentralized as well? Cuz if it have a central server to keep all user’s passwords, it might not be safe tho.

      • 7Sea_Sailor@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        13
        ·
        1 year ago

        Classic password managers are not decentralized, and why would they be? If you’re worried about storing your credentials on one central server (the official one), there are plenty of very good options for selfhosting a password manager on your own infrastructure. I will always point out the Vaultwarden project, an implementation of the Bitwarden API thats very efficient on ressources and works near flawlessly with all apps and extensions. A wonderful addition to your homelab or VPS.

        • c1177johuk@lemmy.world
          link
          fedilink
          English
          arrow-up
          9
          ·
          1 year ago

          I can’t recommend KeepassXC enough. And it’s not even hosted either, it’s a simple keepassxc database file. Sharing it across devices is done using any file server or service you want to use.

          • kill_dash_nine@lemm.ee
            link
            fedilink
            English
            arrow-up
            1
            ·
            1 year ago

            After having gone to solutions that allow for simple and seamless password sharing between users, it’s hard for me to go back. Last I checked, none of the Keepass solutions could really seamlessly share passwords and have them update in some fashion without manual user intervention. That being said, I used it for a long time in my Dropbox and then Own/Nextcloud before moving to a password service, Lastpass and then Vaultwarden after the Lastpass security fumbles.

      • d3Xt3r@lemmy.world
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        Instead of * warden, just use the tried and trusted KeePass, no need to run your own server. KeePassXC is a nice open-source alternative client, and KeePassDX is it’s Android equivalent. You can keep your password file in sync with other devices by using your favorite cloud backup or sync tool. The best part is, KeePass supports auto-type, which *warden and other cloud-based password managers don’t. Auto-type is handy when you want to input your password into a program that’s not a web page, or you’re accessing something via remote desktop etc.

    • Haui@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      This exact comic was what led me to change my whole password philosophy. Since then, I have hundreds of easy to memorize but insanely long passwords. I love that comic.

      • Taringano@lemm.ee
        link
        fedilink
        English
        arrow-up
        2
        ·
        1 year ago

        I wish I could do that it every place apparently feels the need to invent a new requirement for password composition.

        1 symbol, then 2 symbols, then at least 2 numbers, then can’t have some “easy to guess words” in the middle (like wtf?) or require maximum of 12 characters. It’s so frustrating. It’s impossible to have a easy to remember passwords because all of them have to be slightly different depending on the case.

        And what pisses me off the most is they don’t tell me when I am. Authenticating “remember this one’s needs 2 symbols and at least 10 characters” or whatever.

        Sorry I get really worked up. About this.

        And the worst part is the least important the service the more requirements it has.

        • Haui@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          2
          ·
          1 year ago

          Yes, tell me about it! The fact that services just do not tell you their requirement sometimes really sucks. I mean, if you cant do easy and you have a vault then you can go generated for those sites and done. I do have some site specific passwords too but mostly they’re easy to remember and insanely long.

    • chicken@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      It might be good enough for web passwords, but coming up with your own mnemonics is not truly secure because there are discoverable patterns in anything people come up with themselves, it isn’t actually random. If you order words in such a way to make it easier for you to remember it also makes it easier to bruteforce. Lots of crypto wallets where people tried to do this were remotely drained.

      Doing this is only safe if the words are selected with secure RNG of some kind.