Skip to main content
Home

Main navigation

  • Services
  • Accessibility
  • Partner Program
  • Blog
    • All Blog Posts
    • Ask Freelock
    • Dev Corner
    • Sustainable/Open Business
    • Off Topic
    • Newsletters
  • About
    • About Freelock
    • Meet the Team
    • Portfolio
    • Client Feedback
    • Typical Hosting Options
    • Invoice Payment
    • Advent 2025 - 24 days of accessibility
  • More ...
    • Topics
      • Reach
      • Engagement
      • Delivery
      • Security
      • Performance
      • Usability
    • Analytics
    • Support and Improvements
      • Drupal Development
      • WordPress
      • Migration
May 2014

How should I manage my passwords?

Heartbleed. The end of XP. Zero-day Internet Explorer attacks. April was a tough month for security on the Internet -- are the days of safe browsing over?

Probably not. But it is time to make sure you have good password management processes -- or learn how to do it if not.

Years ago I wrote about Smarter Password Management, and how to more easily create secure passwords. It's time for a brief update, as the environment has changed a bit.

Most of the recommendations in those posts are still quite valid -- the one important thing that has changed is it's really no longer safe to use the same password across a bunch of sites. Every day we hear about new sites that have had their password database compromised, and if an attacker can figure out your password on one site, they will almost certainly try it on others. So that means it's time for just about everyone to start using a password manager.

 

These days I use KeePass for my passwords, mainly because it's open source, completely free, and available for all my computers and phones. There are several variations of this, for each system:

  • Windows (the original)
  • KeePass for OSX
  • KeePassX for Linux
  • KeePassDroid for Android
  • iKeePass for IOS

Getting started

The first thing is to do just a touch of planning. You can see from the download page that there are two major versions of KeePass, a 1.x and a 2.x version, and the file format has changed. So first make sure that you get programs for each of your devices that share the same version.

I've been really happy with KeePassX on Linux, which uses the version 1 database format, and that's supported on my Android devices just fine.

Download and install to each of your devices.

Create a strong master password

Password managers keep track of all your passwords in a single encrypted file, which you need to decrypt whenever you want to use it. Your master password is used as a secret key to encrypt your password database, and without it, it can be virtually impossible to crack -- unless your master key is short and guessable.

My earlier post on Hard Passwords Made Easy has some very good tips on creating a memorable strong password. I still hear security professionals recommend my favorite approach after all these years: Diceware.

Import your passwords

KeePass has a number of ways of importing passwords from other formats. I was able to import directly from my previous password manager, but you can also load from a CSV file if you want to get organized in Excel. Be sure to delete your source files when you're done!

Save your database in a Sync directory

Now comes the glue that makes your passwords available wherever you are: save the password database into Dropbox or some other file sync service. Dropbox has software for all operating systems, and will automatically copy the password databases to all your other devices.

For mobile devices, be sure to mark the file as a "Favorite" so Dropbox keeps a copy up to date you can use even if you go offline.

You no longer have an excuse.

This will take you maybe 1/2 hour to get set up. Do it now. Once you have your master password, you can forget all the rest of your passwords, and simply copy in from your password database.

I particularly like how I can open up a web site, make sure the cursor is in the username field, find the entry in KeePassX, and use Ctrl-V to auto-type the username, password, and hit the login button. You don't even have to see the password -- it stays hidden the whole time, so you can even do this while doing a presentation in front of a group!

It will also generate strong passwords for you with a couple clicks.

Or, trust the world with your online life.

Think you're not a target for an attacker? You could always amuse the rest of us by becoming the next Internet experiment, like Woody Brown. He posted his passwords to a comment on the Washington Post web site to show how little security can matter. Sure enough, his Twitter, Facebook, and blogs all got taken over by pranksters. He does make a great point about this not really affecting him all that much -- but that's probably because he has not developed much of an online reputation that was worth anything.

If you have a business, your reputation counts -- more and more business comes from being online. If you're ever going to search for a job, any future employer is going to be looking at your online footprint for any warning signs. Being careless about Internet security might be fine if you do no online banking, never shop online, are at the end of your career, and are not trying to sell anything to anybody.

For the rest of us, it's time to start using a good password manager. Now.

Case Study

Max Dale's Steak and Chop House

Read More
Visit Site

As usual, lots of changes at Freelock. One thing that hasn't changed is our commitment to deliver the best results we can. One major part of that is getting very clear with our customers exactly what results we all want to achieve.

To faciliate that role, Rob Mathewson joined the team at the beginning of March. Odds are if you work with Freelock, or want to work with Freelock, you’ll be talking to Rob. With over 20 years in sales and marketing management roles, we think he’s more than qualified and we’re excited to have him on board!

Rob has managed numerous development projects in Ruby on Rails, Drupal and iOS. He's accustomed to commanding the role of customer advocate, ensuring that dev teams deliver clean, highly usable UX that meets user needs and exceeds product owner expectations. Rob is an accomplished public speaker and is a past president of Emerald City Toastmasters. Rob holds a B.S. in Manufacturing Engineering from Boston University and a MBA from Seattle University.

That's just the beginning, there's lots more in store. As always, if we can help with your web project in any way, please drop us a line or give us a call, we'd love to help your business or organization succeed!

David Dixit (not verified)

March 21, 2016

Any way to manage all your

Any way to manage all your passwords for online sites?

  • Reply

Add new comment

The content of this field is kept private and will not be shown publicly.

Filtered HTML

  • Web page addresses and email addresses turn into links automatically.
  • Allowed HTML tags: <a href hreflang> <em> <strong> <blockquote cite> <cite> <code> <ul type> <ol start type> <li> <dl> <dt> <dd> <h1> <h2 id> <h3 id> <h4 id> <h5 id> <p> <br> <img src alt height width>
  • Lines and paragraphs break automatically.

Drupal Canvas — Block HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href> <p> <br> <ul> <ol> <li>

Drupal Canvas — Inline HTML (locked)

  • Allowed HTML tags: <strong> <em> <u> <a href>

Recent Rants

Dark banner graphic showing "Drupal" and "matrix" connected by a line.
🕑Aug 31, 2026 🖋John Locke 💬0

Drupal Meets Matrix part 1: Setting up Matrix API

I've been maintaining the matrix_api module on Drupal.org since 2016, nearly a decade of it doing one thing well: posting Drupal events into a Matrix room. This year that changed.

dev corner icon
Dev Corner
software maintenance security patch vulnerability
🕑Aug 27, 2026 🖋John Locke 💬0

WordPress Has Thousands of Maintainers. Does Your Replacement?

Last month, a critical WordPress vulnerability triggered emergency patching across the web — and reignited a familiar argument: if WordPress keeps having security problems, why not let AI build something new instead?

It’s a reasonable question.

AI has made software dramatically cheaper and faster to create. But somebody still has to understand it, patch it, test it, and keep it running eighteen months from now.

That’s the part of the “AI instead of WordPress” pitch we think is getting overlooked.

sustainable business icon
Sustainable/Open Business
Drupal developer local environment setup tools
🕑Aug 01, 2026 🖋John Locke 💬0

Zero to new Drupal site in 133 seconds

Gabor asked in Slack about how people contributing to Drupal manage multiple different Drupal versions, and different contributed module branches, when using AI agents:

dev corner icon
Dev Corner
WordPress security vulnerability hacker cyberattack website
🕑Jul 21, 2026 🖋John Locke 💬1

We Patched wp2shell in 4 Hours. On a Friday Afternoon.

On July 17, WordPress shipped an emergency security release for a vulnerability chain now being called wp2shell.

sustainable business icon
Sustainable/Open Business
hacker cybersecurity website breach recovery
🕑Jul 09, 2026 🖋John Locke 💬0

Tempting Fate: What Happened When One of Our "Protected" Sites Got Hacked

A real client site got hacked and lost 35GB of files overnight. Here's how we diagnosed it, recovered in a few hours, and what we changed after.
sustainable business icon
Sustainable/Open Business
workshop board of old-school woodworking tools
🕑Jun 12, 2026 🖋John Locke 💬0

Against Inevitability

What Freelock is for, and what we're against
sustainable business icon
Sustainable/Open Business
fragmented data, multiple, coding agents, directory structure, context markers, documentation
🕑Jun 02, 2026 🖋John Locke 💬0

"Argo-nizing" Our Platform for AI Development

How grouping related repos into a single parent directory made AI coding assistants significantly more useful
dev corner icon
Dev Corner
Website management, Drupal, WordPress, security, automation, configuration management.
🕑May 28, 2026 🖋John Locke 💬0

Every Night, Argo Watches

While your site is running, things change. A content editor tweaks a configuration setting. A security vulnerability surfaces in a dependency. A production fix gets applied directly instead of going through the normal release process.

sustainable business icon
Sustainable/Open Business
Website security, data breaches, ransomware attacks, recovery solutions, cybersecurity practices
🕑May 19, 2026 🖋John Locke 💬0

Your Website Will Be Attacked. Here's How We Make Sure You Survive It.

The question used to be whether your website would face a serious security threat. That question has been answered. The question now is whether you'll be ready when it happens — and whether you can recover cleanly when something gets through.
sustainable business icon
Sustainable/Open Business
AI vulnerabilities, security incidents, resilience, Drupal WordPress, cybersecurity
🕑May 18, 2026 🖋John Locke 💬0

The Rules Have Changed: Security in the Age of AI-Assisted Attacks

Security is getting dramatically harder and more expensive. AI is simultaneously driving an explosion in vulnerability discovery and weaponizing the exploits that follow. The question for every organization with anything online is no longer whether to invest in resilience — it's whether that investment is already in place before the next incident arrives.
dev corner icon
Dev Corner

Footer

  • Contact
    • +1 206.577.0540
    • Sitemap
  • Freelock Blog
    • Ask Freelock
    • Dev Corner
    • Newsletters
    • Sustainable/Open Business
    • Topics
  • Services
    • Website Maintenance
  • About Us
    • Our Team
    • Client Feedback
    • Portfolio
  • Policies
    • Acceptable Use Policy
    • Copyright Infringement Policy
    • AI Use Policy
    • Privacy Policy
    • Security Statement
    • Standard Contract Terms

Contact

We are located in beautiful Seattle, WA.

 Freelock LLC
 PO Box 9625
 Seattle, WA 98109

User Menu

Social media

  • BlueSky
  • GitHub
  • LinkedIn
  • Mastodon
  • YouTube

1995-2026 Freelock LLC. Neonbyte theme by Dripyard.