Keychain password different from login password

I've gotten mixed feedback on this: What additional security, if any, is obtained by making your keychain password different from your login password?

I concede that if:
- any shoulder-lookers/keyloggers have equal access to the login and keychain passwords
- the login password isn't being used for anything else
- the login password isn't being stored in some other insecure location (maybe in a script for use in a sudo command)
- you're not using ftp/some other protocol w/insecure logins to connect to that computer and get data
then there is no reason to have separate login and keychain passwords.
But what I'm saying is that there are lots of little things (like those I mentioned above) that can be security holes that one simply doesn't think about. A user who is truly concerned about security may wish to simply have two separate passwords, thereby avoiding many (not all) potential insecurities.
ddr

Similar Messages

  • Keychain pw different than login pw

    Okay, so out of the blue, my keychains have decided to sputter...
    I have a few of them I use for various things, and those are fine. I had 1 login keychain that I changed the password to, but when I went to login to ichat shortly thereafter, I put in the new password and nothing doing. Old password, still nothing. I got it to reset and was able to import the others, but now I have:
    1 new login keychain
    1 "loginrenamed1" keychain
    The latter of which I'm being prompted for continuously, and neither the old nor new password works. To avoid huge headaches, I changed the default keychain to the new login keychain, but my old stuff is still in renamed_1. Stranger yet, it appears I can write to renamed_1 but not access it.
    I'd like to just move all those old passwords to the new login keychain, but without the renamed_1 access, that's hard.
    Any ideas? How could I do the password sync thing now?

    Try this:
    Assuming that you are using a recent build of OS X, go to /Applications/Utilities and launch the app called Keychain Access. Go to the Window pulldown menu and select "Keychain First Aid". Enter your password, set the radio button to "Repair", and click "Start".
    If the above does not resolve the problem, then you may try the following:
    Tutorial: Keychain issues; resolving
    If you can't access your keychain, or forget your password If you can't get into your keychain file because you've forgotten your password or the keychain file appears to be corrupt, there are a couple of options.
    First, if you've forgotten your password, you can use the "Keychain First Aid" utility to make the keychain password the same as the login password.
    This can be accomplished via the following process:
    Open Keychain Access (located in Applications/Utilities
    Go to the "Keychain Access" menu and select "Preferences"
    Click the "First Aid" tab
    Make sure the "Synchronize login keychain password" box is checked
    Close the Preferences window
    Go to the "Keychain Access" menu and select "Keychain First Aid"
    Enter your username and password
    Click the "Repair" button
    Another option is to completely delete your keychain then recreate it. This routine is useful if your keychain appears to be corrupt or otherwise inaccessible.
    This can be accomplished as follows:
    Launch Keychain Access (located in Applications/Utilities)
    Click "Show Keychains" in the lower-left corner of the window.
    Select the problematic keychain from the left-hand pane.
    Navigate to the "File" menu and select "Delete Keychain '(name of keychain)'"
    Check all options for deletion and press "OK"
    Create a new keychain by going to the "File" menu, then "New" and selecting "New Keychain"
    You can now make this keychain your default if you desire by selecting it, then going to the "File" menu and selecting "Make '(name of keychain)' Default"
    Login as root and perform repair In some cases, problems with keychains can only be resolved when logged in as the root user.
    First, enable root user.
    After enabling the root user, and logging in under this account, again open Keychain Access. First attempt repairs using Keychain First Aid, and failing that, delete then recreate the keychain as described above while logged in as root.
    Persistently asked for stored passwords If you are persistently asked for passwords in various applications that you have specified should be remembered in a keychain, your "login" keychain may not be active for one reason or another.
    Navigate to ~/Library/Keychains/ (this is the Library folder inside your user home folder). Find the file named "login.keychain" and double-click it.
    Failing that, select the "login" keychain within the Keychain Access application and make sure it is the default keychain by going to the "File" menu and selecting "Make 'Login' Default"
    Turn off Keychain synchronization in applications having problems If specific applications are experiencing issues when accessing password-protected material, Keychain may be to blame.
    For example, it appears that in some cases, failures in .Mac synchronization transfers are linked to issues with Keychain.
    If you are having problems synchronizing data with .Mac servers, you may want to try the following process:
    Open System Preferences and access the .Mac pane
    Click the "Sync" tab
    Uncheck the "Synchronize with .Mac" checkbox
    Close System Preferences
    Re-open System Preferences and repeat steps 1 and 2
    Re-check the "Synchronize with .Mac" checkbox
    If the above process does not re-allow synchronization, you may need to leave Keychain synchronization turned off in the "Sync" tab of the .Mac System Preferences pane.
    The above comes from an article published on MacFixit.com.

  • Password email different from login

    Do I understand that the Mac OS X stores only one password per user for OS login and email.
    That is the password for the user to login to the machine and the password for email access are one in the same?
    thanks
    ben

    Sorry let me try to be more clear.
    Server mountain lion mac_mini
    create a new user account
    I want to have password1 for the user password and password2 for their email account.
    Can this be done?
    ben

  • I just upgraded to Lion. I was trying to set up the iCloud and it asked for my "login" keychain password. I've never been asked for that before. I've tried every password I can think of and nothing works. Is there a way to reset the keychain password?

    I just upgraded to Lion. I was trying to set up iCloud and it asked for my "login" keychain password. I've never been asked for the keychain password before. I've tried every password I can think of and nothing works. I'm normally asked for the password to my machine when upgrading software, signing on, etc. but this is different apparently. I tried the same password and it didn't work either. I read a couple of posts and they all want to take me through Applications/Utilities but that requires knowing your password in order to change it. I don't know it. Don't remember ever setting up a keychain password. Does anyone know how to change the keychain password if you don't know the keychain password???

    Most of the time your Keychain password is the same as your login password. If you configured your computer to log you in automatically, you may not have used your login password in so long you forgot it.
    There is no way to retrieve the "login" Keychain password, but you can reset the Keychain from the Preferences menu: select it in the Keychain Access menu and select "Reset My Default Keychain". This will create a new, empty Keychain but the old one will be saved should you ever remember its password.
    The result of this is that you will have to supply passwords for everything that requires it, since without your Keychain they will no longer automatically fill themselves. However, once you supply them and store them in your new Keychain, they will be remembered.

  • LOGIN keychain password forgoten

    Hello_
    I bought a mac mini for a in-laws a few months ago and somehow they made their LOGIN KEYCHAIN password different from their admin and system password and then forgot what it was.
    I tried to reset it by starting up from the OS disc and reseting the admin password but it wouldn't take without knowing the current keychain password. It also won't seem to let me delete the Login Keychain and start over... without it, the machine will not remember any email or web login passwords, so they are always being prompted by the keychain, it bugs them, then they call and bug me... HELP!
    Thanks.
    Michael
    www.michaelditullo.com

    Hi,
    Have they tried changing their password via System Preferences -> Accounts?
    That should reset the keychain password to the same one as their account.
    Also, have they tried running Keychain First Aid? It's under the Keychain main menu at the top of the screen.
    It also won't seem to let me delete the Login Keychain and start over...
    Do you mean that deleting this file has no effect?
    /Users/YourUsername/Library/Keychains/login.keychain

  • Keychain password request on login

    When I log in (admin account) I am asked for my keychain password. I'm not sure why?
    When I enter my password (my login password) I am told that iti is invalid. I looked in the Help (a bit!) and it said the keychain password was the same as the Login password. If that's not the case, which password would it be as I haven't set any others up. Have I??
    iBook 1.42Ghz   Mac OS X (10.4.3)  

    Your keychain password is usually the same as your login password, but it doesn't have to be. You can manually set the keychain password to be different, or in some situations it can become "out of sync".
    Have you perhaps had to reset your password by booting from the install CD? Or have you logged in to another admin account and then used Sys.Prefs to change the password of the account that now has the problem?
    In either of the above cases the login password will be changed but the keychain password will not. In those cases the keychain password will still be the original password it had before the change. So you might try using a previous password when prompted by the keychain to see if it works.
    If you can discover the keychain password, then you can use Keychain Access to change it's password to match your login password. Then it will unlock automatically when you login and you'll stop getting prompted.
    I suppose it's also possible that the keychain password may have become corrupt in some way. If this is the case you may be out of luck.
    If you can't get the keychain unlocked after attempting any previous passwords, then you'll likely have to simply delete the keychain and let the system create a new one (which will be created with your login password).
    In your home folder, go to ~/Library/Keychains and drag "login.keychain" out of the folder. Then logoff and log back in. This should create a new empty keychain for you and it should be "in sync" with your login password.
    Steve

  • I logged onto my MacBook Air and it is asking me for my "local items" keychain password for several different things. I do not know what this is or how to get rid of it. Please help. Thanks.

    I logged onto my MacBook Air and it is asking me for my "local items" keychain password for several different things. I do not know what this is or how to get rid of it. Please help. Thanks.

    There are several possible causes for this issue. Please take each of the following steps that you haven't already tried, testing after each one, until it's resolved. Back up all data before making any changes.
    Step 1
    Follow the directions in this support article.
    Step 2
    Open the iCloud preference pane and uncheck the Keychain box. You'll be prompted to delete the local iCloud keychain. Confirm. Then re-check the box. Follow one of the procedures described in this support article to set up iCloud Keychain on an additional device.
    Step 3
    Open the Keychains folder as in Step 1. There should be a file in that folder with the name "login.keychain". If there is also a file iwith the name "login_renamed_1.keychain", then please do as follows:
    Rename login.keychain to "login-old.keychain".
    Rename login_renamed_1.keychain to "login.keychain".
    You can then close the folder.
    Launch the Keychain Access application in any of the following ways:
    ☞ Enter the first few letters of its name into a Spotlight search. Select it in the results (it should be at the top.)
    ☞ In the Finder, select Go ▹ Utilities from the menu bar, or press the key combination shift-command-U. The application is in the folder that opens.
    ☞ Open LaunchPad. Click Utilities, then Keychain Access in the icon grid.
    Delete the login keychain from the keychain list. Choose Delete References when prompted, not Delete References & Files.
    Select
    File ▹ Add Keychain...
    from the menu bar. Add back the file now named "login.keychain". If any of your needed keychain items are missing from it, also add back the file now named "login-old.keychain". I suggest you transfer any needed items from that keychain to the login keychain, then delete it. The transfers are made by drag-and-drop in Keychain Access. You'll need to enter your password for each item transferred.
    Select
    Keychain Access ▹ Keychain First Aid
    from the menu bar and repair the keychain. Quit Keychain Access.

  • HT1554 Apparently, I don't know my "com.apple.smig keychain" password. And I'm in the middle of setting up my new Mac mini. I transferred data from my MacBook and what I thought was the password isn't working! Help!!

    Apparently, I don't know my "com.apple.smig keychain" password. And I'm in the middle of setting up my new Mac mini. I transferred data from my MacBook and what I thought was the password isn't working! Help!!

    Hello,
    See if this helps...
    Mac OS X 10.4 Help, I forgot a password in my Keychain
    http://docs.info.apple.com/article.html?path=Mac/10.4/en/mh1960.html
    Mac OS X 10.4: Keychain Access asks for keychain "login" after changing login password...
    http://support.apple.com/kb/HT1631
    Resetting your keychain in Mac OS X...
    If Keychain First Aid finds an issue that it cannot repair, or if you do not know your keychain password, you may need to reset your keychain.
    http://support.apple.com/kb/TS1544

  • Unable to type in the "login" keychain password

    When I switch on my iMac G5 I am asked for my keychain password: but I can't type in the space provided. I can still use the computer normally, e-mail, internet etc. are all unaffected but the pop-up box asking for the keychain password won't go away, (and won't allow me to type in the password).
    The message I get is, "com.apple.internetaccounts.xpc wants to use the "login" keychain"

    Only thing that got me around this was a clean install of Mavericks on the new Mac and , when I used migration assistant, avoiding transferring the network settings. It was my mother in law's Mac so I essentially only transferred her documents and mail messages. I then went back later and manually transferred the music and photos. I ' knew' there was some issue with the OS itself because I had tried to clone the old system with Super Duper as an extra back up and even that balked with an error. Shrit Pocket Supprt read the error file and it was they who divined that that my "old" copy of OSX was corrupted. Plus I was umm more familiar with this scenario as this was the second Mac that I was having this issue with. Admittedly both the upgrades in question were from Macs that had been transferred and transferred and transferred etc so I am not surprised that there was something crappy that had got passed through. Bottom line: clean install of Mavericks then manually move over what you need is the cleanest way in this scenario unfortunately. Yes a whole lotta work!

  • Choose a password that is different from your last 5 passwords

    Hi Experts
    "Choose a password that is different from your last 5 passwords."
    I want to take this setting off. So that you can use the same password every time.
    What I have done is:       -Transaction - rz10
                                           -Change the following parameter "login/password_history_size =  0"
                                           -stop and start the SAP system.
    Are there any other settings that I must change?
    Thanks

    This is not possible.
    The password may not be changed to any of a useru2019s last five passwords, if the user changes the password himself or herself.
    The administrator can reset a useru2019s password to any password, even to one of the last five passwords of this user. This is necessary, since the administrator should not know the passwords of the users. The user is prompted to change the password at the first interactive logon.
    Regards,
    Pavan

  • When I boot up i keep getting requests for keychain password, about 6 different things asking for it before i can get to desktop, HELP !!!!!

    When I boot up I keep getting requests for keychain password from various things ive never heard of like cloudd
    Like this basically
    Any ideas how i stop this
    Pete

    Hi Lutonpete,
    Welcome to the Apple Support Communities!
    I understand that you are receiving repeated prompts for different “Local Items” keychain passwords and know how frustrating this situation can be. There is a solution to this issue however. Please use the steps and information in the attached article to resolve this issue. 
    OS X Mavericks v10.9.1: Repeated prompts to unlock "Local Items" keychain - Apple Support
    Cheers,
    Joe

  • Why does it keep asking me for the login keychain password?

    I am having a problem where my imac keeps asking me for a "login keychain" password. I type in my password every time, but that doesn't fix my problem. I need to know if this is bad or not, and how i can turn it off.
    Thanks!

    Hey there Daniel,
    It sounds like you are being prompted over and over for your Login Keychain, and entering it does not seem to make the prompts stop. I would start by running First Aid on the Keychain with this article:
    Mac OS X 10.6: Solving problems with keychains
    http://support.apple.com/kb/ph7296
    To check keychains for problems using Keychain First Aid:
    Open Keychain Access, located in the Utilites folder in the Applications folder.
    Choose Keychain Access > Keychain First Aid.
    Enter your user name and password.
    Select Verify and click Start. Any problems found will be displayed.
    If there are problems, select Repair, and then click Start.
    If that does not resolve the issue, I would next reset your Keychain:
    In Keychain Access, choose Preferences from the Keychain Access menu.
    If available, click the Reset My Default Keychain button. This will remove the login keychain and create a new one with the password provided.
    If Reset My Default Keychain is not available, choose Keychain List from the Edit menu.
    Delete the "login" keychain.
    The next time you log in to the account, you can save your current password in a keychain.
    From: OS X: Keychain Access asks for keychain "login" after changing login           password
              http://support.apple.com/kb/ht1631
    Thank you for using Apple Support Communities.
    All the very best,
    Sterling

  • After restoring iPhone 4S, Login password and Keychain password not working!!

    Hey!
    So last night my Girlfriend restored her iPhone 4S running iOS 7 as new to fix a battery issue she was experiencing. Before doing this she went through and backed up her photos using iPhoto. She then restored the iPhone as new and when it had completed attempted to login to the mac as it had locked itself due to inactivity. Unfortunately she wasn't able to login and waited until I got home so I could try the password.. When I did get home I tried to login using the password but it didn't work. At that point I realised something had gone wrong so I tried all of my other passwords I had previously used with the mac as well as my Apple ID. None of them worked. At this point I booted to the Recovery 10.8.2 Partition and reset the password using the Password Reset Utility.
    I then logged in and attempted to update the Keychain Password (This was the default "Login" keychain so it should be the same password as the Users password.). It didn't accept it so I went through and created a new Keychain to test if Keychain Access Application was working. It accepted the new keychain and I could operate the Application as if nothing was wrong (There was something wrong though, all of my passwords for many websites were stored in this keychain). I then removed the reference to the keychain and moved the keychain file from ~/Keychain folder to the desktop. I then reimported the Keychain and it still did not accept the password.
    I called AppleCare to get a second opinion and spoke with a Senior Advisor who told me to just start a new one. I don't mind starting a new Keychain as I know the passwords for the main websites I browse, HOWEVER, I'd like to see if anyone knows what may have happened so I can perhaps prevent this from happening again.
    Thanks in advance,
    Nathan Freeman

    Tlix!
    Thanks for the reply! Yeah, I'm quite aware that the restore of an iPhone should not have impacted the login password/keychain password. This thought has been further concreted after consulting a few of my Apple Fanboy buddies who are fairly experienced in troubleshooting issues relating to Mac computers. In regards to try a blank password, I've actually had the exact same thought and will be trying this tonight. I'll be sure to post the results of this to let you know what happens.
    Unfortunately I haven't gotten round to making a TM backup of my device, primarily due to my current lack of an external HDD.
    Thanks,
    Nathan Freeman

  • Keychain showing different character for the password

    Hi just wanted to ask why my keychain is showing different character for my password in my AIM and Yahoo account? When i mark the show password its show plenty of letters but not the one i am really using. How can i show the right one?

    Hi Irvin,
    If you see a crazy corrupt password, I'd delete that item, ythen login yo AIM or Yahoo again to create a new one, unless you don't remember your PW, then try Keychain First Aid under the Window Menu item, then either check the Password under that item, change it, or delete it and start over.
    Resetting your keychain in Mac OS X...
    If Keychain First Aid finds an issue that it cannot repair, or if you do not know your keychain password, you may need to reset your keychain.
    http://support.apple.com/kb/TS1544

  • Is there a way to reset keychain passwords from server.app?

    We have a Lion server and a number of Macs that authenticate with the server through open directory. On occasion users have forgotten passwords, and so I've reset them from server.app. I've tried both getting them to enter their password on the server, or setting their password to "password" with reset at next login set, but both methods result in an issue whenever the user logs in where they're prompted to create a new keychain or use their old one (which is not possible because they have forgotten the password to unlock it). This is frustrating for me and users.
    Am I doing something wrong, or is this how it is supposed to work? It'd be a real pity if the latter was true, and would go against the idea that "it just works" on the Mac.

    That's the way it works. Due to the nature of a Keychain, and what is potentially stored in it, once a password is forgotten you need to use a new Keychain and all data within is "lost". If there were a way to reset the Keychain password then you can grab anyone's Keychain, insert it into another account and then use the reset password to get all of the data out of it… at which point there's little point to password protecting it at all.

Maybe you are looking for

  • How can I disable animated tab effects in Firefox 19.0?

    I updated Firefox a few days ago from 18.0.2 to 19.0 and now see that the tabs slide around when I drag to rearrange them or try to ppostion a tab over a bookmarks toolbar folder for bookmarking. The tab being dragged also gets transparent although I

  • Laptop mode tools problem with kernel 3.0

    today I just updated the system and my laptop runs dramatically hotter after that. I read the archwiki, it does talk about the laptop mode tools problem with kernel 3.0 but when I opened the file /usr/sbin/laptop_mode, the lines which the wiki mentio

  • ORA-27300 during night hours, restart database needed

    Hi, Last year we upgraded a small database system on several systems from Oracle 8.0.6 to Oracle XE. We installed XE, dropped the XE database and created a new one with standard scripts. (We didn't need APEX) Next we imported the data of the old data

  • Runtime Errors CONNE_IMPORT_CONVERSION_ERROR

    Error in IMPORT statement: Change of length on conversion. Hi this is an error i had when creating a source system for a client. Runtime Errors CONNE_IMPORT_CONVERSION_ERROR Occurred on 21.02.2005 at 14:08:20 The error probably occurred when installi

  • App for taking notes on PowerPoint ? Ipad

    I'm a college student and I just got an ipad. I always have PowerPoint for class and would like to go paperless with my ipad but I need an app where I can physical write on the power point with a stylus. I like to circle and star things on the power