Your password manager is the most sensitive piece of software in your tech stack. It holds everything - your email, banking, work credentials, health records, crypto, and more. Here’s how 12 of the…

  • FiniteBanjo@feddit.online
    link
    fedilink
    English
    arrow-up
    1
    ·
    13 days ago

    And? What next?

    The major counter-argument I’ve heard is that passwords can get exposed in leaks, but even if you only have a few passwords the odds of somebody hacking a social media account and then that same password working for your bank is slim to none if you’ve been smart about it AND

    as I mentioned

    use 2FA but not SMS. Something that really grinds my gears is when services don’t allow you to disable certain 2FA options such as email or SMS, those services are the ones that are actually vulnerable, compared to a non-google auth code generator.

    TBH I trust password managers less than I trust these institutions and I don’t trust these institutions AT ALL. If ever somebody finds a vulnerability in the password manages you lose EVERYTHING.

    • hendrik@palaver.p3x.de
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      13 days ago

      Yeah, what next is either a storm comes and your roof comes off in one piece. Or there’s no storm where you live and you’re fine.

      If you make sure to always(!) combine the password with a second factor, you should be safe. It’s usually some relatively secure design. The keys should be locked away in some hardware backed storage. Or at least encrypted by some other password. That’ll be very good protection.

      Though I wonder… You probably store your 2FA tokens in some app? What makes you trust that app but not the other one which does the same thing? (Store an authentication factor.) It’s literally the same thing as a password manager. Just that it does some clever trickery so every password is just valid for 30s. And it forces you to have a different authentication token for each service. (Which is a bit like using many different passwords.)

      And you’re right of course. Losing a password manager isn’t an option. That’ll compromise everything. And if you forget your master password and didn’t take care of it, you’ll be logged out of your digital life. It needs to to the job properly. I think as of now we have a few options with a pretty much spotless track record. Same for 2FA algorithms. Just phishing is hard either way.

        • hendrik@palaver.p3x.de
          link
          fedilink
          English
          arrow-up
          1
          arrow-down
          1
          ·
          13 days ago

          Hmmh. Now that I know what you do, I’m less worried. But maybe you should phrase your advice the other way around. 2FA shouldn’t come as the last thing buried in “tips”. It’s like well >90% of what you rely on. So I think proper 2FA should switch places with your advice for the passwords. Keep them around. And I’m not a big fan of what banks do with the 4-digit PIN protecting the card. But it’s also not like that you absolutely need to focus on a super strong password with that. At that point it’s more the safety for your 2FA. Better is better. But it’s not the decisive factor any more.