3 ms·
If I had logged into my actual password manager (1Password, the one I chose), and saved the master password that that somewhere that could be autofilled, then I
by fasterthanlime 6y ago
If I had logged into my actual password manager (1Password, the one I chose), and saved the master password that that somewhere that could be autofilled, then I'd be right there with you.
That's not what happened at all though. Chrome collected passwords over the years, Safari saved the wrong one, and it leaked all my old passwords - and a few ones I hadn't changed yet.
I spend a large amount of time admitting my mistakes in the article, Google's approach to 2FA is still really surprising to me and a lot of others are hearing about it for the first time.
- BuckRogers 6y agoI think he’s saying that your Google account password is your master password in this case, and was leaked. I get what you’re saying though, no one expects Google’s password management to be so riddled with holes. Encrypting the view or usage of the rest of your passwords with a master password needs to be mandatory, not optional. I’ve always used Keepass stored on Dropbox and enter my master password everyday, multiple times as it logs out after 3 minutes. I do save some passwords in Firefox but don’t sync those, and 2FA through Microsoft Authenticator (SMS only when it’s the only option). That’s still not perfect but your attack surface doesn’t exist. This is all really complex for the average person and it took me years as a relatively astute developer to handling properly. A device (something you have) biometric (something you are) authentication should resolve all of these issues in an easy way that you don’t have to think about, and I’m looking forward to ‘sign in with Apple’ to become a universal login for this reason. They nailed this problem, now we need Microsoft and Google to do the same.