5 ms·
What, is "password managers are insecure" really a thing?
by metafunctor 6y ago
What, is "password managers are insecure" really a thing?
- wccrawford 6y agoYup. And they are, technically, because if someone has that one login and password, they can access all your accounts. But it turns out that keeping that 1 login and password in your head and trusting the rest to your password service (especially if you let it make random passwords) is way more secure than what people do if they have to try to keep them all in their head. So it's about relative security. Both sides are correct, in their narrow views of the situation.
- yoz-y 6y agoI believe security should optimise for the threat levels on the order of importance. No.1 is password reuse, which is what password managers solve.
- yoz-y 6y agoYes, if not explicitly then by their actions definitely. E.g.: there is only a single bank in France that hasn't switched to a stupid 6-8 digit system where you have to click buttons that appear in random order. Before then they often disabled autofill on passwords (luckily that could have been easily bypassed). They incessantly re-invent the wheel for 2-factor auth and so on. I find it very curious why banks of all institutions are those with the worst security.
- benhurmarcel 6y agoNot sure if that's the bank you're talking about, but FYI Fortuneo lets you use a normal password.
- yoz-y 6y agoYep, Fortuneo is the one still having sane security. There might be others but when I was bank-shopping I haven't found one.
- benhurmarcel 6y agoSane security would be using a one-time password 2FA in my opinion, but yes, it's the only one I know with a non-crazy login method.
- tinus_hn 6y agoHardly surprising considering how long they clung to ‘secret questions’.
- iamacyborg 6y agoBnp paribas have had this on their online accounts for at least a decade now
- dspillett 6y agoIt can be. Single master password, if leaked or otherwise getting into the wrong hands, gives access to all your auth details. This is part of why I keep to a desktop based password manager rather than an online one. But it depends on your threat model and attack surface area/shape. A strong password on a post-it on your monitor is stupidly insecure locally, but far more than just having a weak password if you consider only non-local (to the user) attacks (neither that site hacker in far-off Hackyoustan nor his pet bots can see the post-it, but could try brute force a short easy to remember password).