5 ms·
I use a password manager for the hundreds of accounts I have where security is not super important. Mostly as way to not have to reuse passwords (credential stu
by 0x0000000 5y ago
I use a password manager for the hundreds of accounts I have where security is not super important. Mostly as way to not have to reuse passwords (credential stuffing now makes up a significant amount of attack traffic), nor fight the varying password requirements ("shoot, did this website require a special character?"). Tbh, it's nice to have one less thing to worry about. For the increasing number of sites which require 2fa, it also let's me keep a totp token accessible from all my devices.
My most secure accounts use their own individual, memorable, secure password.
I do fear that even if my self-hosted password manager is secure today, there's nothing stopping a malicious update to that software which could exfiltrate all of my passwords.
- jimbob45 5y agoCame here to say this. When you're on the job hunt, there are a thousand different MyWorkDays you'll need to sign into and what an incredible pain it is to keep track of those manually. Just don't forget to delete all those accounts when you're done hunting.
- PennRobotics 5y agoI leave the really unimportant crap in the Firefox "generate and remember this login", the regular passwords in Bitwarden, and financial passwords in my head. Answering the original question: I trust that Bitwarden's Github source is what drives their service and that their popularity ensures the source is audited on a regular basis by reasonably skilled software folks. It's the same degree of trust I give to the people that build every reasonably vulnerable product I use: elevators, phones, cars, door/window locks, etc. ----- For me (and perhaps only me) a more pressing concern is that fingerprint scanning is common in apps that are meant to protect data: banking apps, stock market apps, Bitwarden. NOBODY makes a significant effort to hide fingertips. Cameras are cheaper, more accurate, and more numerous than ever. People don't clean every surface they touch. It can't be so difficult to 3d print a mold and find the right material to make a false finger. Android's security model has a nice built-in feature: If you have someone's phone for a few seconds and know their unlock code (not too tough to espy... right, Ye?) you can keep retrying the false finger for that person until it works. Only then do you switch to the important app. Oh, and... Fingerprints, unlike master passwords, are nearly impossible to change.
- tasha0663 5y agoThis is my approach as well. I see passwords as being in tiers: - Level 0: the serious stuff that would absolutely suck if it got compromised. Namely Google. Banks. - Level 1: things that would be an inconvenience if they were compromised. Okay it's annoying that someone got into my Amazon account or something, but this can be dealt with. - Level 2: passwords my in-laws are going to use to watch Netflix or the like. If this gets compromised... ok, that's a pain for Netflix but this is essentially a victimless situation. Password managers are really good for the Level 2 stuff. Really, there are too many passwords we need to know. They are okay for the Level 1 stuff, just have an idea who you're going to call. I wouldn't use them for the Level 0 stuff. Like anything else, you balance your risk against convenience. Approached this way, even if the password manager gets hacked, you're only minorly inconvenienced. Always have 2FA on where allowed and what's the worst that will happen?
- TameAntelope 5y agoPassword managers are by far the safest way to store the level 0 stuff too, fwiw.
- BenjiWiebe 5y agoThat's what I'm thinking. My level 0 passwords for sure will be in my password manager (except for one of them, for some reason). Level 2 passwords I'll sometimes just reuse a memorable password. My password manager is open source and offline, though, so that helps.