4 ms·
No one has mentioned this to you yet, from what I can see, but Master Password[0] is basically what you're asking for. It is well worth it to switch to an imple
by coder543 4y ago
No one has mentioned this to you yet, from what I can see, but Master Password[0] is basically what you're asking for. It is well worth it to switch to an implementation of that instead of your mental calculus.
> I believe there are alternatives that are more secure such as using a mental algorithm that generates a unique password per site.
Being completely honest, I consider this a terrible strategy. I seriously doubt your "algorithm" is anywhere close to as secure as you think it is. Humans suck at coming up with passwords, period, no matter how clever they think they are, and then memorizing those passwords is at least as difficult. Any algorithm that would actually be secure would take far too long to mentally apply to each website each time you visit it.
Fully featured password managers like 1Password can include much more than just usernames and passwords, which increases their value significantly. Otherwise, users absolutely store that incredibly important information in completely unencrypted places, often synced with the cloud, because it is important information that they need access to, and they want to make sure it doesn't get lost. There is tremendous value in having a user-friendly encrypted vault.
Since the entire vault is fully end to end encrypted with any decent password manager (like 1Password), the weaknesses that repeatedly affect LastPass do not ever apply here. The only thing that matters is having a strong password on your vault, and keeping that password secure. It doesn't matter if 1Password gets hacked, no one will even know what websites you have accounts on. Coincidentally, 1Password also doesn't have the same history of breaches that LastPass does.
The only other security risk beyond a weak password is a supply chain attack, where 1Password ships a compromised version of the 1Password client that steals your vault password, but this is significantly harder for a malicious actor to pull off than the breaches LastPass has dealt with, and any software vendor that you trust could be compromised and install a keylogger on your device, which would achieve the same outcome, so this is not specific to 1Password, and therefore I don't consider it very relevant to the discussion beyond mentioning that other people might bring it up.
> That's my personal approach and I think it's a better way to go.
It's really not, but someone who comes to the internet to rant about this stuff is so strongly convicted of their belief that I don't think I'm going to be able to change it, so I'll just leave it at that. I have cared a lot about cybersecurity for a long time, even before I worked in the cybersecurity industry for a few years, which gave me lots of additional exposure to experienced people and current events.
I have never recommended LastPass to anyone, and I would never recommend it to anyone. 1Password is a completely different story. There are valid open source alternatives, which you can self host, but most people (outside of this forum) are not going to succeed at hosting their own password manager, so it's important to find a trustworthy hosted option.
[0]: https://en.wikipedia.org/wiki/Master_Password_(algorithm) https://en.wikipedia.org/wiki/Master_Password_(algorithm)