11 ms·
For me the main barrier has been convincing my family to actually take password management seriously. My entire family has had their emails hacked at least twic
by waffl 4y ago
For me the main barrier has been convincing my family to actually take password management seriously. My entire family has had their emails hacked at least twice due to poor/reused passwords that have been in leaks, constantly forget IDs/passwords, and are constantly overwhelmed with the idea that they need to keep track of all these things.
I've set up a 1password family and set up accounts/vaults on everyone's computers/phones/tablets, yet they still find it too troublesome to use rather than simply writing passwords down in plaintext on their notes apps or just on sticky notes attached to their computers etc...
If anyone has had success encouraging family to use a password manager I would love to hear any tips, as I've sat my family down every holiday season to reset everyone's forgotten passwords and walk them through everything, practice creating/saving/using passwords and within a day it's all forgotten again. Like backups, I feel like no one takes it seriously until something truly horrible happens.
- jefftk 4y agoHave you tried getting them set up with Apple's (if they're on Mac/iOS) or Google's (if they're on Chrome/Android)? Using something built-in is almost always the lowest friction option, and it sounds like it's friction that's keeping them from the sticking with the password managers you've tried them on.
- squeegee_scream 4y agoI dislike the idea of recommending these OS-specific password managers because what if they need to access their passwords on another machine? But I'm guessing for most folks that's not a concern. I also don't trust them _nearly_ as much as I do 1Password, but that's at least some prejudice on my side.
- mmcconnell1618 4y agoBoth the Apple and Chrome password managers sync to the cloud so as long as they can sign in to their account on another computer or phone, they can still get access to the saved passwords.
- mynameisvlad 4y agoBut only when using an Apple product (for the iCloud solution) or Android device or Chrome browser (for Google's), right? My parents use whatever browser their company has installed on their computers, which I think is Chrome for one person and Edge for the other. Their home laptop is a Surface Laptop device with Edge on it. It'd work for their phones, and I honestly don't see them switching to Android anytime soon, but it's still not available all the time, and I haven't been able to get them to do anything but autofill of the passwords I created for them. Even as is, telling them to go to a dedicated app to copy a password to use on their laptops is a step too much. Adding more complexity isn't going to help.
- jmbwell 4y agoWith iCloud for Windows, keychain passwords are accessible in Chrome and Edge.
- phonebanshee 4y agoBut in the real world ease of use is _everything_ for the vast majority of people.
- squeegee_scream 4y agoExactly. When I worked at 1Password everyone in the company knew this, and were trying to vastly improve the user experience. I've been gone for about 18 months now and I don't see many changes, which is unfortunate, but I know it's something they are passionate about. I hope they can figure it out, I think UX and easy of use are difficult things to get right for password managers.
- hnews_account_1 4y agoI’d trust them more. They’re likely behind the same security barrier as the rest of Google’s / Apple’s services. They’re probably getting attacked all day every day and holding up so I’d imagine they’re way more robust than most smaller companies.
- squeegee_scream 4y agoIt isn't about how easy/difficult it is to hack them. Any password manager I use needs to be un-hackable in any realistic sense. It's about trusting the company. And before I get flack about "nothing is un-hackable" blah blah, see "in any realistic sense".
- ccouzens 4y ago> what if they need to access their passwords on another machine In the case of saving them to Google/Chrome, they can be accessed online here https://passwords.google.com/ https://passwords.google.com/ I don't know if Firefox or Apple have a similar online tool to access them.
- r00fus 4y agoApple/Chrome ones don’t help setting up 2-factor codes/etc. Ie, you don’t want the second factor to be SMS. They’ve decided passkeys are the way to go so they don’t support TOTP or that stuff natively. 1Password handles TOTP quite well.
- kayodelycaon 4y agoIt's recent, but Safari does support TOTP now. https://support.apple.com/guide/iphone/automatically-fill-in-verification-codes-ipha6173c19f/ios https://support.apple.com/guide/iphone/automatically-fill-in...
- loeg 4y agoMy parents use pen and paper as a password manager and it works pretty well for them -- invulnerable to hackers, they never forget passwords, etc.
- halostatue 4y agoMy parents tried that, but they kept misplacing the notebook in which these passwords were kept, and the passwords were too simple and guessable by half in any case.
- vorpalhex 4y agoI teach "several small unconnected words" as the password algorithm. You can literally crack open a dictionary and pick words at random.
- forinti 4y agoUse a common prefix or suffix that you don't write down so that even if someone reads your little book (which is unlikely anyway), they won't be able to use the passwords.
- pandemicsoul 4y agoSure, this is great if your biggest concern is password security vs. password breaches. No one using pen & paper is creating new passwords for every site they register for, so they're probably just reusing the same few passwords (or, maybe, with small variations) between sites. Which means they're constantly putting themselves in a position to be hacked, regardless, since breaches expose all your other accounts when you have just one email address.
- halostatue 4y agoShow them. Since you’ve got them set up, if you are called on for tech support (especially around a password), remind them that you can’t help them if they don’t have the password in 1Password, because you can’t debug those things. It took 4–5 years, but my wife is now a 1Password advocate and tells people that it’s the best way to protect themselves. Sort of like a feature of our banking apps‡, she has been convinced by the fact that the 1Password URL matching provides strong anti-phishing protection. For the most part, my family has found it easier to remember that they only have to know one password than to put up with my complaining that they’re not using 1Password and I can’t help them because they’re not… ‡ The feature for the bank was the "spending notifications". Almost ten years ago I installed the "spending tracker" app from the bank, and about a month or two after, I got a notification of a 0.01 charge from a company we have no business with. After I tapped through, I noticed that it was on my wife’s credit card, so I notified her that her card had been skimmed and she needed to contact the company. We knew before the bank knew because of their feature. She installed the app the next day.
- squeegee_scream 4y agoI used to work at 1Password, and have been a happy 1Password user before that. I recommend it _all the time_, and I carry around a $20 1Password gift card in my wallet to give to people when I recommend it. But I have been trying to get my mom setup on it for months and it's still a struggle :( I was hoping this article was going to say, "FooPassword has great security, and amazing UX and even your mom can easily use it", but alas... The problems my mom experienced setting up 1Password, some I had never encountered. There are at least a handful of things going on that can cause problems, including web browser, internet connection, 1P browser extension, 1P desktop app, OS (at this point my mom has become unfamiliar with all desktop OSes since she has primarily used her smartphone for over 6 years and rarely if ever uses a desktop OS). There are enough opportunities for issues to occur that are trivial for me to troubleshoot, but are non-starters for my mom. And I suspect that my mom's experience is very common :(
- brimstedt 4y agoI use 1pw and if you has any contacts left there, please urge them to fix their UIs! The ux is terrible, and on Mac there are at least three different UIs you can open (browser, click on toolbar icon and "full" UI.) On Linux I think there are at least two variants, maybe more, dont remember. Just make one and make it simple and usable. By simple I don't mean Google/apple-style "hide everything because people are stupid". I mean simple, consistent, reliable, usable and powerful. BR
- lazide 4y agoClearly you're not an ex-lastpass user. 1Password is about 100x better!
- novok 4y ago1p is a fairly complicated UX that fails a lot. Sometimes password autofill shows up, sometimes it does not. If I bring up password autofill, sometimes it shows a list of 0 websites because I didn't use the website association thing when recording the password login, and often because it failed because the UI fails very easily if it doesn't go in it's happy path, or I press back, or the password was rejected, etc. A lot of this is probably OS & browser vendor limitations, but it ends up with 1p being a power user only piece of software.
- sz4kerto 4y agoI know a person who works in tech, is very smart, has plenty of gadgets -- he just can't take this seriously and uses a single txt file in Dropbox for all their passwords (that are all just human-generated, reused, MyRandomW0rd123-like passwords). Claims to be optimistic and thinks that they're not going to be that person who gets hacked.
- raverbashing 4y agoAnd to be fair he's not that wrong The real annoyance is that we need a "password manager" in the first place You wouldn't need to worry (too much - as long it's not a weak password) about password reuse if websites abided by security best-practices and wouldn't leak lists of weakly hashed password. salt + pepper + good amount of rounds proper hashing function: good luck And to be fair the browser ones work great. Another one that works great is a paper notebook And again, it all depends on your threat models. Using very complicated passwords and 2FAing your password manager will only ensure that you'll get locked out of your accounts sooner or later (unless you have a target painted on your back for some reason)
- nicolaslem 4y agoStrong disagree about password reuse, the average person has multiple dozens if not hundreds of accounts on various services. Even if none of them ever get hacked, you are still trusting thousands of engineers having access to production to not record the passwords that are sent to them with each login. Just use a random password per service and keep it in a password manager.
- raverbashing 4y agoAgain, if companies didn't treat password data carelessly (or, even worse like your example) it would have been a minor issue Yeah, I'm not advocating for password reuse, I'm saying that a good system would make it a non-issue
- RickHull 4y ago
- SV_BubbleTime 4y agoFWIW... I set up 1Password as a business account for demo and eval. I hated it almost every part of it. If you are coming from Bitwarden, Dashlane, or Lastpass, the UI makes little sense. All three of those used Lastpass's initial UI. It's a better UX. I couldn't get off of 1Password fast enough. Something about their desktop app it seemed overly heavy/slow.
- deleted 4y ago[deleted]
- jordanpg 4y agoI've had success with my parents and 1Password by only teaching them an extremely limited feature set: how to create new entries, update existing entries, and to copy and paste usernames and passwords. No browser extensions, no autofill features, no URLs, no vaults, no labels, etc. I think that almost all the friction with respect to password managers relates to autofill, how to make it work, and in particular, how to recognize when and why it's not working. For non-technical people, this is an intractable problem. It's too much even for a lot of technical people. It's also why I doubt password managers in their present form will ever get widespread adoption. Their best features are just too finicky. Not due to any fault on the part of the authors -- it's just that the web is a mess, things change, and this kind of thing will always break from time to time. So, my advice is to distill password management down to its simplest essence and just teach that to non-technical people in the hopes that it will more-or-less resemble the notepad/spreadsheet method, except with a password now.
- hnews_account_1 4y agoMy mom cannot understand how to use auto fill etc, but what I did was to set up a KeePass database file for her on her google drive and just sync it up on every device. She refuses to use anything but an android and she acquiesced to an iPad when I told her android tablets are still catching up. So I just found the most common service - google - and put everything on it. She now knows to open it and expose the password as well as create new entries. She still can’t copy paste or handle the generator. My dad does not give a flying fuck however many times you tell him and just writes it down in a notebook. He just doesn’t care despite much of the family wealth residing mostly in his accounts.
- milosmns 4y agoI've never heard of mobile OS being THE barrier for using password managers. It's usually a ton of other things... after all, both of our favorite OSs use autofill from the keyboard bar, so it should be straightforward. But hey, I have a similar parent. I just installed it for him and told him this is the new way... "computer programmers made it this way now".
- hnews_account_1 4y agoIt’s not the mobile OS so much as the fact that I want something I can troubleshoot easily and isn’t hidden behind several layers of UX. KeePass satisfies that. I just shared my mom’s database file with me on Drive so I can also access it in case of issues. If not, I’d need a service that can support like family sharing and shit and they may ask for extra money. This is easier and more secure since my mom has no idea how to share things from Drive so she won’t even do it by mistake. The auto fill part is relatively straightforward to us but it takes a while to get used to for the previous generation. In fact, despite showing her how to create new entries, she spent the last 2 years still writing it down in her Google Keep notes app. Had to spend a non trivial amount of time transferring them over this holiday.
- AdmiralAsshat 4y agoI had this problem to. And sufficed to say, the one family member we did convert is understandably panicked after the LP breach, and the one who held out is now smug about it. For the ones who have held out, I gave up and just bought them all one of those "Password Journal" things from Barnes and Noble. Having unique passwords for every site is more important than having an electronic vault, so, baby steps.