6 ms·
I have recently moved away from lastpass onto 1password and find myself with some 1000+ credentials that I will now have to change. Been working though the list
by ThatsAllForNow 4y ago
I have recently moved away from lastpass onto 1password and find myself with some 1000+ credentials that I will now have to change.
Been working though the list and made a small dent of 50 accounts so far... There must be a quicker way to do this?
- fckthisguy 4y agoWe should introduce an industry best practice for account management. A "/.well-known" url for changing passwords would make this trivial to do in bulk with a password manager.
- monsieurbanana 4y agoNothing could go wrong with having a way of hitting millions of websites at once with a 0 day exploit :)
- dns_snek 4y agoThe functionality provided by such an API could be limited to disabling the account until the password is manually reset given that the client provides a valid email and password. The blast radius for that would be pretty small. I don't use 90% of the entries in my password manager on a monthly basis so anything that allows me to delay the password change on hundreds of accounts until I need to use the account again would be valuable.
- devnullbrain 4y agoObscurity is security, as the saying goes.
- lathiat 4y agohttps://www.w3.org/TR/change-password-url/ https://www.w3.org/TR/change-password-url/
- 2Gkashmiri 4y agoso if i get access to your PM, then i would be able to destroy all your accounts en masse. at least this way they would have to prioritize
- alpaca128 4y agoI don't think this matters that much. Most accounts are just for random websites that don't let you use basic functionality without a login. Being able to manage such accounts efficiently & without dark patterns in one program would be a massive time-saver, but whether a bad actor takes a few seconds or a few minutes to take over my important accounts I'm screwed either way.
- tokamak-teapot 4y agoIronically I believe I remember that LastPass had such a feature, though it didn’t work for more than about 2% of my passwords when I used it a long time ago.
- fluidcruft 4y agoI remembered that and before I learned more about the breach and was feeling "breaches happen" about things (I have strong master password) my thought was to use that to update passwords by age... but they actually removed the feature! That seemed so user hostile it made me mad enough that migrating somewhere where I can work with password age became my goal. Then as I've learned more about the breach, their design and their response it's just put wind in my sails. Bitwarden isn't much better, but they do have a cli technical users can cobble something together. (I ultimately decided to skip on Bitwarden also)
- coremoff 4y agoI imagine you can triage that quite heavily; change the critical ones (bank/email/etc.), then change anything where passwords and usernames have been duplicated. Anything else is probably pretty low priorty both in importance or criticality.
- 4lun 4y agoCurrently in the process of cycling a few thousand passwords myself. Realised I just have to nip away at it a bit each day Time boxed to about 15 mins a day, it hasn't felt like too much of a burden. But also finding I can just delete quite a few, as my vault is over a decade old and many sites/services are now defunct Will take another month or so, but have the more recent/crucial ones done already so worst case someone might crack my old digg password
- matesz 4y agoWhy not just go through them in one go and be done with it?
- jeromegv 4y agoBecause telling your boss you will be spending the next 3 working days going through all your password might not be the best use of time and might want to spread it out a bit. Especially when most of them are obscure website that are not likely to be the first target in a password leak.
- fluidcruft 4y agoOne thing I've found is "forgot password" is typically far, far faster/easier than hunting around trying to figure out how to change a password.
- substation13 4y agoDashlane claims to be able to do this for you. I don't personally use Dashlane and cannot speak to its security.