not_that_guy05,

I just use engine model codes and body series# with special characters. Most of them are not even from the same vehicle so I doubt any one can remember. Shit sometimes I even forget what engine I coded with a certain vehicle. And then I get the you “can’t used the same password” which was enter previously to login.

Kedly,

Counterpoint: Password Manager = One point of failure

Multiple Strong Passwords that have to be changed every 3 months even to sign on to your cornerstore rewards program without a password manager? Guess you’re never accessing any account older than 3 months because you’ve forgotten th3 b1lli0n$ oF s+r0ng p4s5w0rds Y0u h4Ve cr3atEd!

Catsrules,

Actually you are the single point of failure

xkcd.com/538/

Kedly,

I mean yeah, the security benefit from being un-notable isnt negligible

0xD,

Okay and now let’s get into threat modelling and risk management.

What is the purpose of a password manager? What are the possible threats against them, and what are those against singular passwords for services? What is the risk of each of those?

Kedly,

Guys, before you argue with me, password security is something that EVERYONE in the 1st world has to deal with, not just tech nerds. If you need to grow up around computers or take a class for it to be a good form of security, its a shit form of security for the general public

0xD,

But you don’t?

Password managers really are not hard to use. Also there’s stuff like the password manager built into iOS, for example, which you don’t even have to think about.

My comment about threat modelling was that you do not seem to understand the purpose of password managers. A way bigger problem for the average person online is password reuse, not targeted attacks against password vaults. That is the problem they solve.

wewbull,

The weird trope I’ve seen now is “don’t use the password manager in your browser”. For the life of me, I can’t think why some think a browser plugin to a commercial password manager is safer than the built in version.

Gestrid,

They probably think it’s safer somehow. But I don’t really get how.

Most built-in password managers allow for you to setup a master password of sorts if you try to sync everything to a new device, and most also require you to use your computer’s native verification to view a single password in plaintext or export all of them as plaintext. (For browsers on Windows, they use Windows Hello; for browsers on Android, they use the fingerprint scanner or the lock screen pin.)

FakinUpCountryDegen,

That’s…not a counterpoint.

You can have strong authentication on your central password manager, and have an encrypted container protecting it.

There is no logical argument against password vaults as a concept. There are bad implementations of specific password vaults, but a password vault is the answer for the highest possible password based security available in 2023.

Kedly,

And figuring out which password managers to use is not a task which a lot of people know where to start, and it is STILL a single point of failure

RedditRefugee69,

What makes it completely unusable for me is that I don’t have a single work computer I use. I have to bounce around computers at work, my personal phone, computer, work iPad, etc.

Comment105,

I have no idea about how to protect a password manager with an encrypted container.

And to be honest with you, it’s not something I’m likely to do even if you do attempt to explain the 60 minute long $10 18-step process to me. Or however long it takes and whatever it costs.

And really, for all my ignorant ass knows you could’ve just as well been encouraging me to get malware and I’d be none the wiser.

Lunachocken,

Well once you get passkeys implemented in every website. Now they’ll need to steal your phone. Haha.

Tekchip,
@Tekchip@lemmy.world avatar

I get the joke.

But related real talk phones get got a lot. They won’t need to steal your phone they’ll just hack it like every other computer on the planet.

You don’t have to look much for the evidence.

pcmag.com/…/ileakage-flaw-can-prompt-apples-safar…

www.bleepingcomputer.com/news/security/…/amp/

crashoverride,

Use a passphrase, so much better and more secure

lhamil64,

But that doesn’t do anything to mitigate using the same password/phrase on multiple services.

clanginator,

I came up with a formula for my passwords - as easy to remember as a single password and makes a unique login for every site feasible without a password manager. Can be updated as often as you like and all you gotta do is remember the latest version of the formula. At the very least, the hashes will be different and it’d take someone having more than two of my passwords to figure out the pattern.

I also use over 100 email aliases with my own domain name so that my most important accounts have a separate login that isn’t a common domain that wouldn’t be easy for someone to guess.

It would take a lot of concentrated effort for someone to get at any of my important accounts, and even my less important ones would be pretty difficult to get into even if multiple accounts are compromised, due to using a smaller pool of aliases under common domains for less important accounts.

Someone got into half a dozen of my accounts a few years ago and I finally started taking security seriously.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • memes@lemmy.ml
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #