this post was submitted on 14 Aug 2024
350 points (100.0% liked)

Privacy

789 readers
55 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

It is truly upsetting to see how few people use password managers. I have witnessed people who always use the same password (and even tell me what it is), people who try to login to accounts but constantly can't remember which credentials they used, people who store all of their passwords on a text file on their desktop, people who use a password manager but store the master password on Discord, entire tech sectors in companies locked to LastPass, and so much more. One person even told me they were upset that websites wouldn't tell you password requirements after you create your account, and so they screenshot the requirements every time so they could remember which characters to add to their reused password.

Use a password manager. Whatever solution you think you can come up with is most likely not secure. Computers store a lot of temporary files in places you might not even know how to check, so don't just stick it in a text file. Use a properly made password manager, such as Bitwarden or KeePassXC. They're not going to steal your passwords. Store your master password in a safe place or use a passphrase that you can remember. Even using your browser's password storage is better than nothing. Don't reuse passwords, use long randomly generated ones.

It's free, it's convenient, it takes a few minutes to set up, and its a massive boost in security. No needing to remember passwords. No needing to come up with new passwords. No manually typing passwords. I know I'm preaching to the choir, but if even one of you decides to use a password manager after this then it's an easy win.

Please, don't wait. If you aren't using a password manager right now, take a few minutes. You'll thank yourself later.

top 50 comments
sorted by: hot top controversial new old
[–] Ilandar@aussie.zone 38 points 3 months ago (1 children)

people who use a password manager but store the master password on Discord

??????????

[–] Charger8232@lemmy.ml 15 points 3 months ago (1 children)

Yeah, true story. Really weird.

[–] Ilandar@aussie.zone 6 points 3 months ago

I really want to know what the logic behind their thinking was...or maybe they were just lazy? I don't know, it's so weird that they'd get to the point of using a password manager but then still make such a basic error.

[–] sudoroot@lemmy.zip 33 points 3 months ago (2 children)

In my experience preaching this same thing to many users at work and just personal friends, they won't change their ways. Because "omg not another password to remember" and "that's too much work to login just to get a password".

I've just stopped trying to educate people at this point. That's on them when their info gets leaked or accounts drained.

[–] zephorah@lemm.ee 10 points 3 months ago (2 children)

People are already annoyed at base that they need any 2FA at all and don’t want to deal with more info. They just tune out.

[–] Jessica@discuss.tchncs.de 7 points 3 months ago (5 children)

Tell them some password managers have TOTP support. I think I paid Bitwarden $10 for life or per year for TOTP so I don't need to use my phone.

load more comments (5 replies)
[–] sudoroot@lemmy.zip 5 points 3 months ago

Yup, they couldnt care less about any 2FA. But then they get the surprised Pikachu face when they get breached after being phished lol.

load more comments (1 replies)
[–] wuphysics87@lemmy.ml 21 points 3 months ago (1 children)

My sell on password managers is quality of life. You never have to reset your passwords and you can use a hotkey to enter it faster than typing. Gone are the days of fat fingers.

But I get where people have an issue. It's one point of failure vs. many, but they don't realize It's easier to well secure the one than it is to not spread the same vulnerability everywhere.

[–] icedcoffee@lemm.ee 7 points 3 months ago

Honestly as someone who has helped family members set up a password manager one person felt this way and the rest are just not tech savvy. All the simple straightforward stuff took ages because they had never done it before.

[–] land@lemmy.ml 20 points 3 months ago* (last edited 3 months ago) (2 children)

You are right. However most of the mainstream YouTubers promote rubbish password managers, which is why most people I know don't know about bitwarden. I usually recommend bitwarden or proton pass. (I'm self-hosting vaultwarden). More privacy focus YouTubers need to promote bitwarden, keepassxc etc. (I'm waiting for proton pass self-hosting option).

[–] vovo@lemmy.dbzer0.com 5 points 3 months ago (1 children)

whats missing, since the proton pass source code is available?

[–] mrmojo 4 points 3 months ago

I have only found the source code for the Android and iOS application, but not for the server.

load more comments (1 replies)
[–] orca@orcas.enjoying.yachts 15 points 3 months ago

Been using 1Password for 6+ years and I probably won’t use anything else ever. My wife and I both use it and have a shared family vault for things we both use. I couldn’t live without a password manager.

[–] Interstellar_1@lemmy.blahaj.zone 13 points 3 months ago (3 children)

My dad somehow believes that that password managers are very insecure ( he got that from some sort of 'reputable source', so me telling him bitwarden is secure doesn't help) and he just writes down all of his completely randomly generated passwords in a notebook, which always seems really inefficient to me, especially when he writes a character down incorrectly.

[–] superkret@feddit.org 24 points 3 months ago

He's doing something right.
You can't hack a paper note over the internet.

load more comments (2 replies)
[–] feoh@lemmy.ml 11 points 3 months ago (3 children)

I blame the tinfoil hat infosec crowd for not understanding that the world they inhabit is not the same one Regular Users live in.

Is there risk in keeping all your passwords in one place, whether it's on your hardware or someone else's? hell yes! Is that risk stastically speaking ANYTHING LIKE the risk you take when you use 'pencil' for all your passwords because you can't be arsed to memorize anything more complex? OH HELL YES.

Sure, if you're defending against nation state level agressors, maybe using a password manager isn' the wisest choice, but for easily 99% of computer users, we're at the level of "keeping people from drooling on their shoes". So password managers are probably a GREAT idea.

load more comments (3 replies)
[–] shortwavesurfer@lemmy.zip 10 points 3 months ago

Absolutely this. Been using KeePassDX for years and its made my life so much easier. I am waiting for it to support passkeys so i can start using them where possible.

[–] purplemonkeymad@programming.dev 10 points 3 months ago (1 children)

I tell non techy people to use a physical book that they can secure. People know how to do hide things or put them in a safe. Digital security is harder to understand and I would say a book in a safe place is way better than reusing passwords they find hard to remember.

load more comments (1 replies)
[–] trk@aussie.zone 10 points 3 months ago

On the plus side, the more people who don't use password managers the more chance us password manager users will remain not worth the effort.

It's kinda like security through obscurity mixed with only having to be faster than the slowest person to outrun a lion.

[–] lemmyknow@lemmy.today 10 points 3 months ago (2 children)

Say, what are the chances either

  1. someone comes to depend on the password manager to get into their accounts, gets locked out of the password manager, and loses access to all their accounts (e.g. using the password manager to create and store passwords they might never have even seen);

or

  1. their password manager (or account) gets hacked, somehow, and all their accounts get taken at once
[–] kevincox@lemmy.ml 5 points 3 months ago (1 children)

These are real issues however they are pretty easy to mitigate, and I would say that the upsides of a password manager far outweigh the downsides.

  1. Make sure that you are regularly typing your master password for the first bit. After that you'll never forget it. You can also help them out by saving a copy of their master password for them at least until they are sure they have memorized it. There are also password managers where you can recovery your account as long as you have the keys cached on at least one device.

  2. This is far, far outweighed by the risk of password reuse. This is because when a single one of the sites you use gets hacked then people will take that credential list and try it on every other site. So with a password manager there is just one target, without it is one of hundreds of sites where you reused your password. Many password managers also have end-to-end encryption so without your password the sync service can't be hacked (as it doesn't have access to your passwords).

[–] lemmyknow@lemmy.today 5 points 3 months ago (1 children)

Well, what if they somehow manage to get into my password manager account? I mean, it has a login, like any other account. The way to prevent it would be to have a strong enough password. Regardless, if they somehow got my main password, they'd have free access to all my credentials everywhere, and would be able to log into them as easily as I can. I mean, it is easier to secure one account well vs. however many others that the password manager can take care of. But still, a centralised hub with easy access to all my accounts feels like a one-stop shop for taking over my online life

I mean, to myself, I can deal with the consequences of my choices (as much as they can suck sometimes). But recommending stuff to other people I find complicated. I mean, I've gotten locked out of accounts due to 2fa (some being old and lost to time, others due to an unlucky series of events and a last minute half-assed backup) and even had to troubleshoot and/or reinstall (Linux) operating systems on my laptop (one instance of which relates to the aforementioned 2fa incident). To recommend something to someone and risk something like that, and be responsible for it… I mean, I once had to help troubleshoot a non-booting Linux machine via messages and photos during lunch out, and I myself am not an expert, so I had to online research from my phone and relay the information

load more comments (1 replies)
load more comments (1 replies)
[–] Pyr_Pressure@lemmy.ca 9 points 3 months ago (2 children)

I don't even understand why I need to make a password for some sites anymore. They send a code to my phone everytime.to make.sure it's me so it seems like there's practically no point.

[–] No1@aussie.zone 7 points 3 months ago (1 children)

2FA really stands for

2 FUCKING ANNOYING !!!

[–] Crikeste@lemm.ee 5 points 3 months ago (2 children)

Do you not understand how much 2FA helps you? That shit is cash money.

[–] No1@aussie.zone 5 points 3 months ago* (last edited 3 months ago) (1 children)

I've got a random username if the stupid website/app allows it. Most don't. It has to be your email address.

And a minimum random 20 char password for each website/app. Again if the stupid website/app allows it.

Secure your (I don't mean you personally) fucking website/app and credentials storage and stop making your weaknesses my problem.

Most places, and all of my stupid financial websites/apps, only have phone/SMS as the second factor. And yet there are plenty of horror stories about people 'losing' their phone numbers.

Oh wait. There is one financial site that has developed its own authenticator app. I really expect that to go about as well as storing passwords in cleartext.

Then there's all the shit websites/apps that I don't give a fuck about that now insist on having 2FA set up. They're not interested in the security, it's just to get your email and phone number to onsell your data to whoever.

It's fucking security theater.

load more comments (1 replies)
[–] NauticalNoodle@lemmy.ml 5 points 3 months ago (1 children)

I don't think 2FA being effective needs to be mutually exclusive with being "fucking annoying" -It is a security measure after all, and the one thing security measures never are is convenient.

load more comments (1 replies)
[–] KevonLooney@lemm.ee 5 points 3 months ago

Because different layers protect you against different things. It's like how you have anti-lock brakes, a seatbelt, an airbag, and crumple zones on your car. You don't just have one thing to protect you.

[–] Ovata@lemm.ee 8 points 3 months ago

Been using Bitwarden for a couple years now…

No regrets

[–] chottomatte@lemdro.id 7 points 3 months ago (2 children)

Using Proton Pass was a game changer to me , I don't have to ignore the necessity to put a strong and complicated password for security reasons anymore, Proton generate it to me and stores everything ( so I don't need to remember which password I set for which account ) But the bad aspects of cloud services worry me a little about this: the possibility of a security breach of the service, or the possibility of not being able to access it for any reason is a real disaster if it happens... so I'm thinking of exporting my passwords to another safe place for such cases.

[–] Charger8232@lemmy.ml 6 points 3 months ago (4 children)

But the bad aspects of cloud services worry me a little about this

KeePassXC is entirely local.

[–] 14th_cylon@lemm.ee 5 points 3 months ago (2 children)

Which creates issue with having to synchronize it between devices. There is always something to worry about :)

load more comments (2 replies)
load more comments (3 replies)
load more comments (1 replies)
[–] SocialMediaRefugee@lemmy.ml 6 points 3 months ago (1 children)

I'd be open to using a pw manager then I read the comments here and everyone is suggesting different apps, arguing over how inconvenient one or the other it, various issues, etc. It doesn't make me feel like taking action if everything feels sketchy.

[–] Kaiserschmarrn@feddit.org 5 points 3 months ago* (last edited 3 months ago) (1 children)

I'm paying for Bitwarden's Family plan and share it with three friends. It costs me ~80 cents per month and it just works. We are using it for multiple years now and migrated to their new EU servers this year. Bitwarden has everything I need and it's in my opinion the best bang for your buck. But try out their free option and form your own opinion.

load more comments (1 replies)
[–] jsomae@lemmy.ml 5 points 3 months ago (5 children)

is it possible to sync keepassxc between computers + phone?

[–] lseif@sopuli.xyz 5 points 3 months ago (1 children)

tbh i just keep the master version on my computer and physically transfer it to my phone every so often. i try to avoid using too many password-requiring services on my phone.

load more comments (1 replies)
load more comments (4 replies)
[–] far_university190@feddit.org 5 points 3 months ago (7 children)

Is there manager than create password based on masterpassword and domain/username? Do not want to lose all password just because drive dies. Do NOT want to use cloud anywhere.

[–] lseif@sopuli.xyz 6 points 3 months ago (3 children)

backups backups backups.

keep a copy on your computer, your phone, and every spare drive u have in the house. ask a friend to store the file at their place.

also, whats wrong with a cloud provider, if the file is encrypted ?

[–] far_university190@feddit.org 4 points 3 months ago

Cloud can go down, cloud can delete my file, cloud can be hacked and someone try crack encryption (rsa vulnerable to quantum compute in future, maybe similar happen to aes).

load more comments (2 replies)
load more comments (6 replies)
[–] ColeSloth@discuss.tchncs.de 4 points 3 months ago

But I wanna tell people my master password to my pw manager. It's such a fantastic password that no one could ever possibly guess I would have. I wanna gloat.

[–] Rubanski@lemm.ee 4 points 3 months ago (2 children)

How do I convince my girlfriend to stop using her safari password manager and migrate it to bitwarden? Is the password manager in Safari so unsafe that it's worth the additional effort she might ask.

[–] morgin@lemm.ee 10 points 3 months ago (1 children)

Apple is releasing a more comprehensive password manager in the next few months, if she’s heavily in the apple ecosystem the switch could be pretty convenient

Obviously bitwarden or keepass would be great but this would be a bump up from being stored in a browser

load more comments (1 replies)
load more comments (1 replies)
[–] Blizzard@lemmy.zip 4 points 3 months ago (3 children)

What's wrong with a password manager built in the browser?

[–] kevincox@lemmy.ml 7 points 3 months ago (1 children)

Honestly nothing. I recommend this to everyone because it is the easiest way to set up and offers huge advantages.

  1. No more password reuse, per site random passwords.
  2. Auto-fill reduces chance of phishing attacks work because you get suspicious if the password doesn't auto-fill.
  3. Most browsers will integrate it into their sync service to reduce the risk of you losing your passwords.

I think these are the two biggest benefits and every browser password manager will accomplish both.

load more comments (1 replies)
[–] Monstrosity@lemm.ee 5 points 3 months ago

That's what I've resorted to, but I only use Firefox because it has a master password.

Chrome has no master password so what stops any fool from stealing your passwords while you're taking a piss, I don't know.

Password managers always cause me headaches, though, and never want to integrate correctly. More trouble than their worth in my estimation.

load more comments (1 replies)
load more comments
view more: next ›