Risk assessment is a big part of this. Risk when reusing passwords is very high. Risk of forgetting passwords or using weaker/guessable passwords when they’re unique, is high. Password manager mitigates these risks. A good one will also bark at you when you try to use a password in a website that isn’t the one you saved it in (ie phishing warning)
The risk of your PW manager somehow leaking passwords is worth considering. So we ask: How are the passwords stored? Where are they stored? How are they accessed? Different tools work differently; some keep the storage local but others sync in the cloud. Local storage can also mean “in my Dropbox folder”. If it’s a secure format with a strong password (or perhaps Yubikey), that’s fine, but if it’s an excel sheet, you’re leaking to Dropbox. But is that really a problem for you? Think of the steps between an adversary and your password file.
1Password has some white papers published about how they secure the data you entrust them with.
It is my strong opinion, and that of most security experts, that using a password manager to create unique, long, and secure passwords is a lot better than the alternative. It’s usually the opinion that a password notebook in a reasonably secure location (in your desk at home) is better than recycling weak passwords.
Risk assessment is a big part of this. Risk when reusing passwords is very high. Risk of forgetting passwords or using weaker/guessable passwords when they’re unique, is high. Password manager mitigates these risks. A good one will also bark at you when you try to use a password in a website that isn’t the one you saved it in (ie phishing warning)
The risk of your PW manager somehow leaking passwords is worth considering. So we ask: How are the passwords stored? Where are they stored? How are they accessed? Different tools work differently; some keep the storage local but others sync in the cloud. Local storage can also mean “in my Dropbox folder”. If it’s a secure format with a strong password (or perhaps Yubikey), that’s fine, but if it’s an excel sheet, you’re leaking to Dropbox. But is that really a problem for you? Think of the steps between an adversary and your password file.
1Password has some white papers published about how they secure the data you entrust them with.
It is my strong opinion, and that of most security experts, that using a password manager to create unique, long, and secure passwords is a lot better than the alternative. It’s usually the opinion that a password notebook in a reasonably secure location (in your desk at home) is better than recycling weak passwords.