South African bank advises against the use of password managers
1–10 of 75 posts
Re: South African bank advises against the use of password managers
#2Re: South African bank advises against the use of password managers
#3I wonder how they share credentials without a PAM or similar. All service accounts are using 'S3cur3P@$$w0rdzSuck'... Or more probably just a 'passwordz'?
What a shocking state of affairs.
Re: South African bank advises against the use of password managers
#4Half of Android "password managers" are scams.
Re: South African bank advises against the use of password managers
#5Re: South African bank advises against the use of password managers
#6I feel like this is a similar red flag as the 'no single quotes in passwords' limitation that used to be common.
Re: South African bank advises against the use of password managers
#7I'm frequently baffled when I encounter a login form that doesn't allow pasting a password. Of course with developer tools I can just remove the attribute that causes that, but plenty of internet users lack that level of technical knowledge and are forced to resort to easy to member and very likely reused passwords. I feel like this is a similar red flag as the 'no single quotes in passwords' limitation that used to…
[0] https://keepass.info/help/base/autotype.html
[1] https://github.com/carnager/rofi-pass
[2] http://bradfrost.com/blog/post/dont-get-clever-with-login-fo...
Re: South African bank advises against the use of password managers
#8Re: South African bank advises against the use of password managers
#9If you use hardware 2FA and have lots of bank accounts (business, trading, etc) then using a password manager starts to make sense.
Re: South African bank advises against the use of password managers
#10For any customers that do use said bank, take this as an indicator of their own security practices and consider if you still trust them with your money, data and PII. I wonder how they share credentials without a PAM or similar. All service accounts are using 'S3cur3P@$$w0rdzSuck'... Or more probably just a 'passwordz'? What a shocking state of affairs.
I also agree with their statement for the most part. The general public, at least here in SA, aren't too discerning when it comes to tech matters who will probably download any random app from the play store. If you don't trust pretty much anyone with your credentials, why trust a probably unknown 3rd party with them.
I think the best idea in this case is to choose a strong password, try and remember it or write it down and store it in a safe.