Earlier quoted context omitted.
Not in one "basket".
Why not? The thing is that your argument is just not compatible with real life. Humans are humans, they are absolutely not going to create unique and strong passwords for every service. What happens in actuality is that they create one or two okay passwords, then reuse them, which is 100,000x worse than using a password manager. The promise of a password manager is you get infinite perfect passwords. Perfectly long,…
Password managers less secure than promised
81–87 of 87 posts
Re: Password managers less secure than promised
#82That's why KeePass is still the king. Offline vault > online vault.
KeePassXC can even still be online, too; example: https://logandark.net/passwords.kdbx It's not centralized, of course; you still have to download the entire database, and then potentially upload the entire database again for any changes; but it doesn't have these vulnerabilities.
And I was queasy of hosting mine on Dropbox.
Re: Password managers less secure than promised
#83Earlier quoted context omitted.
KeePassXC can even still be online, too; example: https://logandark.net/passwords.kdbx It's not centralized, of course; you still have to download the entire database, and then potentially upload the entire database again for any changes; but it doesn't have these vulnerabilities.
The database is encrypted, so theoretically it doesn't matter if other people have it, but what a chad. I suppose these are not your real passwords, or are low-value ones, because there could be zero-days we don't know about. And I was queasy of hosting mine on Dropbox.
I tuned the encryption to take a short while to unlock for even a high-tier desktop CPU, to the tune of slow password hashes. I actually somewhat enjoyed the delay every time I opened up the database...
Re: Password managers less secure than promised
#84Earlier quoted context omitted.
The database is encrypted, so theoretically it doesn't matter if other people have it, but what a chad. I suppose these are not your real passwords, or are low-value ones, because there could be zero-days we don't know about. And I was queasy of hosting mine on Dropbox.
A bunch of them have changed since I migrated to iCloud Passwords, but no, that is an actual real passwords database with every internet account of mine that I knew about as of around December 2024. I tuned the encryption to take a short while to unlock for even a high-tier desktop CPU, to the tune of slow password hashes. I actually somewhat enjoyed the delay every time I opened up the database...
Re: Password managers less secure than promised
#85Earlier quoted context omitted.
What clients are you using ? Trying syncthing with synctrayzor with my windows boxes and Synctrain on my iPhone and it’s mostly alright but still a little spotty.
I'm also using Synctrayzor on my Windows 10 machine. I'm on Android using the official Syncthing app there as well as on Linux. It sometimes takes a while for them to discover each other, and it of course works better when all the devices are on my home network. The only real problem I've encountered is when filenames have special characters another OS doesn't like.
Re: Password managers less secure than promised
#86Earlier quoted context omitted.
Not in one "basket".
Why not? The thing is that your argument is just not compatible with real life. Humans are humans, they are absolutely not going to create unique and strong passwords for every service. What happens in actuality is that they create one or two okay passwords, then reuse them, which is 100,000x worse than using a password manager. The promise of a password manager is you get infinite perfect passwords. Perfectly long,…
Re: Password managers less secure than promised
#87Earlier quoted context omitted.
Your argument is flawed. And you know it. For a starter, one gold bar there is around 12.5 kgs.
It doesn’t perfectly map, but it gets a visual point across. I cannot be convinced that it’s better for the average person to maintain a couple permutations of a primary password for a hundred different sites than it is for them to store it in a vetted and audited password manager. Even with the vulnerabilities mentioned in the paper you are far better off with a password manager and thus 100 fully unique passwords t…