Best password manager?

Author
Discussion

Lim

2,274 posts

44 months

Sunday 21st February 2021
quotequote all
colin79666 said:
Filling in fields without user input is actually a bit of a security risk. It has been found to fill in hidden form fields and therefore details can be stolen (at least in theory).

It is only 2 clicks to populate with Bitwarden.
Does it actually fill in the real data? I had assumed it was some kind of proxy placeholder until you submit. If not that does sound dodge yes.

How certain?

colin79666

1,848 posts

115 months

Sunday 21st February 2021
quotequote all
Lim said:
Does it actually fill in the real data? I had assumed it was some kind of proxy placeholder until you submit. If not that does sound dodge yes.

How certain?
Unsure if they every fixed it, I just turned the feature off.

https://www.theregister.com/2017/01/10/autocomplet...

Lim

2,274 posts

44 months

Sunday 21st February 2021
quotequote all
colin79666 said:
Unsure if they every fixed it, I just turned the feature off.

https://www.theregister.com/2017/01/10/autocomplet...
Jeez.... disabled, thanks!

I just assumed it was so slow, because they couldn't be so lax to prefill the actual data, and something clever was going on.....

Edited by Lim on Sunday 21st February 10:10

extraT

1,777 posts

152 months

Sunday 21st February 2021
quotequote all
I’m genuinely shocked the overlords at Google haven’t developed a dedicated password manager outside of Chrome. They must have the encryption tech, surely for them, it should easy? Hell, they know just about everything else about everyone on the planet!

colin79666

1,848 posts

115 months

Monday 22nd February 2021
quotequote all
Anyone else who has switched off the LastPass browser extension noticed how much faster general web page loading is now?

Did a little Googling and it appears to be a common problem due to the amount of extra JavaScript it injects into pages.

Terminator X

15,229 posts

206 months

Monday 22nd February 2021
quotequote all
Write them on a bit of paper? Fairly sure the hackers can't get hold of it wink

TX.

Tye Green

674 posts

111 months

Monday 22nd February 2021
quotequote all
It seems those who use password managers have huge trust in those that provide the service

Turn7

23,744 posts

223 months

Monday 22nd February 2021
quotequote all
Tye Green said:
It seems those who use password managers have huge trust in those that provide the service
you have to, obvs.....

IMHO, using a "reputable" PM offers the best security, other than writing down stupidly complex PW;s.........andthen what happens if you get burgled and thye find your list ?

Given the amount of logins we all need now, I suspect its almost impossible to maintain strong and very different PWs'.

Funk

26,354 posts

211 months

Monday 22nd February 2021
quotequote all
Tye Green said:
It seems those who use password managers have huge trust in those that provide the service
The National Cyber and Security Centre says you should be using one - and they're right. Even more so when the password manager is secured with 2FA etc as well.

https://www.ncsc.gov.uk/blog-post/what-does-ncsc-t...

In fact anyone NOT using a password manager of some sort is highly likely to be more at risk due to chronic password re-use or ones that are susceptible to brute force/dictionary attacks. A password manager allows you to have a single, unique and strong password for every site you use. If you want one run locally without a third-party involved then yes, you can do that but even cloud-syncing ones like LastPass don't store anything in a way that can be decrypted in the cloud - all decryption is done on the device.

You are MUCH more secure with one than you are without, despite your brain trying to tell you the opposite.

xeny

4,431 posts

80 months

Tuesday 23rd February 2021
quotequote all
Tye Green said:
It seems those who use password managers have huge trust in those that provide the service
Not necessarily. I use keepass, so nothing in the cloud.

The computer's firewall doesn't allow keepass to access the internet, and has never logged an attempt to access the internet.

Unless it starts printing notes with my passwords and posting them, I'm reasonably relaxed.

zedx19

2,779 posts

142 months

Tuesday 23rd February 2021
quotequote all
Thanks to those that suggested Bitwarden, together with the link on how to export from Lastpass and import to Bitwarden. Took minutes, seems to work great, just the same as Lastpass but without the costs. I've enabled two factor on Bitwarden as well.

Lim

2,274 posts

44 months

Tuesday 23rd February 2021
quotequote all
As a lifelong user of lastpass until a few days ago, having researched the company, I will now evangelically discourage anyone who will listen to give them up .

ZesPak

24,450 posts

198 months

Tuesday 23rd February 2021
quotequote all
Lim said:
As a lifelong user of lastpass until a few days ago, having researched the company, I will now evangelically discourage anyone who will listen to give them up .
Was planning on it this afternoon, but can you elaborate?

Lim

2,274 posts

44 months

Tuesday 23rd February 2021
quotequote all
ZesPak said:
Was planning on it this afternoon, but can you elaborate?
Basically this YC thread.

https://news.ycombinator.com/item?id=21172569

But to be fair, I'm not informed enough to verify the more speculative comments on their privacy policy, so I should probably reign in my evangelicalism.

Can anyone more informed confirm?

The speed stuff is more easily verified. I just tested my browser speed with speedometer.

Lastpass - 79.4
1password - 117
No password manager - 132

Don't have bitwarden but from benchmarks, I guess it would be in the 120s

Perhaps it is all legit, but I'm not going to sift through the privacy policy to find out, when it's so easy to export.

Edited by Lim on Tuesday 23 February 12:06

davek_964

8,902 posts

177 months

Tuesday 23rd February 2021
quotequote all
xeny said:
Not necessarily. I use keepass, so nothing in the cloud.

The computer's firewall doesn't allow keepass to access the internet, and has never logged an attempt to access the internet.

Unless it starts printing notes with my passwords and posting them, I'm reasonably relaxed.
Does that mean you can only use it on one device though?

ZesPak

24,450 posts

198 months

Tuesday 23rd February 2021
quotequote all
davek_964 said:
Does that mean you can only use it on one device though?
When I used keepass many moons ago that was the case.


Moved my entire lastpass to Bitwarden. I use the google stuff for most of it so it's a bit redundant. I do have some extra notes though.

dapprman

2,350 posts

269 months

Tuesday 23rd February 2021
quotequote all
KeePass has just the one file, but if you want to you can keep it on cloud storage and access it from there. My key file is in my dropbox account and accessed from my PC, laptop, phone (android) and old tablet (iPad). You can go two factor with a key file and potentially host that on another cloud account.

xeny

4,431 posts

80 months

Tuesday 23rd February 2021
quotequote all
davek_964 said:
Does that mean you can only use it on one device though?
Depends - I actually run three databases - one is on a machine with no remote access and is to the really high value credentials - broker passwords and the like. Another is on a machine I can remote to, and if need be can go with me on an encrypted USB stick, or encrypted on my phone with a local keypass app.

Things like a PH password lives in one drive, but obviously MS simply see it as another file to sync.

stemll

4,133 posts

202 months

Wednesday 24th February 2021
quotequote all
Mr Pointy said:
Well Bitwarden has turned out to be a disappointing bag of crap for me. I've downloaded the Firefox extension, logged in & gone Settings/Tools/Import & it just opens up the Import help web page, with no further dialogue box to select the .csv file to import. If I click on Export it opens up another dialogue but of course there are no sites in the vault. For some reason it also thinks it's entitled to close the bookmarks sidebar & open up it's own sidebar instead.

ste.

Right, it seems the fktards who wrote this software didn't bother to explain that you can only import when you're logged into the website, not from the browser extension.


Edited by Mr Pointy on Wednesday 24th February 17:04
So that will be the help web page that says

To import your data into a personal Vault:
1. Log into the Web Vault

where the words Web Vault are a link to the login page?
Seems pretty clear to me

Mr Pointy

11,360 posts

161 months

Wednesday 24th February 2021
quotequote all
stemll said:
So that will be the help web page that says

To import your data into a personal Vault:
1. Log into the Web Vault

where the words Web Vault are a link to the login page?
Seems pretty clear to me
Click on the browser icon. It says Log In to your vault. Not a crippled version of your vault.
Click on the browser icon. Go Settings/Tools/Import. It doesn't work. Nor does it tell you why it doesn't work.