Best password manager?

Author
Discussion

TonyRPH

12,996 posts

169 months

Wednesday 13th February 2019
quotequote all
ZesPak said:
davek_964 said:
Although I understand the sentiment that somebody needs to pay for these things or they wouldn't exist (and I have paid for the full version of plenty of apps) I'm not sure what payment for Lastpass would give me. The premium features don't seem to be anything I'd actually use.
I use it from a lot of machines and locations, which always sends me an email to verify the machine/location. 2 factor would be a major help for example.
I'm using the free version, and I have a Lastpass app on my phone, and each time I log in I have to approve it, so you don't need to pay to get 2F auth?

ZesPak

24,439 posts

197 months

Wednesday 13th February 2019
quotequote all
TonyRPH said:
I'm using the free version, and I have a Lastpass app on my phone, and each time I log in I have to approve it, so you don't need to pay to get 2F auth?
That's my issue, at the moment I have to verify the location and device by email activation. I would prefer to have it in the authenticator app or something.

TonyRPH

12,996 posts

169 months

Wednesday 13th February 2019
quotequote all
ZesPak said:
That's my issue, at the moment I have to verify the location and device by email activation. I would prefer to have it in the authenticator app or something.
That's what I meant? I have the authenticator app?

Or do I misunderstand you?


davek_964

8,850 posts

176 months

Wednesday 13th February 2019
quotequote all
Mr Pointy said:
Well one of them is Emergency Access. I don't know what arrangements you have made to allow access to your accounts should you die or be incapacitated but not having password access in those situations can be a big issue.
I work on the principle that I'll be dead, so not something I need to worry about! wink

bitchstewie

51,633 posts

211 months

Wednesday 13th February 2019
quotequote all
ZesPak said:
The main thing I dislike about lastpass is that they really want you on a paid subscription (login is cumbersome and the like), but I find it too expensive for my use now. I see that 1password is even more expensive.
I get it, but cup of coffee every month or have faith your sensitive information is secured properly? smile

LeoSayer

7,315 posts

245 months

Wednesday 13th February 2019
quotequote all
I've used 1Pass for a few years on Android and PC synched via Dropbox.

I don't know how I managed without it - over 100 login details stored. Well worth the small amount I paid for the licence and app.

Maybe there are better ones out there but I'm very happy with 1Pass.

Mr Pointy

11,303 posts

160 months

Wednesday 13th February 2019
quotequote all
davek_964 said:
Mr Pointy said:
Well one of them is Emergency Access. I don't know what arrangements you have made to allow access to your accounts should you die or be incapacitated but not having password access in those situations can be a big issue.
I work on the principle that I'll be dead, so not something I need to worry about! wink
Well true, but there's plenty of accounts that it would be incredibly helpful to be able to access by whoever is clearing up the mess you left behind. This bloke's widow wishes he had:

https://www.theregister.co.uk/2019/02/05/cryptocoi...

jesusbuiltmycar

4,539 posts

255 months

Wednesday 13th February 2019
quotequote all
ZesPak said:
TonyRPH said:
I'm using the free version, and I have a Lastpass app on my phone, and each time I log in I have to approve it, so you don't need to pay to get 2F auth?
That's my issue, at the moment I have to verify the location and device by email activation. I would prefer to have it in the authenticator app or something.
I use the free version of LastPass with Authy (which is compatible with Google Authenticator - bot use TOTP).

See:
https://www.lastpass.com/multifactor-authenticatio...
https://www.reddit.com/r/Lastpass/comments/8vofjh/...

ZesPak

24,439 posts

197 months

Wednesday 13th February 2019
quotequote all
TonyRPH said:
That's what I meant? I have the authenticator app?

Or do I misunderstand you?
Doh! Just found the options regarding 2 factor.
I could have sworn I was looking for them and it looked like they were behind a pay wall.

Penelope Stopit

11,209 posts

110 months

Wednesday 13th February 2019
quotequote all
Buttercup

Mr Pointy

11,303 posts

160 months

Wednesday 13th February 2019
quotequote all
Penelope Stopit said:
Buttercup
Bird's Foot Trefoil

boyse7en

6,772 posts

166 months

Wednesday 13th February 2019
quotequote all
Can someone give me a brief outline of how these things work in practice?

I'm getting swamped with passwords for everything and sometimes struggle remembering them between my phone, iMac, Windows 10 laptop and work's PowerMac.

Do these store passwords in the cloud so they can be retrieved, or are they stored on a device somehow?

How are these apps better than writing them into a documents and saving them on my phone? (I'm not saying they're not, but struggling to get my head around how they are more secure)

anonymous-user

55 months

Wednesday 13th February 2019
quotequote all
I use keepass. I have it save the encrypted password file on drop box. That way I have only one password file and it is accessible at all times on all devices. Android tablet, android phone, and windows desktop and laptop. And it's free.

ashleyman

6,996 posts

100 months

Wednesday 13th February 2019
quotequote all
boyse7en said:
Can someone give me a brief outline of how these things work in practice?
I used to have mine listed out in a notepad document. I have a different random password for every single website all generated by strongpasswordgenerator website. Remembering them is impossible so I would just copy/paste them into the password field from the document.

Obviously anyone who has access to the document can look and then have passwords for everything. Using a password manager keeps the passwords safe and secure.

It works well because now when I go to log into a website the password manager will tell me if it has a password saved and then I can use it to log in. No need to remember passwords so they will instantly be more secure and no need to copy or paste either. If you have multiple accounts for a site then you can save them all and pick the account you want to use.

It also means if you use a mobile device or multiple computers all your passwords are saved and accessible wherever you are so long as you have the password manage installed.

You basically just need to remember 1 password - the password to the manager, everything else can be forgotten.

tog

4,552 posts

229 months

Wednesday 13th February 2019
quotequote all
boyse7en said:
Can someone give me a brief outline of how these things work in practice?

I'm getting swamped with passwords for everything and sometimes struggle remembering them between my phone, iMac, Windows 10 laptop and work's PowerMac.

Do these store passwords in the cloud so they can be retrieved, or are they stored on a device somehow?

How are these apps better than writing them into a documents and saving them on my phone? (I'm not saying they're not, but struggling to get my head around how they are more secure)
They will generate random passwords for you, store them encrypted in a cloud service somewhere, sync them between devices and browsers, and fill them in for you as required. Some will let let multiple users (teams / families for example) share all or some passwords as required and let you control who has access to various subsets of details.

Some will also store payment details and other secure notes and documents.

I've used one for years, and as a result have different, long, passwords for every site so if one site suffers a data leak the same email username remains unaffected on other sites. I only need to remember my password for 1Password, but its a good idea to at least know your email password too.

Mr Pointy

11,303 posts

160 months

Wednesday 13th February 2019
quotequote all
boyse7en said:
Can someone give me a brief outline of how these things work in practice?

I'm getting swamped with passwords for everything and sometimes struggle remembering them between my phone, iMac, Windows 10 laptop and work's PowerMac.

Do these store passwords in the cloud so they can be retrieved, or are they stored on a device somehow?

How are these apps better than writing them into a documents and saving them on my phone? (I'm not saying they're not, but struggling to get my head around how they are more secure)
They generally fall into two camps & which you prefer depends on your level of paranoia. One stores your usernames & associted passwords in an encrypted database on a local device, say a USB key, or you can store it somewhere like Dropbox. Others store this database on their servers in the cloud, but also have a local copy. Generally they are cross platform so you can access the same passwords on your Windows PC (& probabaly Linux), an Android phone, an iPhone etc. You have one master password you need to remember to access the database (you can link your fingerprint scanner to it as well) & you can supplement this with various forms of 2FA: I use a Yubikey with NFC.

You don't need to cut & paste anymore: the password app auto-fills the fields for you.

Secondary functions are auto-generation of very secure passwords, storage of pdfs, & sharing with other family or team members plus a few others. If you lose your PC or phone you can generally use another device to access your store & log on to do stuff like email, cancel cards etc (if you use a cloud based service).

Generally look at Lastpass, 1Password & Keepass & have a play to see which suppports the level of cross-platform working you need. They all have free trials.

Funk

26,330 posts

210 months

Wednesday 13th February 2019
quotequote all
I'm another one who settled on LastPass. Does everything I need and more and in the grand scheme of things it's very inexpensive.

extraT

1,774 posts

151 months

Tuesday 13th August 2019
quotequote all
Thread revival

After resetting what must be the 20th password, I’ve had enough, giving in and getting a password manager.

If I list what I need, will someone be kind enough to recommend a manager ( from what’s I’ve read, it will be lastpass anyway, but you never know...)

- both mine and my wife’s accounts
- multi device/browser
- can connect to phone to recover accounts if necessary
(Not necessary but could be important) autogenerated passwords/ a way to recover it autogenerated password goes belly up...)
-other things that I’ve possibly not thought of...!

Is lastpass still king?

Thanks

ET.

bitchstewie

51,633 posts

211 months

Tuesday 13th August 2019
quotequote all
I don't think the list has changed that much, I still wouldn't look beyond LastPass or 1Password.

Mr Pointy

11,303 posts

160 months

Tuesday 13th August 2019
quotequote all
I wouldn't say Lastpass is king, but it will do most of what you require. It stores the encrypted list on the Lastpass servers (& a local copy) so if you want to keep your database locally then look at Keepass (although I'm not sure how good is it's integration with phones etc). Look at 1Password as well, both have free trials so you can see which you prefer. Think about using 2FA such as a Yubikey or similar.