On password managers

Photo of cat and computerCurious about password managers?  Computer guy Matt Bentley takes a look.

There are things called ‘password managers’, which, as the name suggest, store and manage your online passwords for the various accounts you have across the internet. Let’s go over these and why I find them less satisfactory than my favourite method, Writing Things Down. Don’t get me wrong, in the hands of a skilled user, password managers take the effort and stress out of dealing with the gazillion passwords and usernames/email addresses we tend to store with our various trusted internet services. But they come at a cost to the regular user.

Password managers generate a different password for each website. This is good and absolutely something that everyone should do. If someone breaks into, say, your facebook account, the first thing they will do is grab your email address from the facebook account and then try the facebook password for your email. And then they’ll usually lock you out of both. But let’s look at the way password managers generate passwords. They tend to generate non-memorable strings of numbers and letters that are effectively non-guessable in a rudimentary way. This is good, but it also makes those passwords impossible to guess for the end user, should they ever lose their access to the password manager, which is bad.

Password managers generally integrate into a web browser, thereby bypassing your need to run a special program to use them. This is good. However this also means that if you’re using someone else’s computer, or a public computer, you can’t use the password manager without logging into the password manager’s website and accessing your passwords that way. This is bad. Lastly, password managers and their hosts, while significantly improved over previous years, are not infallible. It wasn’t so long ago that one of them (Lastpass) got hacked and the master passwords for a whole mess of accounts got stolen. This didn’t rely on knowledge of the users’ passwords, just some basic internet security flaws.

In short: if you know what you’re doing and are more technically savvy, password managers like Lastpass and Dashlane can be a godsend, particularly if you’re logging into a ton of websites. But for the casual home user, they are probably overkill and have significant downsides. You’re almost invariably better off following basic security measures and (a) making a different password for each website (b) making long passwords that are easy for you to guess, but not anyone else, (c) Writing them down in a notebook with the name of the website, the username/email address associated with the account, and a date, and (d) enabling 2-factor (cellphone) authentication on every account you can.

  • Need help with your internet security? Phone Matt at 021 1348 576 or email: Photo of Matt Bentleyinfo@homepcsupport.co.nz
    $70 per hour, or $60 for drop-off-to-workshop services.
Share this page:
Share

N8N

Number 8 Network - a community website for the rural areas northeast of Hamilton, NZ, is run by Gordonton journalist/editor Annette Taylor.

Leave a Reply

Your email address will not be published.

%d bloggers like this: