Do All The Data Breaches Make You Nervous about Your Password Managers?

Optus, Medibank, … and now LastPass password manager is rumoured to have been hacked as well.

Putting all passwords in one place on the cloud seems like a great temptation for the hackers to attack. Also, it's like putting all eggs in one basket, once you lose it you lose them all. This is the main reason I can't convince myself to use a cloud based password manager. Instead I only use a local based password manager on my phone and computers. I would like to hear the different opinions from the password manager users or non-users out there.

I also include a poll about which type of password managers everyone is using.

Poll Options

  • 221
    I use a cloud based password manager
  • 58
    I use a local (non-cloud) password manager
  • 50
    I don't use password manager at all
  • 16
    I only use the good old paper and pen
  • 14
    I just remember everything

Comments

  • +8

    So long as you're using a decent password for lastpass, it shouldn't matter if they get hacked. Assuming they're not just flat out lying about how they store data, it's all encrypted so even they can't access it (and therefore a hacker can't either).

    The concern is that if someone does get your encrypted password file, they have infinite time to try crack it. So if your password is somewhat weak as we see GPU power continue to ramp up they might be able to crack it a few years from now (which is why it's good to change passwords on important accounts regularly).

    I use a cloud one, although I probably should move to a security through obscurity move of a 'local' one that I host myself on OneDrive or AWS or something.

    • Good explanation.

      I use local password managers on all my local devices. No automatic sync beween them. I just sync them through manual file transfer from my phone. It's not the most convenient way but I feel more secure this way. Of course people can break in and steal my computers :)

      I used to spent some time doing security testings for a network device company. Whenever we connected our devices on to the Internet with a public IP and monitored the traffic, there were a lot of login attempts from foreign countries. The hackers out there must have automated their attacks. We also carried out tests with network penetration test suites. At the time, we just followed instructions and I often wonder if what we had done were sufficient.

      • +3

        Local is far easy to get for a hacker because it can be scripted via exploit, much harder to break into a commercial operation ;)

        • +4

          Meh, once a bad actor has direct access to your device you're stuffed no matter what methodology you're using.

          I see minimal (to the point of none) actual security advantage in manually syncing and a massive downside that you'll get caught out at some stage needing a new password on a device that you haven't synced and there's no way to access that password when you need it.

    • +2

      Add to that turning on 2FA for everything, including your password manager and I have zero issues with storing everything on a cloud password manager.

  • +22

    im not nervous because i use bitwarden
    https://bitwarden.com/help/security-faqs/

    • +3

      Mmmm, salted hash…

      • +1

        Yummy right? Just like Singapore salted egg fish skin crackers

    • +1

      +1 for Bitwarden. I’ve been self hosting it for years via nginx proxy manager, have a 20 character master password and 2fa enabled. Not worried at all.

      • Do you know if i can self hosting from synology nas, and then what happen if i am not at home? I dont set my syno to be accessible from outside

        • +1

          If it has Docker then yes. Vaultwarden is an open source server software (shows as Bitwarden and works with Bitwarden extension) with all features unlocked.

          When not home you can't add passwords but you can read them from your computer or phone's cache. I use OpenVPN to get into my network if I need to add a password.

          • @Void: Can we switch between vaultwarden and the official bitwarden anytime without need to add all the pass manually etc basically just click few buttons (just in case i dont like the own hosting way)

            • @CyberMurning: Yeah you can export and import vault. It's called Vaultwarden but aside from the admin page it's identical to Bitwarden, and even display itself as it.

  • +2

    This is the main reason I can't convince myself to use a cloud based password manager.

    Im with you.

    I've been looking at these things for 2yrs now… I just cant get my head around if someone DOES hack your account, they have your everything…

    The only secure PC is a stand alone one turned off… once on any network they can be vulnerable.

    Reminds me, need to order some more post-it-notes..

    • +2

      I just cant get my head around if someone DOES hack your account, they have your everything…

      This is the issue. I've used a locally hosted password manager for years and been very security conscious but the threat that I hadn't considered was my own family. One night I stayed at my uncles house and the piece of shit made a backup of my phone while I was asleep. He was looking for my cryto and didn't find it but as a bonus he got to read 15 years of my emails.

      • +1

        How did he do that? Which phone was it?

        • It was a Samsung Galaxy S4 with an unlocked bootloader. It's really easy to do a backup and then just restore it to a different phone of the same model.

    • The only secure PC is a stand alone one turned off

      Not if wake-on-lan is enabled…

  • +2

    Pats el trusty postit note

  • +2

    password123

    • +6

      Password123!

      Fixed it for you. :)

      • +4

        hunter2

      • P@55\/\/0RD123!

        Is this too much?

  • +1

    I use my little brown index book. Can be used for all systems.

    • True. Same as my wife :)

      • +7

        Your wife can be used for all systems?

    • +1

      And I bet you still have crap passwords in the "brown book" like plain worded with a number "Grips3972" or the name of a pet "f1dob0y" because you don't want to type out "a$7hJ$?hQ#9kZ(3" every time you use the brown book.

      My parents run an excel file, that isn't encrypted and is just plain text that they keep on their desktop that is full of the same passwords used over and over and over OR are just variations on that same password.

  • +1

    text file for me. contains all details every site knows about me

    • +4

      Any rogue app on your computer can read it, right?

  • +1

    KeepassXC as my main offline passwords storage. Can store/generate TOTP secrets too.
    iCloud Keychain for frequently used passwords (with a copy in KeepassXC). This autofills my passwords on MacOS and iOS.

    So I cannot tick both first poll options.

    • How that offline thing works? So if i am at the hotel overseas i can access them? So cannot even open my gmail then…

      • If you have your laptop with you, KeepassXC app and database are both files on your laptop. No internet needed.

        On Mobile, If you once used Strongbox (Keepassium) to open database, a copy is still on your mobile in iCloud files (Dropbox … ), and will open without internet.

  • LastPass password manager is rumoured to have been hacked as well

    LastPass has actually acknowledged the security incident. See Wikipedia entry which has links to related blog posts / articles. Also GoTo's response to security incident in November. GoTo is the parent company of LastPass.

  • +1

    I used different passwords for different websites/services. All my passwords are stored locally using KeepassXC, which I backup onto an external HDD.

    I also try to avoid using mobile apps that require logins/passwords. If I have to install an app, then depending on the app, I use fake information.

  • I use 1Password and I'm not concerned. You would have to get my 13 character password AND my 34 character secret key to get in. So even knowing how many character they are, and knowing what sort of character they can be, so that means 4.473650959253981e+25 multiplied by 8.2089012e+52 in possible passwords. Yeah I feel pretty safe. Even the latest quantum computers would take way too long to get that one.

  • +1

    I use a cloud based password manager

    Does that include just going to websites containing data breach dumps to get your username and password info as you need it?

    Also, the poll needs an option "password123 is easy to remember and I use it everywhere"

  • Hey @mokr , aside from your plain 'code' , please consider some Uppercase , numbers & special character symbols.

    Just so you don't have to remove your comment after revealing your password here.

  • +3

    Not worried in the slightest..
    I know the data is encrypted on my device before it's stored in the cloud.
    And I know my Encryption key is stupidly long, non-dictionary and therefore virtually impossible to be brute forced using foreseeable technology.

    • 1Password removed the local storage option with latest version, and forced subscription.

      "1Password 7 and earlier supported standalone vaults, which stored information locally on your device outside of a 1Password account. 1Password 8 requires a 1Password membership. " source

      • That is true, but it also irrelevant to the point.

        • post i was replying to was edited.

          • @nuker: I think maybe you replied to the wrong post as I don't believe my comment was edited.
            And if it was, I certainly never mentioned 1Password in the original version.
            I've never used 1Password or even considered using it.

            • +1

              @ESEMCE: yea, likely my mistake, peace brother

  • Are password managers free?

    I use a handful of passwords across different apps and sites but after the reaches I think I should make much more complex passwords but there’s no way I’d remember 10 x 50 alphanumeric passwords.

    I’m definitely paranoid about my accounts being hacked, if a hacker can breach my email and bank accounts they could easily change my details and steal my money.

    • +1

      Are password managers free?

      Yep Keepass (may want XC) is free, all you need is a dropbox/google drive and you can access it from your mobile.

      • I see, might have to look into using one finally…

      • Huh why need gdrive? Then what if someone hack our gdrive?

      • +1

        i recommend Strongbox as mobile app. On desktop it is vanilla KeepassXC, and database shared via any file sharing apps you have, like iCloud included in iOS.

    • +5

      Bitwarden is also free for single user, personal use.

    • +4

      Bitwarden is free.

      Signup now and go through every random online account you have and add into Bitwarden, changing to a newly generated randomised password.

      For email and bank accounts you can keep doing it the old way but make sure you are using a strong password - will be easier to just remember one or two of these though, and let Bitwarden worry about the rest for you.

      There is a browser extension so it can literally just fill in the password for you when you go to log into a website, it's great.

  • +1

    this digital id and economy thing is going great hey?
    cant wait to see what the future has in store!!!

  • +3

    Nah not worried. I write down all my passwords on paper and lock them up in a commercial-grade safe. I then place that safe inside a weatherproof box, buried at least a metre below the ground in my backyard. To make it harder, I placed a mat over the area and put my green, recycle and rubbish bin on top. #nevereverbetoocareful wahaha

  • +4

    It won't be the cloud-side that'll leak your passwords from your manager.

    It'll be the fact that you're still signed into Chrome on your PC whenever it eventually gets hacked and someone remotely logs in, or your PC is stolen, or similar. The weakest link in the security chain is almost always the user.

    Relevant XKCD

    • Hackers in Russia will have trouble kidnapping and torturing you though, especially without being caught.

      • But they won't need to, they'll just utilise our laziness.

        What's the use of a password that's 36 characters long for your banking, when your 10-year-old router still uses the default 'Telstra' username and password as a gateway to your entire network?

        Little point having a massive lock on your front door when your lounge window is open for the breeze.

        • Was just responding to your XKDC.

          I agree password managers are the best route for most people.

        • What's the use of a password that's 36 characters long for your banking, when your 10-year-old router still uses the default 'Telstra' username and password as a gateway to your entire network?

          I get what you're saying but that's a terrible example. Admin access to almost every consumer modem/router is only available on the LAN side (at least as default). It would need some sort of unpatched vulnerability to be able to log in from the internet side. FAR more likely to be breached from a device inside the network due to insecure practices by users of the network.

          • +1

            @banana365: Yeah, definitely an inaccurate example - I was just trying to give a broad example that most people would be familiar with.

            Just trying to make the point that the password manager itself won't be the attack surface that the OP is worried about!

    • All true. I switched to incognito /Private browsing as default. When you close tabs, all cookies and tokens gone. Logging back in is easy with autofilled passwords.

  • +1

    Cyber attacks are the next COVID: https://www.weforum.org/videos/a-cyber-attack-with-covid-lik…

    It's a fear campaign designed to trick the whole world into a global digital ID to track your carbon emissions as part of a social credit score ;)

    • …hey! that sounds like it would be handy for future pandemics too!!!

  • +2

    Even if you don't 100% trust cloud based password managers, do yourself a favor and start using one for every online account that is non-critical. Bitwarden is great.

    You can keep doing your banking, gmail, facebook etc the old way

    But man it makes life so much easier to have all the rest in one secure and easy to access place.

  • +1

    If all of iCloud gets hacked then my passwords will be the least of my worries while society collapses.

  • With CBA now touting a credit report for any bot that asks for.
    So all banks know all about you and can tease you and send you bankrupt.

    Please fill out the consent form and place in recyle bin. We had all your info anyway we just had to make it legal!

  • there should be one more poll option: "I use same password everywhere" :D

  • If the dimwits in charge of security at Optus, Medibank Private etc had designed my password manager I'd be worried.

  • Needs another poll option: I'm not worried because I use a password manager with a ubikey, so I won't be the weak link.

    As others have said, if the password manager company gets hacked, they should have controls in place to make use of hacked password data extremely difficult to use.

    • You'd hope all (I know Lastpass and Bitwarden do) do not have any unencrypted password information. Both platforms do client side encryption of data, so the only thing the hackers get is your general account information.

      As for the Optus / Mydeal / Medibank hacks, these were all done by infiltrating the company, not the end user. Whether you have the same password for all sites, have a little black book or use a password manager, you're as likely to be victim as much as the next person.

      The greatest thing a password manager does is make it (nearly) impossible to fill in credentials for a forged website. That, and not using 'correct horse battery stable' as the password for every site you have an account on.

      • That, and not using 'correct horse battery stable' as the password for every site you have an account on.

        But, but, I was told that was secure! I know, I'll stick '99' on the end and she'll be right.

  • Been using keeper for years

  • -2

    It's not hard to keep one or two complex passwords in your head(or on paper) that you use for banking and email, they need to be rock solid and changed frequently. 99% of everything else can be just that password you used when you were 10, with some variations.

    And don't store any bank card details on browsers, once it's out of your hands it's vulnerable.

  • +1

    Anyone know the pros and cons of a dedicated password manager or just using the one that's just what Google offers?

    The Google one basically works off any app on my phone via the Google keyboard and obviously any chrome browsers. Seems safer to me than having to install extra apps for another password manager everywhere?

    • People will say they don't trust the Google one, because google. But it's no different to any other one. As long as your Google account is secure with 2fa and your recovery methods can't be hacked into as well.

  • I'm keen to gain a better understanding. When people say "cloud-based" they're referring to a service like Lastpass where they maintain a copy of your (encrypted) password file, which is then synchronised and decrypted on whatever client device you're using, right?

    I've heard some mention using their own self-hosted password file e.g. using Bitwarden, on yet another service like Dropbox or OneDrive. (How) is that more secure?

    I'm willing to give up a little security for the sake of convenience, but would like to know what the compromises and risks are.

    • +1

      My understanding is that if it's stored on Bitwarden's cloud, then attackers have a single point to try and compromise, where everyone's password files, including yours, is kept.

      But if you self-host, then they won't know where your encrypted file is. But it's a lot more hassle. Even I can't be bothered with this, and I use to work in web hosting.

      • Thanks.

  • What do people think of android apps having access to your clipboard, for example if you copy paste passwords on your phone?

    • Apple gives you a prompt when an app is trying to paste from the clipboard. Handy when you were clearly going to do that anyway but sometime it pops up when just opening an app which makes you feel suss on that given app.

  • +1

    None of the breaches make me nervous because I don't publish my password manager to the cloud: https://www.passwordstore.org/

  • Cloud based or stored locally. What matters the most is how you secure your password vault. I’d highly recommend securing your vault and any other service that accepts it with U2F (e.g. a yubikey). Note this method works in conjunction with a password.

    It’s would not be feasible to decrypt anything without the physical key and password.

    If you’re super keen you can get a biometric yubikey.

  • I don't use a password manager so I'm not concerned about it at all.

  • I was using Lastpass, but moved to Keychain when I moved from LineAgeOS to iOS. I’ll likely be moving from passwords to passkeys when they are more widely accepted on websites.

  • I'm more likely to forget a password, than get hacked. But i know both may happen so I have 2FA on for all bank accounts etc.

    Im using vaultwarden, after using Roboform for years. I thought I may as well host it myself, and it's free too.

    It's a balance between paranoia and usability…

  • +2

    I used to be like you, OP, and only used a local password manager, which was KeePass, as I was paranoid.

    But after doing a lot of research I've recently switched to Bitwarden, mainly for convenience, a nicer interface and user experience. Though I still keep my banking credentials in KeePass. I feel that's a good compromise.

    • +1

      Good to hear I am not alone :) I guess we should just do what we feel is safe after sufficient research.

      The poll so far shows more than 50% use a cloud based password manager…

  • Diggity….

    People still happy with BitWarden??

Login or Join to leave a comment