OK. #PasswordManager: I have been told (yes... by @jonny ) that I should use one. 🔐 I am still a bit reluctant: isn't there a risk that the password manager itself gets hacked? How do they work on multiple devices? Do you need internet to use them, what if you're offline? What if you forget the main password and then loose access to all your accounts? I'd like to know if any of you had any of these problems with a password manager, and also which one do you trust the most? 🙏
@jonny@elduvelle Hi, I use Cozy Pass for every online account, and I just generate a random passphrase for offline passwords (FDE, login password, passwords manager, etc.)
The vault is zero-access and encrypted with my passphrase, they hire notorious crypto-paranoid activists with strong opinions about e.g. the way some crypto functions in Python are coded in C, so I think I'm safe from a leak in general and from my vault being brureforced in particular. On the upside:
1. I've sent my social security password to a homeless man once by accident, but nothing happened because it was changed in about 5 minutes. I wasn't going to update every account I could recall, which would've taken, without taking breaks, more than 10 hours.
2. The single best reason to use a passwords managers is that you can create accounts everywhere. You don't have this feeling of guilt for using an insecure password anymore, because you don't, so you may try any small-scale service provider you want. Because there's no cost in creating an account, there's zero cost in deleting it either; you can become more demanding about the nature of a web page as a resource for example.
In case something got cracked, I'm satisfied enough with my YubiKey for MFA, it's just a shame that my bank won't accept regular OTP-based authentification. It's super convenient; I may replace regular passwords, for anything else than zero-access encryption or emails, with pin codes and just press a button.
If you're willing to pay ~$130 for a hardware passwords manager, go for it but don't rely on it against a State-level threat model.