Best to just use a password manager and keep unique per-site passwords.
Best to just use a password manager and keep unique per-site passwords.
Of course, it's a different situation when e.g. managing many sensitive servers which you only access from work or so.
True, though your handful of passwords can be stolen in the same way.
With a password manager, you:
- ensure your master password is not transmitted over a network
- ensure you never reuse passwords
- ensure you have long, strong passwords everywhere
- never forget login details and never worry about remembering yet another password
On the other hand,
- you _need_ access your password manager in order to login
- you now have a single point of failure
- cloud-based password managers are very attractive targets for hackers
I don't like these aspects of it.
Still, a password manger is incredibly convenient and I do feel a greater sense of security/confidence when I copy a big old 64 character password to log in. As it is, I use so many different services (gmail, github, slack, aws, steam, dropbox, reddit, etc, etc) and that number is only going to increase. I think a password manager is a practical, scalable solution to both remembering login information and improving my security.
I don't have to deal with password managers, maintaining their files. Or deal with multiple passwords.
Password managers are horrible - Whenever I change machines, I could never remember all my passwords and I certainly don't want to store my passwords in the cloud.
1Password can sync locally which is a nice plus:
But you're not. You're storing an encrypted blob in the cloud. You just need a good master password and a password manager that isn't broken.