Dashlane's Super Bowl ad proves password managers have arrived
wired.com
wired.com
I can teach my parents how to use one of the more user-friendly ones, like Dashlane or 1Password, and it works great much of the time.
But for some percentage of sites, for a variety of reasons, the standard steps don't work: non-standard web forms, Javascript games, browser updates, obscure password rules, just to name a few common issues. For non-technical users, these issues are blockers -- indistinguishable from show-stopping bugs from a UX standpoint.
Since using a password manager really needs to be an all-or-nothing proposition in order to get into the habit of using it 100% of the time, this means that most users will not use one.
I'm sure the commercial managers will get better at addressing some of these over time, but I do not see a product that works flawlessly 99.9% of the time emerging anytime soon.
Anecdote: I was doing my periodic visit with my grandmother, where I tend to any overdue computer/software maintenance, resolve any questions she has, install new things if needed (i.e. someone got her a printer which she likes to use for printing photos, but it was still in the box.)
As we were going through some things, she didn't know her password for everything; she had a notebook, but it wasn't organized enough. Eventually we figured out or reset each password as needed. (She only has a few total!)
Part of me wanted to utilize a password manager; after all we could use some proper long, randomly generated ones! But I was there on the fence of... what happens when she's stuck and I'm not sitting next to her to help?
To be sure, I have about a billion online accounts. I use unique email addresses and passwords (and a password manager) so I don't really hesitate to create accounts that aren't asking me for any real information about me. And along with that, I come upon the edge cases where if you're using Firefox for Android and Bitwarden, the web site some how goes out of its way to ensure that I will end up having to type in a super complex password (or close my browser tab and walk away). My grandmother almost certainly won't hit those same edges cases. She's got email and one social media account and that's just about it. And she'll need to write down that one mega password for the password manager, and learn some new things.
So I'm not sure if it's right for her. Definitely a consideration, though, and to your point, sometimes I get angry and wish there were consequences for the companies that work so hard to break things like password managers on their web sites and in their software!
(Insert obligatory XKCD on relative complexity)
... Gee, it sure would be nice if all sites simply allowed long-length passwords without bizarre, mutually-incompatible special character requirements.
At least the 2017 updated NIST guidelines swung back sane (less complexity requirements, 64 character maximum). So in... a couple decades we'll be able to reliably use long passwords.
I just got a new TV and wanted to sign into my Amazon Prime account. Unfortunately for me, that meant I had to enter my 32-character numbers/lowercase/uppercase/symbols Amazon password using the TV remote. I did not get it the first time.
A few months ago I got a new iPhone. They wanted me to type in my iCloud password so that all my settings and data could transfer automatically to the new phone. Similar results.
I agree though, it's pretty bad once you hit those edge cases.
One nice thing with apple tv or an android box is you can typically use your phone as a remote keyboard for inputs and have access to the password manager from there. Works pretty decently with the apple remote app.
All we need now is a couple viable first-factor implementations in browsers and major sites, and WebAuthn can start to take over. It's really, really unfortunate that WebAuthn has been a W3C recommendation for almost a year now and yet no major browsers have integrated WebAuthn into their credential sync system so it can actually start to be used as a password alternative.
(insert "but why?" meme)
All I want from a password manager is to securely store a list of passwords. That's it. Add in copy/paste functionality, and I'm all set.
I don't want to pay a monthly fee just to store a KB or two of data.
Set a super long generated password on your bank account and then need to log in on your phone? That's a pain if you're just using KeepPass on your desktop.
That said using an encrypted storage file and an existing file sync service (Dropbox, Box.net, Onedrive, GDrive) and a client that supports using such a file would solve the problem, and I think 1Password at least supports this.
Sure. We could all evangelize some esoteric command line FOSS system, but the general public NEEDS secure password management
You are giving a centralized 3rd party identifying information about you because of the subscription, control over your passwords because of the updates and you have to believe and trust it's never going to deny you access even without payment, issue an update to steal those passwords or be hacked by someone who does the same or hacks you through it. Oh, and they can do all the surveillance capitalism business models since they have access to the websites you visit.
Sure, you could put the money in your safe at home, but security always has tradeoffs.
Also there are definitely results when you search for “standalone” in the support section, including the link I had in my comment.
Now all of that aside -- the 1Password funding round was oriented around selling to businesses and the investments needed to run hard at that. It costs money to build a business that's competitive in that B2B market but businesses can provide healthier / less jumpy revenue streams, which is good for a business like 1Password.
That said, $200M seems crazy. You don't need that many employees for a password manager. How much of that is going to just end up being funneled to Google/FB via ads, as often happens with these raises.
Security is like investing, don't use what you don't understand. (At least at a high level.)
Why would it be a hassle? It should be trivial to switch password managers. Do some not allow you to export or import data?
This brings up another question: How can VCs justify $200 million in funding for businesses with essentially no customer lock-in?
Once you have a password manager you're happy with, why would you ever switch? Dashlane works fine, I do export all my passwords once or twice a year in case the sync process ever goes wrong and deletes a bunch of my data, but even with the ability to easily switch I see zero reason to ever consider alternatives.
I’m not sure why TFA says it would require resetting all passwords, but to answer your point, not all password managers have the same features. For example, Bitwarden doesn’t have enough structured types to accommodate things like software licenses, WiFi passwords and other things. When you import such data into it from another password manager’s export, all this data will be in some broken up jumbled format that’s not easy to use or is probably incomplete.
For simple website logins though, every password manager should be interchangeable with another through export and import features.
Since I’m an Apple user I would love to use their keychain but if I want that consistency in my browser I need to use Safari and I prefer Chrome.
If I was an Android user I guess I would get the Chrome keychain by default in my android device, but not making that switch just for a password manager.
I also have 1Password at work and personal 1Password but I don’t use it anymore because I have found that is pretty easy to save passwords to my work vault which apparently will be completely lost if I ever separate from my company.
So now I’m forced to consider something like Dashlane to get the cross environment experience but then again it will probably be very broken.
Basically passwords are the most terribly user experience that you need to deal with.
It’s like having to go and do your necessities before the toilet existed. It probably was wildly uncomfortable and inconvenient.
Someone needs to invent what’s toilets are to shit, because the password experience is just that shitty.
You could actually get whatever you want, PW managers can register themselves as one system-wide (at least in newer Android versions).
Edit: Nevermind. I see it now. I need to explore this. It just that it can’t be 1Password for the reasons mentioned above. Any good alternative that someone can recommend?
but I'm a happy customer for 5 years because of a killer feature : the ability to share passwords with my wife across our desktop and laptops, for all the websites we need to access both (from library to utilities, official websites, kids schools, etc, etc)
The benefits of strong secure password use more pervasively are overall good.
https://www.passwordstore.org/
Add in a GUI and you're set.
My browser extensions are really minimal, HTTPS Everywhere, Privacy Badger, react dev tools. The browser is the modern operating system, and in general you should reduce your surface area as much as is reasonable.