Anything that gets them to use unique, strong passwords for everything vastly improves their general security, even if they are using a third party, commercial organization.
1. Have people manage their own secrets storage? Most people don't have the time or ability do this securely either. I'd rather pay someone else to secure infra, code, distribution, encryption, backups, etc. for me.
2. Reuse the same password on every site? One site gets hacked and now you're screwed.
3. Memorize a unique, long password for every site? Not feasible.
Third-party/commercial password managers are the best solution for most people, practically speaking.
Crypto keys are great but you can lose them and once shared they are keys to you kingdom.
Specific security devices are great but you need to remember to have them with you. They can get lost or broken so you need backups.
Google authentication is convenient but they can ban you. It is also a 3rd party to trust.
Passwords suck but might be the best of the worst. Advantages: password managers can be used to make password useless for other sites and people conceptually understand it.
It is quite a hard problem!
Obviously doesn't work for many sites cause people are still convinced passwords are good.
The main ways people are hacked are re-use of passwords and writing passwords down. If someone gets access to one of my passwords, trying it in other sites won't work. If someone finds the written parts of my passwords, that won't work either as they would need to know the secure part of the password that I memorize. I can even easily take the written part of my password with me if I want to use a password on a different computer.
The only issue with this technique would be if someone finds multiple passwords of mine, they might be able to figure out the scheme and brute force other passwords, but if someone already has multiple passwords of mine and is taking the time and effort to go after me individually then I figure I am probably screwed any which way.
The general population is not going to setup their own open source password manager solution. So going with an easy to use commercial password manager is better than not using one at all.
that's why it's baffling. The convenience is outweighed by the possible loss.
People get their credential compromised via shared passwords way more than compromises of Lastpass or Chrome or 1Password. Sure, it's a bigger risk if your manager is compromised, but for most people it's as much "eggs in one basket" as people only having one bank account which is probably true of nearly everyone.
it's even worse than that. The world's most common password is... password.
What's interesting on these lists is the presence of Dragon and Monkey - am I mistaken or is it due to CJK users entering a Chinese character that got translated somehow? Wouldn't that mean some of the most popular passwords out there are single unicode characters? Surely not...
[1] https://en.wikipedia.org/wiki/List_of_the_most_common_passwo...
Do you really think that’s safer?
U2FsdGVkX19mCN0qo7cyA5EfxgVqPQkygGlHqNgv1jM=
Guess it and post here and I'll supply you with the username