Now multiply the privacy/security implications of that when said company is pumped and dumped by a major VC.
Now multiply the privacy/security implications of that when said company is pumped and dumped by a major VC.
> consider the fact that the threat model for a cloud-based password management solution should start with the vault being compromised. In fact, if password management is done correctly, I should be able to host my vault anywhere, even openly downloadable (open S3 bucket, unauthenticated HTTPS, etc.) without concern. I wouldn't do that, of course, but the point is the vault should be just that -- a vault, not a lockbox.
Pick a good password, pick good algorithms, and you should feel very comfortable about hosting an encrypted blob of data anywhere. Maybe you should worry a little if you're at risk of being specifically targeted by the NSA, but I doubt they've seriously broken any state-of-the-art crypto. At that point OS exploits and trojans are your real concern.
Especially because for the vast majority, the other strategy is going to be reusing the same password ~everywhere and if you're lucky the might use a special password for their bank or something.
I would say a notebook is worse than a password manager. It's not strictly worse in every way, but on the balance it's not a hard choice.
A notebook is better than most other not-a-password-manager solutions though. So it has that going for it.
If your notebook is destroyed (e.g. dog eats it, fire, water damage, et al) then all your passwords are gone. With most good password managers you can actually backup and store a copy of your vault data locally.
I really should have her write out a few key passwords and put them in an envelope for me to keep.
Sure, you need to know how to log into your email, but that isn't any more passwords to remember than the password manager master password.
I don't rely on just that, but between the reset flows and the browsers built-in password store, I don't really see what I gain by adding an external point of failure.
I mean, a browser "password store" _is_ a password manager. It's just usually not a very featureful one.