Website name | account name | password | Date last changed | Notes (check qs and additional login info)
I am doing this for my 80yo mentee.Paper is safer imho. I'd love to take him to a password store but he's ipad and integrations are poor. The built in Keystore is fine: he just forgets which ones he's reused. Chrome does good checks if you love Google.
2FA needed. I wish it wasn't SIM/txt but for now it's all I can reliably get him to apart from Apple "check trusted device"
Distinct pw per account is increasingly vital. Seniors have shitloads of risk in their pension banking and related.
Or go the whole hog and m of n it
The actual question is why haven't we solved authention in a way that would work for most people? Passwords suck. Webauth sucks. Two-factor sucks more than you can ever imagine. There isn't a way to authenticate that wouldn't suck for normal people (apart from password-less one-time sessions but those don't solve most auth problems).
That said, what's wrong with the time-tested way of Post-IT notes? No, it's not secure but it's one of the only ways that actually works with normal non-autistic people. Or like @ggm said above, a paper with login codes attached to their fridge with magnets. It just f*cking works.
Thanks for pointing that out - I don’t mean all 50 year olds struggle with this problem. I guess it is more accurately described as a solution for parents that are depending on their kids/others to give advice/guidance on digital stuff.
The issue with the paper system comes in when they sign up for new things on mobile and they don’t have the paper at hand. It also becomes messy for password changes. And now that we are trying to force them to use unique passwords per service, the list becomes really long! Especially if it is for both parents. Across banking, utilities, social media, paid television, ecommerce, ebooks, etc they have at least 35+ accounts to manage each. They also struggle with their vision which means it needs to be written out in quite large font.
But the main issue I have actually is beyond password management. It is perhaps better classified as general digital security and online identity management. For example, if they use the paper password system I know for a fact they will snap a picture as a backup if I don’t tell and remind them not to do so…
The other issue with the paper system is that there is no good backup. And backups they certainly need!
I totally agree that authentication is general is not solved.
I think sometimes they also write passwords in the Notes app. I think that's in case they use their home computer instead of their iPhone.
I had a similar issue with my parents.
The most common problem is signing up for new services on their phone. On their Windows computer, in a web browser, their password manager's browser extension is great at suggesting generated passwords and saving new accounts. But on mobile it takes a few steps and app switches, which they don't love (and one parent forgets and often has to go to the other for help).
Logins are usually well integrated (my family uses iOS, and Dashlane; I assume 1password works just as well)
He used to manage fine when he could use the same password for everything but alas those days are gone.
Funnily enough I had to hack into his account last week since he was locked out and the only way back in was a phone call to the bank which I was able to make and answer every question required for a reset. It was basically standard name address and date of birth stuff.
Seems to work well for them.