What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.
What I found was a lot of people made security assumptions and never revisited those assumptions. Or never fully did.
I appreciate that KeePassXC has a feature to audit your passwords (Database -> Database Reports -> Health Check), which tells you which of your passwords are weak / should be changed.
https://keepassxc.org/blog/2020-08-15-keepassxc-password-hea... for more details (the threshold for "good" has since been bumped from 65 -> 75). The score corresponds to bits of entropy, with penalties for things like password reuse.
(It also has HIBP integration if you want to perform a one-off check that none of your important passwords have been compromised.)
My point is that if your password manager allows you to readily identify which of your passwords are insecure / have been compromised, that's a very useful tool to revisit any previous security assumptions you may have had.
BUT… this never mattered if you used a strong master pass phrase.
8 hasn’t been the recommendation in quite a long time.
I pushed Lastpass to my company in 2017, made everyone use 24 char.
The LP hack was bad, but I wasn’t worried for any of our people.
Do people actually memorize that?! If so, I strongly suspect that these pass phrases have much less entropy than 24 truly random characters would allow.
I trained people for 5 word pass phrases with no BS.
They were free to spice them up if they like. In 6 years I have had zero password reset requests.
That's about as much as a 12-character truly random case-insensitive alphanumeric password without special characters (log2(36^12) = 62).
> In 6 years I have had zero password reset requests.
What do you mean by that? This can mean that either your scheme is secure, or that nobody has ever attacked it (or you haven't found out that it did happen).
[1] https://crypto.stackexchange.com/questions/62597/calculating...
Now… get 80 people to remember a 12 char randoms.
No resets means no one has forgotten their pass phrase. I can not be just explaining passphrases to you now.
But also, spicing a pass phrase up is huge and not just a few bits more entropy. You go from 24 chars that are 5 word options to 24 char almost completely random again.
Sure, there's nothing in the TOS contractually obligating them to do this - but starting a low level awareness campaign to warn people with passwords that haven't changed in years about this risk seems like an easy thing to do that a (in keeping with the theme) "security minded" company should be enthusiastic about doing.
You can't nanny everyone, but surely if you're paying for a password manager you'd appreciate these kinds of notices.
Rate of change seems like a very poor signal compared to absolute password strength, which won't change over time. Isn't this already built into lastpass?
I started using 1Password in ~2010, not long after the founding of LassPass, and my first master password was 30+ characters, 90+ bits of entropy. After a few years I upgraded to 50+ characters, 140+ bits of entropy. Good luck cracking that even if only one round of PBKDF2 is used.
But I suppose you have a fairly loose definition of "security-minded".
One supply chain attack.
One upstream dependency.
One contractor clicking one wrong button in an office document.
Your entire digital life compromised, in that one click.
Based on history, if you store a password in a obfuscated location on your computer, and you copy and paste it into every websites, its more secure then using a password manager in my opnion. Sure you wont be able to login to every secure websites from every device you have; but SHOULD you be? What is the price of that convience?