• jmlakar 69347 - Friday, March 9, 2018 1:03 PM

    I don't agree. Password managers are so much better than people's inherent lousy passwords (and their reuse). To say that because there exists a small chance your PW MGR will be leaked so don't use it is "throwing the baby out with the bath water". If anyone asks if they should use a password manager the answer should be a resounding YES.

    The risk with password managers is that they exist as encrypted files, which can be decrypted with a rememberable passphrase. If someone gets to copy that file (not at all a rare thing) they can throw unlimited resources at it... and it's valuable enough to try that because it has so much of a person's security inside. By comparison, stealing your password from a corporate hack, assuming you don't re-use passwords, compromises only one thing. 

    Multiple attempts normally will shut down a network account, but a captured file has no such protection.

    ...

    -- FORTRAN manual for Xerox Computers --