Community
Wiki Posts
Search

Password manager

Thread Tools
 
Search this Thread
 
Old Jul 13, 2019, 2:41 pm
  #16  
 
Join Date: Aug 2014
Programs: Hyatt Explorist; Hilton Gold; Marriott Ambassador; Delta PM; United Silver; Global Entry
Posts: 99
Another vote for Dashlane here.
duhe is offline  
Old Jul 13, 2019, 3:51 pm
  #17  
 
Join Date: Jan 2003
Posts: 3,785
I have been using LastPass for a while, but I just want to give a warning about the password to Lastpass: Make sure you remember it. I remember mine because I type it to log in every day. But I set one up for my wife where she just left it logged in on her laptop browser. It was fine until the laptop dies... I put in a hint that was so cryptic that I can't even figured out what it was. And you cannot recover the password unless you have a browser that was used to connected to Lastpass, and her computer died. It doesn't matter if you have control of the email that registered with the account, you won't be able to recover the password. We were lucky because I finally able to find the password that I have stored on my computer.. took lots of digging. I think if you have a paid account, you could set up a recovery method or something, but you have to do it ahead of the time.
Need is offline  
Old Jul 13, 2019, 9:29 pm
  #18  
 
 
Join Date: Nov 2000
Location: Upcountry Maui, HI
Posts: 13,311
Can't you just store the wife's password as one of your passwords in your lastpass data?

-David
antichef and Stgermainparis like this.
LIH Prem is offline  
Old Jul 14, 2019, 12:54 am
  #19  
 
Join Date: Jun 2005
Location: London
Posts: 610
I have been happy with Bitwarden, plus it's free.
678flyer is offline  
Old Jul 14, 2019, 8:39 am
  #20  
 
Join Date: Feb 2011
Location: Virginia
Posts: 110
I have a Keepass file that I manage on my computer, store on two different cloud services, and download to my phone. I get all the benefits of password security without being tied to a service/fees.

The main downsides are that there is some manual uploading/downloading of the file, and that passwords don't get automatically entered in my browser.
GregLeg likes this.
STVA is offline  
Old Jul 16, 2019, 10:36 pm
  #21  
 
Join Date: Oct 2001
Location: Pittsburgh, PA
Posts: 324
Originally Posted by STVA
I have a Keepass file that I manage on my computer, store on two different cloud services, and download to my phone.
I do something similar. I use KeePass and sync my encrypted file to my Google Drive. I feel pretty confident about the security of my Drive (very strong password, and 2FA is set up with a YubiKey). Even in the unlikely event of a breach, the KeePass file itself is encrypted (with another, and very different) strong password.
GregLeg is offline  
Old Jul 19, 2019, 12:03 pm
  #22  
 
Join Date: Apr 2019
Posts: 63
Originally Posted by 678flyer
I have been happy with Bitwarden, plus it's free.
Same here. Plus, it's open source.
jamcoley is offline  
Old Jul 21, 2019, 3:46 am
  #23  
 
Join Date: Apr 2014
Location: Hertfordshire, UK
Programs: SQ,CX,LX
Posts: 343
1Password for me too. Customer service/support is very responsive and first class, I've been a user for several years now mainly with Imac, MacBook Pro, iPhone and Android tablet.
Igene likes this.
Lussac is offline  
Old Jul 21, 2019, 6:55 am
  #24  
 
Join Date: Nov 2006
Programs: Seniors Bus Pass
Posts: 5,529
Originally Posted by LIH Prem
Can't you just store the wife's password as one of your passwords in your lastpass data?

-David
I have an envelope sealed in a safe with the necessary details stored in case I croak it, and my executor who will need it has the safe details.
antichef is offline  
Old Jan 12, 2024, 12:28 pm
  #25  
FlyerTalk Evangelist
 
Join Date: May 2006
Location: DTW, but drive to/from YYZ/ORD
Programs: Chase Ultimate Rewards 2MM, Diner Club points
Posts: 31,911
If you have 2FA for an account, what additional security is provided by using a password manager?
how do you manage password managers on multiple devices
rufflesinc is offline  
Old Jan 12, 2024, 2:47 pm
  #26  
 
Join Date: Apr 2022
Programs: AA: EXP Delta: DM
Posts: 61
Originally Posted by rufflesinc
If you have 2FA for an account, what additional security is provided by using a password manager?
how do you manage password managers on multiple devices
Most sync via the cloud
Igene is offline  
Old Jan 12, 2024, 2:49 pm
  #27  
FlyerTalk Evangelist
 
Join Date: Nov 2002
Location: ORD
Posts: 14,231
Password managers make it trivially easy to use a unique random password on each website. That way people can't use a password from your account on a compromised website, on a new website where you may have used the same password (as most people do). Therefore they won't even get as far as getting a MFA prompt.

Multiple devices depends on the password manager. If you use something like the Apple password manager it will work seamlessly on iPad/iPhone/Mac but nowhere else. Chrome's password manager works only on Chrome. But other third party ones (1Password, Lastpass, Keepass, Bitwarden etc) also work seamlessly when you install them. I use 1Password on my iDevices with the 1Password app, and on Chrome with the Chrome extension.
Igene likes this.
gfunkdave is offline  
Old Jan 12, 2024, 2:52 pm
  #28  
 
Join Date: Apr 2022
Programs: AA: EXP Delta: DM
Posts: 61
I'm a solid 1Password user.. I've tried them all.

I did look at Dashlane, their attachment implementation is horrible. In 1Password, I can create an entry for my Passport, with all fields and I can actually link an image of my actual passport to that same record, such a novel concept! Dashlane keeps documents in their own section.

Bitwarden looks like Windows 3.1, horrible UI and requires a paid sub for attachments, so at that point you lose the "it's free" data point
Bitwarden does not support passkeys on mobile devices
Bitwarden does not support password auditing in the app, only on website. Checks for dupes, weak passwords, lists sites that can use 2FA and passkeys
LastPass is a security nightmare

I'll add.. since this is a forum for travelers, 1Password includes unique vaults that can be put in a "travel mode" so they will not appear in your 1Password app.. if you were to have sensitive material, you could put them in one of these vaults to avoid inspection. I've never been too concerned, but I do keep a vault for my business and my mother's details. They are not accessible on my phone when traveling. if I need them, I can use a browser and re-enable them when I am at my destination. Bitwarden does not have this functionality

I don't mind paying for a service that works for me, hands down 1Password is my best solution.

Last edited by Igene; Jan 12, 2024 at 3:17 pm
Igene is offline  
Old Jan 12, 2024, 2:57 pm
  #29  
 
Join Date: Apr 2022
Programs: AA: EXP Delta: DM
Posts: 61
Originally Posted by antichef
I have an envelope sealed in a safe with the necessary details stored in case I croak it, and my executor who will need it has the safe details.
Same..

I use the 1Password emergency kit, as you, in a sealed envelope in a safe.
Igene is offline  
Old Jan 13, 2024, 12:12 pm
  #30  
 
Join Date: Jan 2015
Posts: 2,918
Originally Posted by rufflesinc
If you have 2FA for an account, what additional security is provided by using a password manager?
how do you manage password managers on multiple devices
So 2FA/MFA is just a component as is a password manager. Depending on if you are a target and the resources the attacker has/needs, 2FA can be rendered ineffective. For example, someone can clone your phone (if the site uses SMS as the MFA authentication) or maybe access your email (another popular MFA authentication method). Having a longer (randomly generated) password for each site provides a time benefit for you especially if your MFA token has been compromised. Depending on your password manager, you can also control the level of encryption you desire (eg, KeePass allows you to have a master password + keyfile + windows login... overkill yes, but it's there)

Many web-based password managers sync via cloud. Personally I use KeePass which is not (by default) web-enabled. I manually sync my password whenever I make a significantly change in the DB (this also encourages me to make backups). But I also do this out of paranoia as a breach of the PW manager site is virtually impossible (cloud based say that their DBs can't be breached but you never know).

Originally Posted by Igene
I'll add.. since this is a forum for travelers, 1Password includes unique vaults that can be put in a "travel mode" so they will not appear in your 1Password app.. if you were to have sensitive material, you could put them in one of these vaults to avoid inspection. I've never been too concerned, but I do keep a vault for my business and my mother's details. They are not accessible on my phone when traveling. if I need them, I can use a browser and re-enable them when I am at my destination. Bitwarden does not have this functionality
While travelling internationally, I usually put my password DB into an encrypted container (also contains scans of my passport and other documents) that doesn't have an extension so it's much harder to find and extract. I can also put this encrypted file in one of the cloud storage providers (like OneDrive or Drive or whoever) or copy it off of my home computer once I am at my destination if need be without worrying.
StuckInYYZ is offline  


Contact Us - Manage Preferences - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service -

This site is owned, operated, and maintained by MH Sub I, LLC dba Internet Brands. Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Designated trademarks are the property of their respective owners.