Infosec has struggled with 'good is better than perfect' - where good advice that is practical for most people is criticized for not being perfect practice that is often impractical.
Thankfully, now that there is a lot more public awareness of infosec practices - driven in large part by there seemingly being a big infosec story every week - a lot of the best practices advice has been loosened towards the more practical.
In terms of password management, I agree with you completely - the default advice should be to use an online password manager. I've got my partner and most of my family using Dashlane and with near 100% unique password compliance.
That type of adoption with regular users would never have happen had I stuck to "keepass, diceware and 32 character unique passwords" level advice.
Comments
Infosec has struggled with 'good is better than perfect' - where good advice that is practical for most people is criticized for not being perfect practice that is often impractical.
Thankfully, now that there is a lot more public awareness of infosec practices - driven in large part by there seemingly being a big infosec story every week - a lot of the best practices advice has been loosened towards the more practical.
In terms of password management, I agree with you completely - the default advice should be to use an online password manager. I've got my partner and most of my family using Dashlane and with near 100% unique password compliance.
That type of adoption with regular users would never have happen had I stuck to "keepass, diceware and 32 character unique passwords" level advice.