Skip to content

Comment on South African bank advises against the use of password managers

Comments

Aren't password managers sacrificing security for convenience? Remembering hundreds of long unique passwords being the most secure, but too difficult. If you could remember everything then you would have an uncompromisable storage system.

Personally I use password managers for most things, but exclude them when money is involved and opt to remember those.

Aren't password managers sacrificing security for convenience?

It depends on what problem you're trying to solve / what's your threat model. The comparison is for realistic (imperfect) use of password manager vs what someone would do otherwise.

Nobody is likely to ever guess your bank password with online tries, so the likely scenarios are: protection from hashed credentials leak, and from another service leaking shared passwords. The tradeoff is your password manager bring possibly exploited. With the known frequency of each so far, no, it doesn't look like we're sacrificing security.

One of the security features that a password manager provides is retrieving passwords based on what domain you're on. They're a lot better than the human brain at making sure you don't get phished by an evil site that looks exactly like Gmail or whatever.

I'd like to believe I know better than that, but I see your point.

In a world where people have perfect, secure memories, sure.

We don't live in that world, and as such, a good password manager is the most practically secure method for the vast majority of folks.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.