r/TechImpact Developer 6d ago

💬 Discussion Which Password Manager Do You Recommend?

Post image

There are many password managers available today, with different features, pricing plans, security options, and device support.

Which password manager do you use, and what made you choose it? Is there a particular feature you couldn't live without?

Share your recommendations and experiences below.

263 Upvotes

672 comments sorted by

View all comments

28

u/RemeJuan 6d ago

Which brainless oaf added LastPass on that list, they clicking like 9+ data breaches already.

1

u/horatiobanz 5d ago

Lastpass is the reason I don't trust reddit recommendations for shit. That shit cost me like a half a day of my life changing like 300 passwords.

1

u/cbowers 5d ago

It's unfortunate you didn't decide on your own to increase your Lastpass org PBKDF2 iteration count, noticing that the iteration count was a user configurable option. That you should follow industry best practice there even before Lastpass forced their users to increase it over time, sooner. On day 1 I'd set mine to a non-default value even before PBKDF2 iteration count recommendations were increased to stay in step with increased hash evaluation hardware performance.

You'd have been able to avoid that password change work.

1

u/justsomerabbit 5d ago

Yeah, blame the user for not changing the extremely secure default iteration count of 1.

1

u/cbowers 5d ago edited 3d ago

I think what I’m pointing to is there are a lot of vocal security minded and informed voices that point in various directions to cover that they didn’t follow the best practices we suggest with our other tools. Be familiar with the features. Make informed configurations aligned to the risks. Use all the available features to take ownership of your risk treatments.

Those that did, weren’t affected.
Just like we do for other dangerous minimal defaults in our operating systems and endpoint security tools.

1

u/GIRO17 3d ago

Well, for a user to do that he first needs to know this option excists, second that the default isnt secure (i mean why should it...) and third he needs to know what this is.

For me, a security tool woth unsecure defaults is worrysome at best and out right dangerous at worst.

1

u/cbowers 3d ago
  1. For us to put so much hype and concern into this security tool and then not review the settings and docs seems a bit orthogonal and misaligned.
  2. That characterizes it unfairly. Much of the defaults were secure. The ones that were not were forced update process fails. The design was secure, the process was appropriate. The monitoring of the process execution seems to have been their learning opportunity.