# Password Managers: Do You Use One?

**URL:** <https://boards.straightdope.com/t/password-managers-do-you-use-one/933227>\
**Category:** In My Humble Opinion\
**Created:** [February 18, 2021, 2:05pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227 "2021-02-18T14:05:32Z")\
**Posts on this page:** 20\
**Page:** 4

<div class="post-metadata">

**Author:** ![erysichthon](https://avatars.discourse-cdn.com/v4/letter/e/d07c76/32.png) [@erysichthon](https://boards.straightdope.com/u/erysichthon)\
**Post date:** [February 19, 2021, 9:26pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/61 "2021-02-19T21:26:47Z")

</div>

> [@Kimera757](#):
>
> I don’t really know what that is, but it sounds like I need internet access to use it (which means less safe, IMO).

Authenticator apps don’t require an internet connection.

---

<div class="post-metadata">

**Author:** ![MrDibble](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mrdibble/32/114_2.png) [@MrDibble](https://boards.straightdope.com/u/MrDibble)\
**Post date:** [February 19, 2021, 9:34pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/62 "2021-02-19T21:34:45Z")

</div>

> [@erysichthon](#):
>
> It’s interesting that nobody in this thread has mentioned using an authenticator app,

I use that for sites that require it, but the site has to be set up to work with the authenticator, so it didn’t seem to speak to what the OP was asking. It’s not a replacement for general passwords.

---

<div class="post-metadata">

**Author:** ![brad\_d](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@brad\_d](https://boards.straightdope.com/u/brad_d)\
**Post date:** [February 20, 2021, 3:53am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/63 "2021-02-20T03:53:55Z")

</div>

I use eWallet, which seems to be a pretty minor player in the market these days. I’ve been using it for a very long time (at least 15 years), since back when I used a Palm PDA.

I’ve got literally hundreds of passwords stored in there, created using its random generator - I know only one or two of them from memory. I’m happy with its availability on both my Android phone and my PC (synching between them via Dropbox - their setup, not some hack I created).

I’m not in a position to meaningfully test the security, so I’m hopeful it’s adequate.

I’ve considered looking into other options, but fear that I’m subject to some flavor of vendor lock-in. There’s no way I’m retyping all of the info I have saved in there, so without a conversion utility it’s not happening - and eWallet’s relative obscurity may be working against me.

---

<div class="post-metadata">

**Author:** ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)\
**Post date:** [February 20, 2021, 4:38am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/64 "2021-02-20T04:38:01Z")

</div>

The ones I love are the recovery security questions: “When we asked you ten years ago, who did you say was your favorite singer?”

---

<div class="post-metadata">

**Author:** ![Enjoy\_Slurm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/enjoy_slurm/32/3937_2.png) [@Enjoy\_Slurm](https://boards.straightdope.com/u/Enjoy_Slurm)\
**Post date:** [February 20, 2021, 9:40am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/65 "2021-02-20T09:40:05Z")

</div>

Why are you picking questions you know you aren’t going to remember the answer to?

---

<div class="post-metadata">

**Author:** ![Wolf333](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf333/32/3460_2.png) [@Wolf333](https://boards.straightdope.com/u/Wolf333)\
**Post date:** [February 20, 2021, 11:19am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/66 "2021-02-20T11:19:32Z")

</div>

Security keys are different from password managers. Every site that I’ve tried still requires a password for initial setup, and passwords are not stored on the keys. There is a method to sign in with only the key, but see below.

Also, sites implement keys in different ways:

Google: The key is only a second factor. I log in with my user name and password, then touch the physical key. Twitter works the same.

Microsoft: I can log in with my password plus security key OR just use the security key plus the security key pin.

For all of the accounts for which I’ve configure my key, I still have to have a password to set it up in the first place. In the case of Microsoft, I also had to set up another form of authentication (app or SMS) first.

---

<div class="post-metadata">

**Author:** ![Wolf333](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf333/32/3460_2.png) [@Wolf333](https://boards.straightdope.com/u/Wolf333)\
**Post date:** [February 20, 2021, 11:21am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/67 "2021-02-20T11:21:52Z")

</div>

> [@erysichthon](#):
>
> > [@Kimera757](#):
> >
> > I don’t really know what that is, but it sounds like I need internet access to use it (which means less safe, IMO).
> 
> Authenticator apps don’t require an internet connection.

Just to add a little to this…

Apps that allow push notifications require an internet connection, but will usually also have a method that works offline.

---

<div class="post-metadata">

**Author:** ![FordPrefect](https://avatars.discourse-cdn.com/v4/letter/f/e99b99/32.png) [@FordPrefect](https://boards.straightdope.com/u/FordPrefect)\
**Post date:** [February 20, 2021, 4:53pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/68 "2021-02-20T16:53:59Z")

</div>

Another LastPass user here, I have been using the paid version for a number of years now. I like it, but it was even better on mobile before Android locked down the Accessibility features against apps like LastPass.

---

<div class="post-metadata">

**Author:** ![puzzlegal](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/puzzlegal/32/3827_2.png) [@puzzlegal](https://boards.straightdope.com/u/puzzlegal)\
**Post date:** [February 22, 2021, 5:37pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/69 "2021-02-22T17:37:10Z")

</div>

> [@jtur88](#):
>
> Passwords are bullshit. . What do I care if some Ukrainian stranger reads my email or IMDB or YouTube account or hacks into my access account to read my local newspaper. I use the same simple password for everthing, except the bastards who make me use at least one Cyrillic letter or change it every week.
> 
> I don’t even care if you know my bank password, because you can’t get in anyway unless they text you a code.
> 
> So, seriously, how does a “strong” password protect you.

Please don’t thread shit.

---

<div class="post-metadata">

**Author:** ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)\
**Post date:** [February 23, 2021, 3:52am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/70 "2021-02-23T03:52:11Z")

</div>

I think password managers are wonderful. I cannot think of any reason not to use them.

---

<div class="post-metadata">

**Author:** ![engineer\_comp\_geek](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/engineer_comp_geek/32/504_2.png) [@engineer\_comp\_geek](https://boards.straightdope.com/u/engineer_comp_geek)\
**Post date:** [February 23, 2021, 6:00am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/71 "2021-02-23T06:00:07Z")

</div>

**Moderator Warning**

> [@jtur88](#):
>
> I think password managers are wonderful. I cannot think of any reason not to use them

Acting like a sarcastic jerk is not the recommended response to a mod note. As our registration agreement says, “We have one guiding principle: Don’t be a jerk.”

This is an official warning for being a jerk.

---

<div class="post-metadata">

**Author:** ![PunditLisa](https://avatars.discourse-cdn.com/v4/letter/p/4af34b/32.png) [@PunditLisa](https://boards.straightdope.com/u/PunditLisa)\
**Post date:** [February 23, 2021, 1:59pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/72 "2021-02-23T13:59:47Z")

</div>

I have used RoboForm for eons. A couple of years ago, I took advantage of one of their Cyber Monday deals for 5 years along with an upgrade to RoboForm Everywhere, which gives me 5 licenses to use between my computer, tablets and cell phones. Changes synchronize to the new devices. Totally worth the $ I spent.

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [February 23, 2021, 4:40pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/73 "2021-02-23T16:40:45Z")

</div>

> [@jtur88](#):
>
> The ones I love are the recovery security questions: “When we asked you ten years ago, who did you say was your favorite singer?”

Yeah I’ve come to the conclusion that these can’t be reliably recalled, and I just pick oddball answers and write them down. Favorite teacher? Grunt. Favorite food? Basketball.

In effect they are really like backup passwords so I treat them that way.

---

<div class="post-metadata">

**Author:** ![echoreply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/echoreply/32/3641_2.png) [@echoreply](https://boards.straightdope.com/u/echoreply)\
**Post date:** [February 23, 2021, 6:16pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/74 "2021-02-23T18:16:41Z")

</div>

I use a command line random password generator and just paste in random text for each answer. Then I add them to the notes field on my password manager.

Recently I was asked one of the questions to verify me to my bank, and I answered, “let me spell my first pet’s name ‘papa uniform eight…’” The person on the other end of the phone was not upset one bit. Either I got it right so she didn’t care, or she’s encounters enough nonsense answers, that as long as it’s right, it doesn’t matter. No, “you really grew up on a street named ‘Quuic3ri’?” type comment.

---

<div class="post-metadata">

**Author:** ![Deeg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/deeg/32/2955_2.png) [@Deeg](https://boards.straightdope.com/u/Deeg)\
**Post date:** [February 23, 2021, 7:14pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/75 "2021-02-23T19:14:12Z")

</div>

This is the correct way to respond to those questions and they are easier to remember when one has a manager to store them.

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [February 23, 2021, 7:39pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/76 "2021-02-23T19:39:46Z")

</div>

Yes, I forgot to mention it could definitely be a bad idea for companies to know the real answers to your security questions, especially with all the data breaches that have happened.

---

<div class="post-metadata">

**Author:** ![Dag\_Otto](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Dag\_Otto](https://boards.straightdope.com/u/Dag_Otto)\
**Post date:** [February 23, 2021, 8:47pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/77 "2021-02-23T20:47:52Z")

</div>

I especially like it when a site lets you create your security question. When I can do that, I get straight to the point - my security question is : What is the security answer?

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [February 23, 2021, 9:51pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/78 "2021-02-23T21:51:10Z")

</div>

Well? What is it?

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [February 23, 2021, 10:16pm UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/79 "2021-02-23T22:16:03Z")

</div>

Forty Two

---

<div class="post-metadata">

**Author:** ![Dag\_Otto](https://avatars.discourse-cdn.com/v4/letter/d/439d5e/32.png) [@Dag\_Otto](https://boards.straightdope.com/u/Dag_Otto)\
**Post date:** [February 24, 2021, 12:45am UTC](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227/80 "2021-02-24T00:45:35Z")

</div>

Damn it!

[Previous page](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227.md?page=3)

[Next page](https://boards.straightdope.com/t/password-managers-do-you-use-one/933227.md?page=5)
