# please explain password managers for me

**URL:** <https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721>\
**Category:** Factual Questions\
**Created:** [March 22, 2015, 11:06pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721 "2015-03-22T23:06:19Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![psychonaut](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/psychonaut/32/4655_2.png) [@psychonaut](https://boards.straightdope.com/u/psychonaut)\
**Post date:** [March 23, 2015, 4:40pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/21 "2015-03-23T16:40:10Z")

</div>

> [@](#):
>
> How do other people do this?

Ideally you’d find a single password manager that features synchronizing (or remote storage) and works with all the devices you normally use. Failing that, if there’s one device which you use primarily, and the others you use only for a small number of websites, then you could install and use the password manager on the main device, and then just manually remember and enter your passwords on the other devices. (That is, your use of a password manager on your main device doesn’t affect the accessibilty of websites on other devices that don’t have it. You just don’t benefit from its ability to remember your passwords.)

---

<div class="post-metadata">

**Author:** ![Implicit](https://avatars.discourse-cdn.com/v4/letter/i/6a8cbe/32.png) [@Implicit](https://boards.straightdope.com/u/Implicit)\
**Post date:** [March 23, 2015, 4:48pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/22 "2015-03-23T16:48:51Z")

</div>

> [@jharvey963](#):
>
> One thing I’m not clear on: I use PCs for home and work use, but I also have an iPhone and iPad. I can’t see using a password manager only on the PC, since I sometimes want to open password-protected sites on my IOS devices.
> 
> How does this work? I don’t want to add a whole bunch of complexity to opening up sites on one architecture or the other.
> 
> How do other people do this?
> 
> Thanks,  
> J.

LastPass has apps for your iPhone and iPad, it’s not only for PC browsers.

I chose LastPass because when I was looking it was the only one that worked across all the platforms I was using (iOS and both a PC and a Mac). Others may do this now.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [March 23, 2015, 5:08pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/23 "2015-03-23T17:08:23Z")

</div>

> [@Doughbag](#):
>
> My choice of password manager is a piece of paper - it surprisingly works very well.

Speaking as someone who has a lot of clients that use this system - it sucks.  
If the notes are handwritten, the passwords rapidly become unreliable - Capital letters get switched with lowercase, spaces are misplaced, 1’s look like l’s, etc, etc.

It’s also unsearchable.

Once you have a few hundred passwords and logins, it becomes a nightmare.

---

<div class="post-metadata">

**Author:** ![Donnerwetter](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@Donnerwetter](https://boards.straightdope.com/u/Donnerwetter)\
**Post date:** [March 23, 2015, 5:44pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/24 "2015-03-23T17:44:21Z")

</div>

I store my passwords in a simple text file which I encrypt with [GnuPG](https://www.gnupg.org/). Not as comfortable as a password manager, but very straightforward and I have total control.

---

<div class="post-metadata">

**Author:** ![Northern\_Piper](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/northern_piper/32/5304_2.png) [@Northern\_Piper](https://boards.straightdope.com/u/Northern_Piper)\
**Post date:** [March 23, 2015, 5:54pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/25 "2015-03-23T17:54:40Z")

</div>

> [@jz78817](#):
>
> Free Software evangelism has nothing to do with the OP’s question.

_Au contraire_, I specifically asked what security there was against hacking and if some were better than others.

The answer, “proprietary, so trust us,” raises different concerns than “open source, tested by computer geeks with no personal financial stake”. I fund that discussion is relevant to both my questions.

Thanks for all the answers, everyone. I’m finding it very interesting (to the extent I can follow it).

---

<div class="post-metadata">

**Author:** ![The\_Joker\_and\_the\_Thief](https://avatars.discourse-cdn.com/v4/letter/t/e79b87/32.png) [@The\_Joker\_and\_the\_Thief](https://boards.straightdope.com/u/The_Joker_and_the_Thief)\
**Post date:** [March 23, 2015, 7:29pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/26 "2015-03-23T19:29:55Z")

</div>

> [@Northern\_Piper](#):
>
> _Au contraire_, I specifically asked what security there was against hacking and if some were better than others.
> 
> The answer, “proprietary, so trust us,” raises different concerns than “open source, tested by computer geeks with no personal financial stake”. I fund that discussion is relevant to both my questions.
> 
> Thanks for all the answers, everyone. I’m finding it very interesting (to the extent I can follow it).

But he’s right. Open source software isn’t necessarily more secure, and blanket support for it is more of an ideological position than a technical one. Many people, including me, would like for open source code to be intrinsically more secure. But it just isn’t so.

> [@](#):
>
> “I’ve done a lot of work on this, there’s no objective evidence either way. On average, good open source is about as good as good proprietary, and [bad] about as bad as bad proprietary,” [said Levy](http://www.zdnet.com/article/six-open-source-security-myths-debunked-and-eight-real-challenges-to-consider/), “technical director with the CESG, a department of the UK’s GCHQ intelligence agency that advises UK government on IT security.”

If it makes you feel better, the mathematical algorithms used by 1Password to encrypt data are open source and widely used. You can read more about the encryption for 1password used [here](https://learn2.agilebits.com/1Password4/Security/1P4-security-changes.html) – I assume something similar exists for other managers.

---

<div class="post-metadata">

**Author:** ![psychonaut](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/psychonaut/32/4655_2.png) [@psychonaut](https://boards.straightdope.com/u/psychonaut)\
**Post date:** [March 23, 2015, 7:50pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/27 "2015-03-23T19:50:35Z")

</div>

> [@The\_Joker\_and\_the\_Thief](#):
>
> But he’s right. Open source software isn’t necessarily more secure, and blanket support for it is more of an ideological position than a technical one.

True, but I also never claimed that free software is necessarily more secure. I said only that it is possible to verify that a given free software program is secure, whereas with proprietary software you have no such possibility.

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [March 23, 2015, 8:55pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/28 "2015-03-23T20:55:45Z")

</div>

> [@psychonaut](#):
>
> Yes, but for some people it may not be convenient. If you use multiple computers (say, one at home and one at the office), then you need to remember to take your paper with you all the time, or else you need to keep a separate copy in each location and keep them synchronized. Also, if you use a large number of websites, then organizing the list is a chore—either you record the websites in the order you register an account there, in which case it can take you a while to find the site’s entry later, or you keep the list in alphabetical order, in which case you can’t really use a single piece of paper but need something with lots of space, like a booklet.
> 
> Electronic managers can solve these problems by organizing and synchronizing your passwords for you, and may have other benefits such as suggesting secure passwords (or at least detecting and warning against cryptographically weak ones), and automatically filling in login fields when you visit websites.

Convenience has a big price, and that price is security.

Maybe not a big deal for your SDMB account but probably a big deal for work and personal finance accounts.

---

<div class="post-metadata">

**Author:** ![Hershele\_Ostropoler](https://avatars.discourse-cdn.com/v4/letter/h/e47c2d/32.png) [@Hershele\_Ostropoler](https://boards.straightdope.com/u/Hershele_Ostropoler)\
**Post date:** [March 24, 2015, 3:10am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/29 "2015-03-24T03:10:03Z")

</div>

One thing KeePass has done for me is lowered the cost\*of using unique high-entropy passwords. So I don’t tier logins the way I did before I got it, with one password for all the stuff I designated low-risk or low-worry, and something else for e-mail, and something else for banking\*\* etc.

\*In effort and memorization  
\*\*Not that I’m all that worried about that right now, but it’s the principle of the thing.

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [June 16, 2015, 1:20am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/30 "2015-06-16T01:20:24Z")

</div>

> [@Northern\_Piper](#):
>
> But isn’t that dangerous? because if it gets hacked, all your passwords are there, ready and waiting. 😕

Ooops. It looks like that may have happened:

[Password storing company LassPass is hacked.](http://money.cnn.com/2015/06/15/technology/lastpass-password-hack/index.html)

Hackers stole the encrypted passwords and other information.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [June 16, 2015, 1:35am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/31 "2015-06-16T01:35:20Z")

</div>

> [@filmore](#):
>
> Ooops. It looks like that may have happened:
> 
> [Password storing company LassPass is hacked.](http://money.cnn.com/2015/06/15/technology/lastpass-password-hack/index.html)
> 
> Hackers stole the encrypted passwords and other information.

It remains to be seen if that data is useful. If the encryption is as strong is they claim, it is essentially uncrackable.

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [June 16, 2015, 1:42am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/32 "2015-06-16T01:42:53Z")

</div>

> [@beowulff](#):
>
> It remains to be seen if that data is useful. If the encryption is as strong is they claim, it is essentially uncrackable.

If they have the data and are any good at decryption, it is only a matter of time.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [June 16, 2015, 2:56am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/33 "2015-06-16T02:56:44Z")

</div>

Why not just use Chrome or Firefox’s built-in password manager and sync? With Chrome it works across all devices, and you can encrypt it with either your Google credentials or a separate passphrase. It’s a lot simpler than any third-party solution. I imagine Firefox’s works similarly.

If your browser is hacked you’re fucked anyway, and realistically only big companies like Google have the resources to defend against ever-evolving security attacks. And if Google does get hacked, your data will be just one person’s out of several hundred million, both giving you time to react while nefarious actors dig through the huge pile and making front-page news so you’ll know about it. If some random third-party plugin gets hacked, you’ll likely never even hear about it until it’s way too late.

TL;DR: “In Google We Trust” makes life a lot simpler.

* * *

> [@control-z](#):
>
> If they have the data and are any good at decryption, it is only a matter of time.

If they don’t have the keys and the data is properly encrypted, “matter of time” is either several billion years or at least several decades for quantum computers.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [June 16, 2015, 4:47am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/34 "2015-06-16T04:47:49Z")

</div>

> [@beowulff](#):
>
> It remains to be seen if that data is useful. If the encryption is as strong is they claim, it is essentially uncrackable.

Contrary to what **psychonaut** said, LastPass is not a black box and it’s simple to see that it [works as they describe](http://blog.tinisles.com/2010/01/should-you-trust-lastpass-com/). They use standard SHA hashes and AES encryption. The important bits of LastPass are _effectively_ open-source because they are in JavaScript, and therefore in plaintext and easily readable by anyone that wishes to do an audit.

I use LP and am not worried about the break. I considered it inevitable, really. As long as you have a strong master password, brute-force attacks are simply not a problem.

---

<div class="post-metadata">

**Author:** ![beowulff](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/beowulff/32/542_2.png) [@beowulff](https://boards.straightdope.com/u/beowulff)\
**Post date:** [June 16, 2015, 4:53am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/35 "2015-06-16T04:53:48Z")

</div>

> [@control-z](#):
>
> If they have the data and are any good at decryption, it is only a matter of time.

A long time.

---

<div class="post-metadata">

**Author:** ![kanicbird](https://avatars.discourse-cdn.com/v4/letter/k/5f8ce5/32.png) [@kanicbird](https://boards.straightdope.com/u/kanicbird)\
**Post date:** [June 16, 2015, 10:45am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/36 "2015-06-16T10:45:09Z")

</div>

> [@Senegoid](#):
>
> …  
> It can only be hacked by someone who physically enters my home. And anyone who enters my home probably isn’t looking for passwords to steal.

Unless they hack your computer/smartphone camera or your drone and fly it over to get a peak

---

<div class="post-metadata">

**Author:** ![psychonaut](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/psychonaut/32/4655_2.png) [@psychonaut](https://boards.straightdope.com/u/psychonaut)\
**Post date:** [June 16, 2015, 11:48am UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/37 "2015-06-16T11:48:54Z")

</div>

> [@Dr.Strangelove](#):
>
> Contrary to what **psychonaut** said, LastPass is not a black box and it’s simple to see that it [works as they describe](http://blog.tinisles.com/2010/01/should-you-trust-lastpass-com/).

I’m not sure I’d call that technique “simple”—at least, not in comparison to reading source code. The author of that blog used a tool which sniffs his outgoing web traffic.

> [@](#):
>
> They use standard SHA hashes and AES encryption.

That a product uses secure cryptography is no guarantee that it isn’t also doing something insecure with the data before it’s hashed or encrypted.

> [@](#):
>
> The important bits of LastPass are _effectively_ open-source because they are in JavaScript, and therefore in plaintext and easily readable by anyone that wishes to do an audit.

Really? They don’t use any obfuscation at all? (Because if they do, you might as well argue that all proprietary software is easily readable on the basis that it can be decompiled or at least disassembled.) If LastPass’s browser-based interfaces are indeed in easily readable JavaScript, then that’s very reassuring. However, it should be noted that these interfaces are not the only way of using LastPass. There are also offline clients which I’m pretty sure are not supplied with source code, and therefore cannot be audited.

---

<div class="post-metadata">

**Author:** ![bob\_2](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bob_2/32/3341_2.png) [@bob\_2](https://boards.straightdope.com/u/bob_2)\
**Post date:** [June 16, 2015, 12:49pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/38 "2015-06-16T12:49:56Z")

</div>

Looks like someone had a go at Lastpass:

> [@](#):
>
> Pasword manager LastPass is urging users to change their master passwords after it admitted data including password reminders and email addresses were compromised by hackers last week.  
> [Cyber attack breaches password database LastPass](http://www.telegraph.co.uk/technology/internet-security/11677827/Cyber-attack-breaches-password-database-LastPass.html)

---

<div class="post-metadata">

**Author:** ![bump](https://avatars.discourse-cdn.com/v4/letter/b/7c8e57/32.png) [@bump](https://boards.straightdope.com/u/bump)\
**Post date:** [June 16, 2015, 2:46pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/39 "2015-06-16T14:46:29Z")

</div>

> [@psychonaut](#):
>
> The OP specifically asked about safety and security, so the merits of free versus proprietary software are quite germane. Simply put, security claims of free software are in general falsifiable, whereas those of proprietary software are not.

That’s entirely fair; same thing applies for encryption algorithms. If you don’t publish it, how does anyone know you’re not doing some kind of ROT13-like encoding that makes everything _look_ encrypted, but is in reality, trivially crackable.

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [June 16, 2015, 6:19pm UTC](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721/40 "2015-06-16T18:19:01Z")

</div>

> [@psychonaut](#):
>
> I’m not sure I’d call that technique “simple”—at least, not in comparison to reading source code.

Simple for anyone capable of doing a legitimate audit.

> [@psychonaut](#):
>
> That a product uses secure cryptography is no guarantee that it isn’t also doing something insecure with the data before it’s hashed or encrypted.

Sure. Encryption can be used inappropriately. But using standard algorithms is a first step towards legitimate security, since it means they benefit from all the existing research that’s been done. If they used proprietary algorithms, I’d consider it insecure, even if it had been audited.

> [@psychonaut](#):
>
> There are also offline clients which I’m pretty sure are not supplied with source code, and therefore cannot be audited.

[Here’s the source code](https://github.com/LastPass/lastpass-cli) for their command line client (I haven’t looked at it myself).

[Previous page](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721.md?page=1)

[Next page](https://boards.straightdope.com/t/please-explain-password-managers-for-me/715721.md?page=3)
