“Don’t use the same password for all your accounts”, a phrase I’ve heard a lot and even repeated to family and friends. Often without thinking about how hard it can be for some people to remember which password they use for which account.
For example, it often happens to me that I go through 3 or 4 attempts with various passwords until I hit the right one for the account I want to access.
The solution we were given? A password manager.
The irony of the master key #
Right, because putting all my accesses under a single password seems very different from having the same password across all my accounts, doesn’t it?
It’s not that I’m against or in favor of password managers, it’s just that I find it ironic that by using them we still have a single point of failure: if the master password is compromised, all your accesses are compromised.
The real weak link #
This is something that can happen with online managers (1Password, Proton Pass, etc.) as well as with solutions that let you own your data like KeePassXC. Because remember, nothing is invulnerable… For example, if you install software left and right on your machine or browse sites that could compromise your computer’s security, you could fall victim to the famous keyloggers that could capture your master password while you type it.
Convenience vs. Independence #
In this case, the decision shifts more towards convenience or independence:
- Convenience: Do you want a password manager that syncs to the cloud across all your devices and is very easy to use?
- Independence: Or do you prefer being the absolute owner of your vault, not depending on third parties that might drastically change the product, prices, etc., but taking on the friction of having to manually sync your passwords between your phone and your computer (or setting up the infrastructure to maintain your own sync server, which of course adds another element that could be compromised)?
My “pragmatic” answer? #
In the end, whether it’s safe or not to use a password manager doesn’t seem to have a very clear answer as far as I researched, because I didn’t want to go down that rabbit hole. In my opinion, the answer might be: what are you doing today that is insecure that a password manager could solve for you?
Keep reading
If this got you thinking about taking control of your digital infrastructure and stopping the use of “default” options, I recently applied this exact logic to my blog:
Log #3: Why I moved my domain from Squarespace to Infomaniak