Why passkeys are a step back for personal security: examining account lockout risks, platform lock-in, hardware key limits, and fragile recovery flows.
“use” I bet it just saves everything automatically, and they don’t even know their passwords are there. just “oh look, my password has appeared, lets click it!”
In my experience you’re more likely to find a sticky note on the desk with passwords than someone using a password manager, 2fa, or an ounce of ‘common’ sense.
I just remember my passwords idk lol. I never understood the logic of a password manager, someone hacks your manager they have everything in your life? Rather just run the risk of getting hacked one account at a time rather than they all get hacked at once when they get my password manager.
So make the manager’s password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It’s just too much brainpower to remember individual websites’ passwords. All important ones have 2FA anyway.
Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.
My current employer will not authorize the use of a password manager. I have a key fob for my Microsoft account, and another account does phone verification. I use one password. If they don’t want to put the effort in for account security then neither do I. I use a password manager for nearly all my other accounts.
Maybe 5 or 10 years ago, but who doesn’t use a password manager these days? They generate random passwords and remember them for you
Do you know any non tech people, especially over 40? Literally none of them uses a password manager.
Most of the non-techy people I know use the password manager built into their Web browser at the very least.
“use” I bet it just saves everything automatically, and they don’t even know their passwords are there. just “oh look, my password has appeared, lets click it!”
https://xkcd.com/2501/
Huh I thought it was going to be the correcthorsebatterystaple comic
In my experience you’re more likely to find a sticky note on the desk with passwords than someone using a password manager, 2fa, or an ounce of ‘common’ sense.
I just remember my passwords idk lol. I never understood the logic of a password manager, someone hacks your manager they have everything in your life? Rather just run the risk of getting hacked one account at a time rather than they all get hacked at once when they get my password manager.
So make the manager’s password massive. There, that complete sentence just now is over 30 characters long and could literally be a password. You can double up security with a secret file that you must locate on your PC, in KeePass, at least. You can also add notes about entries, track more than just website accounts, etc. It’s just too much brainpower to remember individual websites’ passwords. All important ones have 2FA anyway.
Managers are local to your computer so you likely messed up big-time if it got hacked, whereas websites can get hacked entirely out of our control.
So we should be using passkeys to access our password managers that generate random passwords and remember them for us! Ultimate protection.
My current employer will not authorize the use of a password manager. I have a key fob for my Microsoft account, and another account does phone verification. I use one password. If they don’t want to put the effort in for account security then neither do I. I use a password manager for nearly all my other accounts.