The benefits and risks of using a password manager to protect your online identity (2024)

Scribbling a password on a Post-it Note or piece of paper is generally a bad idea. So is storing sensitive information online in a way that could be accessible to others.

Yet many people do this routinely, increasing the risk they'll lose or have their sensitive information compromised.

That's where a dedicated password manager can come in handy, helping securely and efficiently keep track of passwords and other sensitive information. Notably, recent research from Security.org, which reviews technology, products and services, found that Web users withoutpasswordmanagersare three times more likely to experience identity theft than those who properly use them.

"Password managers are an important component of how we need to manage our personal security. They are designed to be used in a way that reduces our efforts to be secure, but still helps us keep our important information secure," said Keri Pearlson, executive director of a cybersecurity research group at MIT Sloan.

But there are some key decisions to make in choosing, and using, a password manager. Here are six things to know about what's becoming a best practice way to protect online identity.

Browser-based options are convenient but limited

Password managers come in different varieties. Most web browsers have some type of password manager, which are convenient and user-friendly. There can be drawbacks, however, including limited security and functionality.

For more robust security and features, security professionals say a dedicated password manager is a better choice. Such third-party apps allow users to enter multiple passwords into one central place that's protected with a single master password. This does require people to hold tight to this master password, but benefits typically outweigh this slight inconvenience, according to security professionals.

Dedicated password managers can also do things such as generate strong passwords and allow users to copy and paste passwords onto a website. They can also be used to safely store many types of information, including PINs, credit card numbers, CVV codes, photos, driver's license information, medical data and more, said Marina Titova, vice president of consumer product marketing at cybersecurity company Kaspersky.

"This is a very secure, encrypted storage and all the major players put a lot of effort into making sure customer's vaults are secure," she said.

Strong security, but hacks still happen

Stand-alone password managers provide strong encryption for a customer's data, helping to ensure no one else — even the password manager provider — can access this information. This type of robust protection helps keep customers' data safe, even in the event of a breach.

That's not to say there haven't been security breaches, including at LastPass, one of the world's largest password managers. In the case of LastPass, no customer data was accessed during the August 2022 incident, but the company just disclosed last week that source code and technical information were stolen and used to target an employee, obtaining credentials and keys which were used to access and decrypt some information stored within the cloud, including potential access to encrypted and unencrypted customer data — company names, end-user names, billing addresses, email addresses, telephone numbers, and the IP addresses from which customers were accessing the LastPass service — but not unencrypted credit card information, according to a blog post which laid out the potential risks to customers.

While using a stand-alone password manager requires placing trust in a third party, despite the LastPass hack, password managers generally do a good job of protecting customer data, said Justin Cappos, an associate professor at NYU Tandon School of Engineering, in a recent interview with CNBC.

Deciding between free and premium security services

Some stand-alone password managers are free, others offer free and premium versions, and some are only available for a fee.Premium features can include the ability to share vault items with multiple people and on multiple devices, dark web monitoring and emergency one-time access to a user's vault.

Which password manager provider to use, and whether to pay for premium services, depends in part on the user's needs and preferences.

Most people should be fine to start out with a free version, and if they want more features, they can look for a paid option, said Rahul Telang, professor of information systems and management at Carnegie Mellon University's Heinz College. For paid services, consumers generally might expect to pay somewhere in the range of about $1 to around $7 per month.

Cybersecurity vendor reputation matters

There are a number of well-known, stand-alone password managers including Bitwarden, LastPass,1Password, Dashlane, KeePass, and Keeper. Cybersecurity providers such as Kaspersky, McAfee and Norton also offer password managers.

Before choosing a provider, pay attention to the vendor's reputation, security expertise, track record with respect to data leaks and how the company stacks up in independent reviews, Titova said.

Reputation can also become a matter of national security concerns, with Kaspersky a prime example. Due to its Russian founder's roots in Russian intelligence, it has been caught up in the Russia-Ukraine war repercussions related to the business world, and even previous to that, had been subject to claims by Western governments that it was too close to the Russian regime to be trusted.

As far back as 2017, the U.S. government barred use of Kaspersky products for government systems. In March of this year, the U.S. government blacklisted the firm. This doesn't stop individual consumers from using and rating manyof the company's services highly, and Kaspersky has denied the allegations, saying in a statement in March, "This decision is not based on any technical assessment of Kaspersky products – that the company continuously advocates for – but instead is being made on political grounds."

How to choose a strong master password

Make sure you have a strong master password, one that's not easily guessable. It's a good idea to use a phrase instead of one or two words, since a longer password will be tougher to crack than a shorter password. It's also advisable to include upper and lowercase letters, numbers and special characters in the phrase, while still making the master password something that's easy to remember, said Daniel Kats, senior principal researcher for Norton, a Gen Digital brand. As an example, "LionelMessi4WorldCup!" would be a strong password for a staunch soccer-fan. Don't use a common phrase or something that could be easily guessed by others such as "masterpassword" or "admin" or "letmein," he said.

What happens if you lose online access

The master password is your entry to the password manager. If you lose the master password, you'll generally lose access to your vault as well. Also, if you don't keep close tabs on your master password, anyone who has it could access your vault. There are ways to mitigate this risk by enabling features such as multi-factor or biometric authentication.

"If you have to write it down so you don't forget it, put it in the place where you would put your most precious records," Pearlson said. She recommends people keep their master password with their will or important papers. No one is going to break into your house looking for your master password, she said, but "you should treat this as a very important record."

The benefits and risks of using a password manager to protect your online identity (2024)

FAQs

What are the advantages and disadvantages of a password manager? ›

Humans can be unreliable as they can come up with bad passwords, forget their password, or are genuinely disinterested in security. With a PM there is no need to worry about remembering all your different passwords. Using the same credentials for each account is dangerous as it creates one point of failure.

What is the main risk of using a password manager? ›

Password managers can be a security threat if they do not encrypt their data. Hackers know that compromising a password manager is like getting the keys to the castle. Because of this a strong encryption must be in place to prevent access to your saved passwords.

What are two benefits of using a password manager to keep your online accounts secure? ›

Password Manager Benefits
  • One-click access to any stored password.
  • Password encryption.
  • Password generation and storage.
  • Seamless access to your accounts across all devices.
  • Freedom from remembering complicated passwords.
  • Security checks to prevent reuse and compromise.

What is the benefit of using a password manager regarding computer passwords? ›

A password manager (or a web browser) can store all your passwords securely, so you don't have to worry about remembering them. This allows you to use unique, strong passwords for all your important accounts (rather than using the same password for all of them, which you should never do).

What are the benefits of password protection? ›

This can prevent identity theft and other forms of online fraud. Protection of networks and systems: Passwords can be used to protect networks and systems from unauthorized access, which can prevent unauthorized users from gaining access to sensitive information or causing damage to the network or system.

Are password managers safer than using your own password? ›

Are password managers safe? Absolutely. But they are only as effective as the person who is using them. If you use “ABC123” as the password for all of your accounts and turn off multifactor authentication, then it doesn't matter how secure your vault is—someone is going to guess that password eventually.

Why are password managers not safe? ›

Password managers can still be hacked if your machine is infected with malware. Weak passwords are still dangerous if they're stored in a password manager. Hackers can still convince your users to give up their master password if they lack cyber security awareness.

Do password managers ever get hacked? ›

In January 2023, Norton LifeLock warned over 6,000 customers of a breach stemming from credential stuffing attacks. Utilizing usernames and passwords likely sourced from the dark web, the attackers successfully accessed customer accounts, potentially compromising stored logins in the password manager.

Which password manager has never been hacked? ›

Keeper Password Manager is safe to use. According to Keeper's website, it's never been hacked or breached. Because it uses the zero-trust, zero-knowledge system, it makes it a more secure product. All encryption and decryption happen on your device when you log in to the vault.

What is the main risk of using password online? ›

Credential Stuffing: A type of brute force attack in which cybercriminals use leaked or known login credentials from one platform (user IDs, email addresses, passwords, and/or pin numbers) to gain unauthorized entry to other accounts.

Where is the safest place to keep passwords? ›

The safest and easiest place to store your passwords is in a password manager such as Dashlane or 1Password. A password manager is an application that stores all your passwords in an encrypted database, which can only be unlocked with a single master password.

What happens if you stop using a password manager? ›

Internet users without password managers are three times more likely to experience identity theft than those who properly use them.

What is the downside of using a password manager? ›

A major possible downside to using a password manager is that if a hacker gains access to it, they will have access to all your passwords. This is why it's important to choose a reputable password manager, like C2 Password, that uses strong encryption and other security measures to protect your data.

What are the benefits of password management? ›

9 Reasons you should be using a password manager
  • One password to rule them all.
  • Generate random passwords. ...
  • Simple access to multiple accounts. ...
  • Easily change your passwords. ...
  • Use the convenient autofill feature. ...
  • Share passwords securely. ...
  • Store more than just passwords. ...
  • Use the same password manager across multiple devices.

What are the advantages and disadvantages of passwords? ›

On one hand, the random passwords generated by a program are nearly impossible to guess or attack via a dictionary approach. On the other hand, they are usually so difficult to remember that users have to write them down, yielding another security problem.

What is the one catch with password managers? ›

Password managers use master passwords to protect access to a password vault. This password vault is used to store passwords. If a threat actor gets access to your master password, your password vault (and the passwords stored in it) is going to become exposed.

Do security experts recommend password managers? ›

Recommended Password Managers

The ISO recommends four password managers that you can use in your daily life: 1Password, Apple's iCloud Keychain, BitWarden, KeePass, and LastPass (alphabetical order).

Do you really need a password manager? ›

It's some of the best money you can spend, save from investing in a VPN. Password managers, like 1Password, are made with the express purpose of keeping all your passwords safe. If you happen to forget one, you won't have to trigger a dozen password reset emails just to get back into your precious accounts.

Have any password managers been hacked? ›

LastPass

Needless to say, 2022 was a rough year for password managers. LastPass experienced a data breach in August 2022 that resulted in hackers gaining access to sensitive data via an employee account. Adding insult to injury, another breach followed in November, targeting sensitive data stored in the Cloud.

Top Articles
Carrying A Knife For Personal Defense
Top 5 Popular blockchains used in NFT development - Blockchain Council
Minooka Channahon Patch
Caesars Rewards Loyalty Program Review [Previously Total Rewards]
Restaurer Triple Vitrage
Tesla Supercharger La Crosse Photos
Craigslist Motorcycles Jacksonville Florida
Triumph Speed Twin 2025 e Speed Twin RS, nelle concessionarie da gennaio 2025 - News - Moto.it
Undergraduate Programs | Webster Vienna
Bloxburg Image Ids
Nyuonsite
Cosentyx® 75 mg Injektionslösung in einer Fertigspritze - PatientenInfo-Service
Giovanna Ewbank Nua
Programmieren (kinder)leicht gemacht – mit Scratch! - fobizz
Socket Exception Dunkin
Aspen.sprout Forum
Cbs Trade Value Chart Fantasy Football
Cinebarre Drink Menu
Best Mechanics Near You - Brake Masters Auto Repair Shops
Fsga Golf
U Of Arizona Phonebook
The Weather Channel Local Weather Forecast
Air Traffic Control Coolmathgames
Telegram Voyeur
Healthy Kaiserpermanente Org Sign On
Generator Supercenter Heartland
897 W Valley Blvd
Vip Lounge Odu
Dentist That Accept Horizon Nj Health
Chapaeva Age
One Credit Songs On Touchtunes 2022
Ni Hao Kai Lan Rule 34
Sinfuldeeds Vietnamese Rmt
Vip Lounge Odu
Natashas Bedroom - Slave Commands
State Legislatures Icivics Answer Key
Vivek Flowers Chantilly
Craigslist List Albuquerque: Your Ultimate Guide to Buying, Selling, and Finding Everything - First Republic Craigslist
D-Day: Learn about the D-Day Invasion
How Many Dogs Can You Have in Idaho | GetJerry.com
Www Usps Com Passport Scheduler
Wilson Tattoo Shops
Lake Andes Buy Sell Trade
Dinar Detectives Cracking the Code of the Iraqi Dinar Market
Ethan Cutkosky co*ck
Candise Yang Acupuncture
Unblocked Games - Gun Mayhem
Craigslist Chautauqua Ny
Okta Login Nordstrom
What your eye doctor knows about your health
Bluebird Valuation Appraiser Login
Read Love in Orbit - Chapter 2 - Page 974 | MangaBuddy
Latest Posts
Article information

Author: Fr. Dewey Fisher

Last Updated:

Views: 6290

Rating: 4.1 / 5 (62 voted)

Reviews: 85% of readers found this page helpful

Author information

Name: Fr. Dewey Fisher

Birthday: 1993-03-26

Address: 917 Hyun Views, Rogahnmouth, KY 91013-8827

Phone: +5938540192553

Job: Administration Developer

Hobby: Embroidery, Horseback riding, Juggling, Urban exploration, Skiing, Cycling, Handball

Introduction: My name is Fr. Dewey Fisher, I am a powerful, open, faithful, combative, spotless, faithful, fair person who loves writing and wants to share my knowledge and understanding with you.