Password Managers!
One of the easiest way to get hacked, and it’s still one of
the most popular methods is through weak and/or re-used passwords. You’ve probably
heard this all before so I’m not going to rant on and on till you wander off
and bury your head in the sand, I’m just going to tell you that you need to
sort it! …… and show you how!
Welcome to the world of Password Managers! The good, the not
so good and the really not so good. There are a
tonne of them out there so I’ll give a quick run down of a bunch, talk about my
favourite: Roboform*, and why I use it, then send you off on your merry way to research and sign up to
one of your choosing .... and then start using it! There is no real, good reason for you not to be using one.
These are in no particular order, rank or favouritism. In fact,
I’ll do them in alphabetical order to avoid any conflict:
1Password
Protect yourself, your family, or your global workforce with simple security, easy collaboration, and actionable insights. 1Password is a popular manager with very similar functionality to RoboForm although a little pricier. For business use you can generate logs which can be diverted to SIEM solutions.
Having not used the service myself I've browsed their documentation, but it doesn't seem to have a built in authenticator - which is a massive requirement for me. Having an all in one solution makes for a much better user experience, without having to load up multiple apps. There doesn't seem to be an app for PC either which means for passwords on desktop apps you'll need to retrieve them from a browser.
Bitdefender
Bitdefender Password Manager is a multi-platform service that helps you store and organize all your online passwords. It comes with the strongest known cryptographic algorithms, so your online credentials are safe and secure. Easily manage your logins with the help of a single master password.
This seems a very similar offering to most of the other managers, has a built in Password Generator, works on all browsers - but no actual PC app, and includes password leak alerts.
Bitwarden
Bitwarden is an Open Source password manager which is again browser based and includes mobile apps. Bitwarden does include and Authenticator in it's Premium account and at just $10 a year it's a pretty hard option to ignore. If you don't need the authenticator then they have a totally free account!
Dashlane
Built for individuals who want to secure and optimize their online lives. Dashlane makes it effortless for you to access your passwords, passkeys, payment information, and IDs anywhere you are, across any device. Dashlane incorporates a nice password generator which is very similar to the one I use with RoboForm and also checks the Dark Web for any breaches (but only on a paid plan!). There is a free plan for their basic Password manager and 3 further plan tiers at additional pricing which include extra features as the plan increases.
Google
Google password manager is available on Google Chrome and Android devices. If all you use is Android / Google devices then this is probably the best option for you. However, if you use a PC / Mac, you'll need to be using the Chrome browser. Google also have their Authenticator app which works just fine but again, what ever device you're using you'll need access to your google account. Check your Google account for more info.
KeePass
KeePass is a free open source password manager, which helps you to manage your passwords in a secure way. You can store all your passwords in one database, which is locked with a master key. So you only have to remember one single master key to unlock the whole database. Database files are encrypted using the best and most secure encryption algorithms currently known (AES-256, ChaCha20 and Twofish).
KeePass is software based and is totally free, you can even have it just on a USB stick. It's probably a little more of an advanced option for the more IT proficient!
Keeper
Never forget another password with Keeper Password Manager. Easily create and store your passwords in a secure personal password vault that you can access from any device. Keeper has 2 paid plans, has a Mobile App or is browser based. There's no mention of and Authenticator function with Keeper so at it's price point is a little on the expensive side.
LastPass
We'll just leave this one for now. Multiple recent breaches make me want to stay away from this one until they improve their systems a bit!
Microsoft Edge
It looks like
Microsoft has improved it’s password manager offering with the Wallet which
includes a Health Check for your passwords. It can keep track of your Payment
info, Passwords and personal info. Edge can also suggest passwords for you.
The downside are: The
Authenticator function for MFA is a separate standalone app. To have the password manager on
all devices, you will need to install Edge Browser on them all and use that to
surf the web using your stored passwords (all except on Chrome Books which don't support Edge). It’s good but not very efficient for
me. TechRadar have a good write up on it here.
NordPass
All of your passwords, credit cards, and personal info in a single secure place. Never forget another password again. Create strong and unique passwords, securely store them in a single place, and autofill them with just a few clicks. Nordpass includes the usual password generator and breach alerts (int he paid plan). The have a free plan for the basic manager, a premium and family option which include all the available features. Again, there's no authenticator component with Nordpass. Discounts may be available if you have their VPN service!
Norton
Norton's offering is a cloud based password manager with browser extensions available and apps for Android and iOS. It appears to be free but is only available on Android and iOS devices with Fingerprint Authentication or Touch ID/Face ID activated. If you already have a Norton account and want a basic password manager then this seems like a great option.
Passbolt
Passbolt is another Open Source manager more aimed at business users. Passbolt can be downloaded and installed on a server, VM or Docker instance and again more for the IT proficient audience. They do have a free offering which is fairly feature rich but it does require configuration to get it up and running.
RoboForm
RoboForm is utilised via a Browser Extension compatible with many browsers or via an app, be it Windows, Mac, iOS, Android, Linux or Chromebook. It can keep track of all of your usernames and passwords, personal info, payment info. RoboForm securely scans for weak, duplicate, or compromised passwords and alerts you if any are found in documented breaches.
It also has a built in Password Generator and Authenticator making it and all in one solution. You can log in with a single click into almost any account or app on any webpage, browser or device and will sync your data across all your devices. Having the built in Authenticator is a massive bonus for the price, which means that when RoboForm enters the Username and Password, as soon as the website requests a TOTP (Time Based One Time Passcode) RoboForm is ready to respond with it immediately.
I use RoboForm Password Manager everyday on all of my devices and love it; I think you would too!
As a first time user,when you purchase a RoboForm Everywhere subscription using my referral link, you'll receive and additional 6 months for Free!
Purchase and learn more about RoboForm Everywhere click here*.
Conclusion
All that's left now is for you to pick one, sign up and start using it!
Thanks for reading,
Rich.
If you find any incorrect or missing details that you feel need correcting, then please feel free to drop me a comment and I'll get them fixed asap.
*These links are affiliate links, should you click and sign up via this link I will receive a small extension to my plan which helps me keep the costs down in creating content, and I thank you for it.
No comments:
Post a Comment