← Back to context

Comment by xvinci

4 years ago

Can anyone enlighten me on

  Some secrets don’t belong in your password manager. Things like backup private keys, 2FS recovery keys, wallet keys, safe combinations, treasure maps, etc.

I am a 1password user and am aware that I am trusting a 3rd party with most of my life basically (minus the 2FA, my phone), but that's the way I decided for convenience. But why would I keep passwords in there but not PKs, wallet keys etc.? To me they all have the same value. What am I missing?

Honestly that statement sounds like BS to me. Also, this person is trusting his life to a third party as well: the browser vendors’ cryptography implementation.

I think for an average person, the biggest factor is not the strength of the security. You’re already better than 99% of people if you use different passwords per site and store them behind a password. No hacker will spend weeks cracking your passwords if he can get the passwords of those other 99% for free.

So I’d say, pick the solution most convenient for you that is least likely to break over time. And an established name like 1Password sounds great for that.

  • Author here.

    I do use a password manager.

    PortableSecret is a complement, not a replacement.

    e.g. where do you store the recovery key for your password manager?

    I also use this to store tax documents and other mildly secret documents which definitely don't belong in a password manager that copies to who-knows-where-and-in-how-many-copies.

    • So out of curiosity, what password manager do you use? And as apparently you don’t trust your password manager, why do you use one? And how do you determine what is “useless” enough to be entrusted to that password manager you do not really trust?

      1 reply →