Comment by ddosmax556

11 hours ago

It's not that hard to enable 2fa & force password manager usage. And it's not that hard to use it. In fact a pw manager alone is much more convenient than remembering passwords. The only people I know who "can't remember their passwords and are locked out" are people who don't use the pw manager and have dogs*it passwords with tiny variants they forget. They often need multiple attempts to log in anywhere. Yeah 2fa & pw manager is a tick more complicated but it's not like it take hours, it takes minutes per day. And you protect against stuff like this. No sympathy, sorry.

It is actually very hard to force password manager usage. You can encourage it, educate, but forcing it? How do you do that.

  • Passkeys.

    • Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.

      I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.

      And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.

      1 reply →

How do you force password manager usage?

  • Technically or socially? The second one is hard, the first one can be done easily - just require the passwords to be 14/16+ characters, multiple symbol domains and calculate tempo of input. Slower than 350ms between keystrokes - error message. Those who can type that fast already are using pw manager or you can just skip this 0.001%.

    • Doing that will certainly get people to use a password manager.

      But it doesn't say which password manager.

      The most popular password manager is some text/word/excel document on the desktop.

      1 reply →