
The Only Password Manager I Can Trust DistroTube
video description
Date: 2022-03-30
Related videos
Comments and reviews: 10
Layput
You know, Microsoft edge has a very nice password manager. And your passwords are stored in your machine automatically because microsoft edge is of course integrated in the operating system (if you choose to install it).
One great thing about Edge password manager is that your passwords are automatically exported to your Microsoft Authenticator app in your phone. That's right. Microsoft Authenticator is one of the two best authenticator apps on Android along with Google authenticator.
There are 2 tabs in Microsoft Authenticator: one is authenticator and one is Password. You can find all of your passwords that had been stored on your Edge Password Manager to your Password tab on Microsoft Authenticator.
The best of all is it's free.
I have tried all other password managers and the best one I used was last pass. But recently, last pass limited your free use to one one machine and you have to pay monthly (MONTHLY?!!!!) subscription to additional machine.
I bought sticky password manager, which has a perpertual license, and which I also use to generate strong passwords. If I had known about Microsoft Edge password manager, I would not have bought the Sticky password. I would just have gone to a site to generate a strong password.
reply
You know, Microsoft edge has a very nice password manager. And your passwords are stored in your machine automatically because microsoft edge is of course integrated in the operating system (if you choose to install it).
One great thing about Edge password manager is that your passwords are automatically exported to your Microsoft Authenticator app in your phone. That's right. Microsoft Authenticator is one of the two best authenticator apps on Android along with Google authenticator.
There are 2 tabs in Microsoft Authenticator: one is authenticator and one is Password. You can find all of your passwords that had been stored on your Edge Password Manager to your Password tab on Microsoft Authenticator.
The best of all is it's free.
I have tried all other password managers and the best one I used was last pass. But recently, last pass limited your free use to one one machine and you have to pay monthly (MONTHLY?!!!!) subscription to additional machine.
I bought sticky password manager, which has a perpertual license, and which I also use to generate strong passwords. If I had known about Microsoft Edge password manager, I would not have bought the Sticky password. I would just have gone to a site to generate a strong password.
reply
JP
If at some point, LastPass, or any other cloud password manager, is somehow compromised, the attackers would find themselves with terabytes of AES-256 encrypted data that they would need to make sense of. Not only every user account is encrypted with its unique salted PBKDF2-SHA256 hash, but user information is practically invisible in a sea of accounts (some of which could be of special interest to attackers).
Saying that hosting your keys on every computer you ever use is more secure than having them hosted in a secure cloud is ludicrous. With this solution, you have multiple points of failure that could be exploited, and the only reason they are not is that nobody wants to hack you, and that would also protect you if your information was stored in a cloud.
Also, this might be useful for a handful of IT guys that manage their own servers. Still, it's useless for the average user since it introduces multiple mechanisms to their regular computer use, each of which could be compromised by an attacker.
reply
If at some point, LastPass, or any other cloud password manager, is somehow compromised, the attackers would find themselves with terabytes of AES-256 encrypted data that they would need to make sense of. Not only every user account is encrypted with its unique salted PBKDF2-SHA256 hash, but user information is practically invisible in a sea of accounts (some of which could be of special interest to attackers).
Saying that hosting your keys on every computer you ever use is more secure than having them hosted in a secure cloud is ludicrous. With this solution, you have multiple points of failure that could be exploited, and the only reason they are not is that nobody wants to hack you, and that would also protect you if your information was stored in a cloud.
Also, this might be useful for a handful of IT guys that manage their own servers. Still, it's useless for the average user since it introduces multiple mechanisms to their regular computer use, each of which could be compromised by an attacker.
reply
Fightlikabrave
I mean, you can create local PW vaults that store offline/locally, with PW manager services.
An EASY way to protect against PW manager hacks is to use the -double blind method-: You use the PW manager to generate a long unique PW for a site and save it like that in the manager, THEN you change the sites PW to that PLUS an extra -PIN- (4-8 characters extra) that you use that can be a pattern per site or just a PIN code that you add to the end of the managers saved PW.
So if you have a PW manager save -df%ghd&63n398%egd8- as a PW then you add -------(whatever your memorized PIN is) to it, then IF someone hacks the PW manager and somehow breaks the encryption..they get a bunch of wrong/incomplete PWs and your accts are still safe.
Since you control your emails you can still use those to change any PWs even IF the PW manager gets compromised.
reply
I mean, you can create local PW vaults that store offline/locally, with PW manager services.
An EASY way to protect against PW manager hacks is to use the -double blind method-: You use the PW manager to generate a long unique PW for a site and save it like that in the manager, THEN you change the sites PW to that PLUS an extra -PIN- (4-8 characters extra) that you use that can be a pattern per site or just a PIN code that you add to the end of the managers saved PW.
So if you have a PW manager save -df%ghd&63n398%egd8- as a PW then you add -------(whatever your memorized PIN is) to it, then IF someone hacks the PW manager and somehow breaks the encryption..they get a bunch of wrong/incomplete PWs and your accts are still safe.
Since you control your emails you can still use those to change any PWs even IF the PW manager gets compromised.
reply
Yura
Can pass automatically fill in the password if URL of the website matches the saved template? Also can you save a set of URLs/domains associated with one login/password pair? This way when the account's password changes, it'll affect all websites that use this account (e.g. Microsoft account, MS Exchange account, other corporate/ecosystem accounts).
Bitwarden offers these features and they really make a difference. My only gripe about Bitwarden client apps is that they aren't as fast as other services/apps I'm used to (Telegram, Aegis, Syncthing...).
reply
Can pass automatically fill in the password if URL of the website matches the saved template? Also can you save a set of URLs/domains associated with one login/password pair? This way when the account's password changes, it'll affect all websites that use this account (e.g. Microsoft account, MS Exchange account, other corporate/ecosystem accounts).
Bitwarden offers these features and they really make a difference. My only gripe about Bitwarden client apps is that they aren't as fast as other services/apps I'm used to (Telegram, Aegis, Syncthing...).
reply
Rowan
My method is Bitwarden (self hosted) in Docker + 2FA + Yubikey . pgp keys etc are encrypted in Cryptomator in various cloud drives and synchronised to all my computers & NASs via Syncthing. Multiple encrypted backups of all important data and passwords everywhere. A paper printout of passwords is also kept in a secure safe off site. PC and NAS access is via 2FA yubikeys. I can survive a world war , power cuts or having all my equipment stolen; and still have access to all my passwords.
reply
My method is Bitwarden (self hosted) in Docker + 2FA + Yubikey . pgp keys etc are encrypted in Cryptomator in various cloud drives and synchronised to all my computers & NASs via Syncthing. Multiple encrypted backups of all important data and passwords everywhere. A paper printout of passwords is also kept in a secure safe off site. PC and NAS access is via 2FA yubikeys. I can survive a world war , power cuts or having all my equipment stolen; and still have access to all my passwords.
reply
Bobby
It's not so bad having your password at your computer if you're like me. The only way they could get it that way is if I was dead and they were dodging lead beforehand lol. But ultimately i prefer keeping them close and not on some cloud service knowing what the feds find legal. The hackers out there actually gotta work at it, the feds don't, that ain't fair they should work at it too! lol
reply
It's not so bad having your password at your computer if you're like me. The only way they could get it that way is if I was dead and they were dodging lead beforehand lol. But ultimately i prefer keeping them close and not on some cloud service knowing what the feds find legal. The hackers out there actually gotta work at it, the feds don't, that ain't fair they should work at it too! lol
reply
JarppaGuru
2:00 yes why give your password to 3rd party to saved on cloud. they see password they made it so they can say your password is weak LOL. what if that cloud or database is leaked YEAH there your passwords even hashed, but still passwords should be hashed by uniq way bu creator not just md5() or sha256() it need be multiple times so hacker cant simplu run bruteforce lol
reply
2:00 yes why give your password to 3rd party to saved on cloud. they see password they made it so they can say your password is weak LOL. what if that cloud or database is leaked YEAH there your passwords even hashed, but still passwords should be hashed by uniq way bu creator not just md5() or sha256() it need be multiple times so hacker cant simplu run bruteforce lol
reply
Marcel
I have my password files on my private gitlab instance and use the password-store app from f-droid to access it from my phone. It has git integration built right in. It's a really nice experience, once you get past the initial pain of authenticating for the first time to get your passwords (copying over the gpg key is not fun either)
reply
I have my password files on my private gitlab instance and use the password-store app from f-droid to access it from my phone. It has git integration built right in. It's a really nice experience, once you get past the initial pain of authenticating for the first time to get your passwords (copying over the gpg key is not fun either)
reply
JarppaGuru
0:14 it can be pass123 if you make it md5(sha256(sha512(-pass123-)))
its easy password to try login and its very strong if hash is leaked. impossible bruteforce LOL.
they cant know its encrypted 3 way or more and between stages its flipped flip reversed on your choosed method lol lol
reply
0:14 it can be pass123 if you make it md5(sha256(sha512(-pass123-)))
its easy password to try login and its very strong if hash is leaked. impossible bruteforce LOL.
they cant know its encrypted 3 way or more and between stages its flipped flip reversed on your choosed method lol lol
reply
yousef
Well it is kinda painful to have all passwords on my computer so if I need pass of any thing I have to go to my pc what about if I am outside ....
I guess using password manager which stores pass on database and using double blind technique would be better
reply
Well it is kinda painful to have all passwords on my computer so if I need pass of any thing I have to go to my pc what about if I am outside ....
I guess using password manager which stores pass on database and using double blind technique would be better
reply
Add a review, comment















