Password Managers 101
Or How I Learned to Stop Worrying and Love the Random
What is a Password Manager?
• Used for storing and generating passwords
• Some generate from random and some calculate on demand
• Some store other kinds of sensitive data
Why Use a Password Manager?
• Creating and remembering secure passwords can be hard
• Help prevent password reuse
• What we know about creating secure passwords is now wrong
Managed Service Password Managers
• Available anywhere with an internet connection
• Don’t have to personally manage database maintenance, performance, security, etc.
• Special features
• $24 per year ($2 a month)
• Very good cross platform
• Emergency contact, 2FA features,
LastPass Sentry (alert of breaches)
• $36 per year ($3 a month)
• $65 for single local license
• TOTP (time-based one-time
password) generator,
Watchtower (alert of breaches)
Other Managed Service Password Managers
• Dashlane
• Passpack
Local Password Managers
• Databases are locally stored
• Can use multiple databases to separate tasks
• Free, OSS, or minimal one time fee
• Free and $10 app
• Very good cross platform
• Portable and TOTP generator
• Open Source
• Ported to many platforms
• Plugin system
Other Local Password Managers
• Keychain
• Password Safe
• Pass
Hardware Password Managers
• Actual physical devices
• Can be used as HID devices
• Fairly new on the market
• $79.00 + Shipping ($4 for
extra cards)
• Nice aluminum construction
and on-board display
• Works on Android and
iPhone
• €115 Shipped (~$135)
• Store your Bitcoin wallet
account
• In public beta
Other Hardware
• Pastilda
• The FinalKey
Password Managers Overview

Password Managers Overview

  • 2.
    Password Managers 101 OrHow I Learned to Stop Worrying and Love the Random
  • 3.
    What is aPassword Manager? • Used for storing and generating passwords • Some generate from random and some calculate on demand • Some store other kinds of sensitive data
  • 4.
    Why Use aPassword Manager? • Creating and remembering secure passwords can be hard • Help prevent password reuse • What we know about creating secure passwords is now wrong
  • 5.
    Managed Service PasswordManagers • Available anywhere with an internet connection • Don’t have to personally manage database maintenance, performance, security, etc. • Special features
  • 6.
    • $24 peryear ($2 a month) • Very good cross platform • Emergency contact, 2FA features, LastPass Sentry (alert of breaches)
  • 7.
    • $36 peryear ($3 a month) • $65 for single local license • TOTP (time-based one-time password) generator, Watchtower (alert of breaches)
  • 8.
    Other Managed ServicePassword Managers • Dashlane • Passpack
  • 9.
    Local Password Managers •Databases are locally stored • Can use multiple databases to separate tasks • Free, OSS, or minimal one time fee
  • 10.
    • Free and$10 app • Very good cross platform • Portable and TOTP generator
  • 11.
    • Open Source •Ported to many platforms • Plugin system
  • 12.
    Other Local PasswordManagers • Keychain • Password Safe • Pass
  • 13.
    Hardware Password Managers •Actual physical devices • Can be used as HID devices • Fairly new on the market
  • 14.
    • $79.00 +Shipping ($4 for extra cards) • Nice aluminum construction and on-board display • Works on Android and iPhone
  • 15.
    • €115 Shipped(~$135) • Store your Bitcoin wallet account • In public beta
  • 16.

Editor's Notes

  • #5 High profile breaches; LinkedIn 165M, MySpace 360M, Yahoo 500M, etc. National Institute of Standards and Technology, Bill Burr 2003
  • #6 (Breach notifications, auto change password for user, wareable integration)
  • #7 Windows, Mac, Linux Firefox, Chrome, Safrai, Opera iOS, Android, WinMoPho
  • #8 Windows, Mac Firefox, Chrome, Safari, Opera iOS and Android
  • #9 ($40 per year (3.33 a month) $18 per year (1.50 a month)
  • #11 Windows, Mac, Linux Firefox, Chrome, Safrai, Opera iOS, Android, WinMoPho, BB
  • #12 Windows, Mac, Linux Firefox, Chrome, Safrai, Opera iOS, Android, WinMoPho, BB
  • #17 $50, uses KeePass 2.x dbx open source software and hardware