<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the password manager that I should use? in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59101#M3924</link>
    <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;said: &lt;EM&gt;Are you referring just to a web-app, where everything lives in the cloud, or do you also eschew installed apps that use the cloud to sync an encrypted vault?&amp;nbsp; Also, do you draw a distinction between public and private cloud in your risk analysis?&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Neither appeal to me in the slightest.&amp;nbsp; The idea of my passwords, my passphrases, my secret questions and secret answers, and backup tools for my 2FA accounts feel unsettling enough to be stored in a "password manager"... but I sure as shootin' won't place that basket of eggs into someone else's computer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the heart of these concerns, all of this is just a management problem.&amp;nbsp; I'm not a high-value target, but I also don't draw a red circle around myself, either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many, many years ago, I was in a class where the instructor said, "Never give away what you can't take away later".&amp;nbsp; He was talking about administrators who grant permissions too freely, but this indelible statement applies neatly to my basic online behaviors.&amp;nbsp; Thank you, LastPass, but you can't have my Netflix password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You've got good points about automation, but I kinda just grew up into this world.&amp;nbsp; One day I was listening to Denis Leary's "No Cure For Cancer" comedy album, and the next thing you know I'm managing over 300 online accounts, all in a hodgepodge of slap-dash protection solutions, by a variety of different companies with different mission statements and differing approaches to cybersecurity.&amp;nbsp; Automation be cursed, because I have walked through the Valley of the Shadow of Due Diligence.&lt;/P&gt;</description>
    <pubDate>Wed, 10 May 2023 23:07:53 GMT</pubDate>
    <dc:creator>ericgeater</dc:creator>
    <dc:date>2023-05-10T23:07:53Z</dc:date>
    <item>
      <title>What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58987#M3916</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am wondering if there is a advice about the use of a password manager on workstations.&lt;/P&gt;&lt;P&gt;What is the most secure password manager that you would use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have the once in our browser that propose to save the password for every website that you use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But also the ones that you can install on you machine and then is holding a local database for example the Keypass, 1Password applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What password manager is used for each OS (MacOS, Windows, Linux)?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any recommendations on this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 10:31:44 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58987#M3916</guid>
      <dc:creator>Pienske8500</dc:creator>
      <dc:date>2023-10-09T10:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58994#M3918</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/656249033"&gt;@Pienske8500&lt;/a&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I work in an enterprise with 450,000 staff globally, we all use 1Password for Windows End Points, MacOS and Linux Machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It works very well indeed, it is stable and works very well indeed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;</description>
      <pubDate>Mon, 08 May 2023 20:30:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58994#M3918</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-05-08T20:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58998#M3919</link>
      <description>&lt;P&gt;I have used a few:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;BitWarden is my current favorite, paying for the $10/year tier.&lt;/LI&gt;&lt;LI&gt;LastPass lost me as a (paying) customer when they changed their pricing and I started realizing that their data protection practices did not meet my requirements.&lt;/LI&gt;&lt;LI&gt;Keypass was a reasonable choice, but found its autofill features lacking, especially on mobile devices.&amp;nbsp; Also, sync was not inbuilt and often ran into replication conflicts when used on multiple devices.&lt;/LI&gt;&lt;LI&gt;Brower password stores were my initial solution, but became disillusioned by browser lock-in.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;From a risk perspective, make sure the following are on your radar:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;You are entrusting confidential data to the vendor.&amp;nbsp; Do you have reason to trust their programming, development and business practices?&lt;/LI&gt;&lt;LI&gt;When syncing your vault to the vendor cloud, is it fully encrypted on the client?&amp;nbsp; Is the key kept local (should be)?&lt;/LI&gt;&lt;LI&gt;Are there protections against a malicious web site gaining access to the vault?&lt;/LI&gt;&lt;LI&gt;What happens if the app/vendor bricks?&amp;nbsp; &amp;nbsp;Is there a mechanism to retrieve your data (e.g.&amp;nbsp; an occasional unencrypted csv export stored on a thumb drive in a physical safe)?&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Is there a mechanism so your heirs/employer can gain control when appropriate?&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 09 May 2023 00:01:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58998#M3919</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-05-09T00:01:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58999#M3920</link>
      <description>&lt;P&gt;First, cloud-based password managers seem like very bad ideas, period.&amp;nbsp; What SLA will you rely on for making you whole after losing every password because that company failed to find &lt;EM&gt;that one big vuln&lt;/EM&gt;?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So if you're wandering from WS to WS and you need access to a small password stash, encrypt a USB stick with BitLocker and throw Keepass on it.&amp;nbsp;&amp;nbsp;BitLocker requires a password.&amp;nbsp; Keepass requires a password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Use long passwords, and make certain they're not the same at all.&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 01:50:33 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/58999#M3920</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-05-09T01:50:33Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59003#M3921</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;I agree, but if it is hosted within the main providers environment globally within their own Data Centres and fully supported including compliant to SOX on a 24x365 day basis.&amp;nbsp;&amp;nbsp; It works, and there is plenty of resilience, and assurance.&amp;nbsp; Especially when there is a huge financial penalty hanging over the CEO's head every 90 days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_Cautim&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 May 2023 20:20:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59003#M3921</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2023-05-09T20:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59008#M3922</link>
      <description>&lt;P&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/809125741"&gt;@Caute_cautim&lt;/a&gt;&amp;nbsp;Yes, but, it's a level of unnecessary complexity.&amp;nbsp; I'm certain that there's use cases which benefit from having an accessible password manager in the cloud layer, but I'm too paranoid to transfer that particular type of risk.&amp;nbsp; At the very least, and if I were required to use such a service, I'd probably compose all my passwords so that they all share the same last ten characters.&amp;nbsp; And then I would store passwords with that bit missing.&amp;nbsp; Anyone who may find my treasure trove would have incomplete data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Besides, the OP described activity moving from workstation to workstation, so theirs probably isn't a good example of cloud-stored passwords, anyway.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 01:37:27 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59008#M3922</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-05-10T01:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59099#M3923</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&amp;nbsp;I'd probably compose all my passwords so that they all share the same last ten characters.&amp;nbsp; And then I would store passwords with that bit missing.&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;The phrase I hear for this is "salting your passwords", in remembrance of the days when UNIX crypt() reigned supreme.&amp;nbsp; It seems to be a common and effective response to lack of complete trust in a password manager -- which in some cases is well deserved.&amp;nbsp; In effect, it is a poor man's 2fa -- the vault &lt;STRONG&gt;has&lt;/STRONG&gt; the first part and you &lt;STRONG&gt;know&lt;/STRONG&gt; the salt.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;cloud-based password managers seem like very bad ideas, period&lt;BR /&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Are you referring just to a web-app, where everything lives in the cloud, or do you also eschew installed apps that use the cloud to sync an encrypted vault?&amp;nbsp; Also, do you draw a distinction between public and private cloud in your risk analysis?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My risk tolerance varies greatly between those cases.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With respect to the USB option, I do like &lt;A href="https://portableapps.com/" target="_blank"&gt;Portable Apps&lt;/A&gt;, but I do get concerned about storing data on USB due to the difficulty in automating backups.&amp;nbsp; USB drives live a tough life; they get lost, broken and corrupted.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 21:29:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59099#M3923</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-05-10T21:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59101#M3924</link>
      <description>&lt;P&gt;&lt;SPAN&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/311867713"&gt;@denbesten&lt;/a&gt;&amp;nbsp;said: &lt;EM&gt;Are you referring just to a web-app, where everything lives in the cloud, or do you also eschew installed apps that use the cloud to sync an encrypted vault?&amp;nbsp; Also, do you draw a distinction between public and private cloud in your risk analysis?&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Neither appeal to me in the slightest.&amp;nbsp; The idea of my passwords, my passphrases, my secret questions and secret answers, and backup tools for my 2FA accounts feel unsettling enough to be stored in a "password manager"... but I sure as shootin' won't place that basket of eggs into someone else's computer.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At the heart of these concerns, all of this is just a management problem.&amp;nbsp; I'm not a high-value target, but I also don't draw a red circle around myself, either.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many, many years ago, I was in a class where the instructor said, "Never give away what you can't take away later".&amp;nbsp; He was talking about administrators who grant permissions too freely, but this indelible statement applies neatly to my basic online behaviors.&amp;nbsp; Thank you, LastPass, but you can't have my Netflix password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You've got good points about automation, but I kinda just grew up into this world.&amp;nbsp; One day I was listening to Denis Leary's "No Cure For Cancer" comedy album, and the next thing you know I'm managing over 300 online accounts, all in a hodgepodge of slap-dash protection solutions, by a variety of different companies with different mission statements and differing approaches to cybersecurity.&amp;nbsp; Automation be cursed, because I have walked through the Valley of the Shadow of Due Diligence.&lt;/P&gt;</description>
      <pubDate>Wed, 10 May 2023 23:07:53 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59101#M3924</guid>
      <dc:creator>ericgeater</dc:creator>
      <dc:date>2023-05-10T23:07:53Z</dc:date>
    </item>
    <item>
      <title>Re: What is the password manager that I should use?</title>
      <link>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59105#M3925</link>
      <description>&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/136236425"&gt;@ericgeater&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;SPAN&gt;but I sure as shootin' won't place that basket of eggs into someone else's computer.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P data-unlink="true"&gt;Both Keepass and Bitwarden have &lt;A href="https://portableapps.com/" target="_blank"&gt;PortableApps&lt;/A&gt;&amp;nbsp;&amp;nbsp;&lt;A href="https://portableapps.com/apps/utilities/keepass-pro-portable" target="_blank"&gt;[k]&lt;/A&gt;&amp;nbsp;&lt;A href="https://bitwarden.com/help/using-bitwarden-offline/" target="_blank"&gt;[b]&lt;/A&gt; that can sync to your own server &lt;A href="https://keepass.info/help/v2/sync.html" target="_blank"&gt;[k]&lt;/A&gt; &lt;A href="https://bitwarden.com/help/self-host-an-organization/" target="_blank"&gt;[b]&lt;/A&gt;, helping address both the attack-surface and backup concerns.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Credential management is one of those areas where there are lots of alternatives to choose from, making it much easier to balance one's risk tolerance vs their convenience goals.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 03:37:59 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/What-is-the-password-manager-that-I-should-use/m-p/59105#M3925</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2023-05-11T03:37:59Z</dc:date>
    </item>
  </channel>
</rss>

