  {"id":562,"date":"2020-05-28T09:55:25","date_gmt":"2020-05-28T19:55:25","guid":{"rendered":"https:\/\/www.hawaii.edu\/testinfosec\/?page_id=562"},"modified":"2023-10-24T16:36:41","modified_gmt":"2023-10-25T02:36:41","slug":"password-manager","status":"publish","type":"page","link":"https:\/\/www.hawaii.edu\/infosec\/resources-tips\/password-manager\/","title":{"rendered":"Password Managers"},"content":{"rendered":"<h2>What is a password manager, and why should I use one?<\/h2>\n<p>Best practices state that you should use a <a href=\"https:\/\/www.hawaii.edu\/askus\/705\">strong, unique password <i class=\"fa fa-external-link\" aria-hidden=\"true\"><\/i><\/a> for each of your online accounts, but as the world shifts everything to online it can be hard to manage all of your online accounts. Password managers can help you generate, store, audit and manage long, complex passwords for each of your accounts. The only way to access your password vault is by using one strong master password, which greatly reduces the amount of information you need to remember and protect.<\/p>\n<p>Most password managers can encrypt the stored information in a &#8220;Vault&#8221;, which makes them a much safer alternative to writing down passwords on Post-It notes or typing them up in a Microsoft Excel spreadsheet.<\/p>\n<h2>What benefits can password managers provide?<\/h2>\n<ul>\n<li>Password managers can sync your vault to various devices making it convenient to login via mobile or workstation.<\/li>\n<li>Zero knowledge architecture, decrypts vaults on the client vs in the cloud infrastructure. Your password is never sent to their infrastructure.<\/li>\n<li>Password generators to help you create strong, secure passwords or passphrases.<\/li>\n<li>Password checkers within the manager can determine if your password has been exposed.<\/li>\n<li>Built-in captcha features on web services portals to prevent brute force attempts.<\/li>\n<li>Multi-factor Authentication to prevent unauthorized login attempts.<\/li>\n<\/ul>\n<p><img decoding=\"async\" src=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/bitwarden-price-tiers.png\" alt=\"Bitwarden price tiers\" class=\"aligncenter\" \/><\/p>\n<p>The recommendations below should not be seen as an endorsement by the University of <span aria-label=\"Hawaii\">Âé¶¹´«Ã½<\/span> :<\/p>\n<ul>\n<li><a href=\"https:\/\/www.pcmag.com\/picks\/the-best-free-password-managers\">PC Magazine&#8217;s List of Best Free Password Managers<\/a><\/li>\n<li><a href=\"https:\/\/www.pcmag.com\/picks\/the-best-password-managers\">PC Magazine&#8217;s List of Best Password Managers<\/a><\/li>\n<li><a href=\"https:\/\/www.wired.com\/story\/best-password-managers\/#intcid=_wired-bottom-recirc-v2_3380b07e-b86e-48d8-b561-1fd74eda27a7_text2vec1-reranked-by-vidi\">Wired&#8217;s List of Best Password Managers<\/a><\/li>\n<\/ul>\n<h2>Password Manager Security<\/h2>\n<p>When considering a password manager, you should evaluate several factors, including whether the service is free or a paid subscription, the level of encryption offered, cross-platform support (for mobile and desktop), and the availability of Multi-factor Authentication. Price versus capabilities is an important consideration.<\/p>\n<p>Keep in mind that not all password managers are equally secure. Avoid using password managers from unverified publishers and untrustworthy sources. Also, be cautious about the browser extensions you install, as compromised extensions can leak your passwords. <strong>How you use your password manager determines its safety.<\/strong><\/p>\n<div class=\"col-sm\" align=\"center\">\n<p><a href=\"https:\/\/www.securityweek.com\/lastpass-says-devops-engineer-home-computer-hacked\/\">LastPass password manager compromised after a home hack<\/a><\/p>\n<p>    <a href=\"https:\/\/www.securityweek.com\/lastpass-says-devops-engineer-home-computer-hacked\/\"><img decoding=\"async\" src=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/last-pass-article.png\" alt=\"LastPass News Article\" \/><\/a>\n<\/div>\n<h2>Tips for Keeping Your Password Manager Secure:<\/h2>\n<div class=\"col-sm\" align=\"center\">\n<p><a href=\"https:\/\/hivesystems.io\/password\">Hive Systems passwords<\/a><\/p>\n<p>    <a href=\"https:\/\/www.hivesystems.io\/blog\/are-your-passwords-in-the-green\"><img decoding=\"async\" src=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/hive-2023-passwords.png\" alt=\"Chart with list of passwords\" width=\"800\" \/><\/a>\n<\/div>\n<h2>Is your master password in the green?<\/h2>\n<ul>\n<li><strong><big>S<\/big>trong Master Password:<\/strong> Your master password should be difficult to guess, with over 12 characters, a combination of letters, numbers, symbols, and without common words or phrases. Refer to the chart above for an idea of the required complexity. A strong master password in the green zone will be hard to &#8220;brute force&#8221; if your password manager vault is stolen.<\/li>\n<li><strong><big>E<\/big>nroll in MFA:<\/strong> Multi-factor authentication on your password manager will prevent unauthorized logins from accessing your fault. Change your password immediately if you get prompted for MFA.<\/li>\n<li><strong><big>C<\/big>aution when installing Third-Party Browser Extensions and Applications:<\/strong> Unverified or compromised applications and extensions can leak your passwords. Use caution when reviewing emails with attachments or untrusted links as they can install malware or capture your credentials.<\/li>\n<li><strong><big>U<\/big>se haveibeenpwned.com:<\/strong> This website lists compromised passwords, allowing you to monitor the security of your accounts.<\/li>\n<li><strong><big>R<\/big>egularly Update OS, Apps, and Extensions:<\/strong> Keeping your password manager updated ensures you have the latest security patches and bug fixes.<\/li>\n<li><strong><big>I<\/big>nstall Anti-Virus or anti-malware software:<\/strong> Regularly scan for malware and new threats as they can steal passwords by installing keyloggers or remote access tools.<\/li>\n<li><strong><big>T<\/big>rustworthy Vendor Reviews:<\/strong> Not all password manager vendors offer the same level of protection and service. Choose a vendor that provides the necessary security features and has a good track record of keeping users safe. <\/li>\n<li><strong><big>Y<\/big>our Security Practices:<\/strong> Unwanted intruders gaining physical or digital access to your devices can compromise the safety of your password manager and associated accounts. Don&#8217;t leave devices unlocked or unattended in public places!<\/li>\n<\/ul>\n<div class=\"col-sm\" align=\"center\">\n<p><a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/04\/new-macos-malware-yoinks-a-trove-of-sensitive-information-including-a-users-entire-keychain-database\">macOS malware compromises users&#8217; Keychain database<\/a><\/p>\n<p>    <a href=\"https:\/\/www.malwarebytes.com\/blog\/news\/2023\/04\/new-macos-malware-yoinks-a-trove-of-sensitive-information-including-a-users-entire-keychain-database\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/apple-article.png\" alt=\"Apple News Article\" width=\"534\" height=\"456\" class=\"aligncenter size-full wp-image-1905\" srcset=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/apple-article.png 534w, https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/apple-article-300x256.png 300w\" sizes=\"auto, (max-width: 534px) 100vw, 534px\" \/><\/a>\n<\/div>\n<h2>What do Password Managers NOT Protect You From?<\/h2>\n<ul>\n<li><strong>Malware:<\/strong> Password managers can be compromised by existing malware on your device or malware acquired while using the password manager. That&#8217;s why it&#8217;s important to use a firewall and keep your device&#8217;s security settings up to date.<\/li>\n<li><strong>Compromised Master Passwords:<\/strong> A password manager is only as strong as the master password used to access it. If you use a weak master password, all your securely generated, complex account passwords are at risk. Choose a master password that is both memorable and sufficiently complex.<\/li>\n<li><strong>A Breach at the Password Manager Provider:<\/strong> The recent <a href=\"https:\/\/blog.lastpass.com\/2022\/12\/notice-of-recent-security-incident\/\">data breach at LastPass<\/a> illustrates the importance of choosing a trusted vendor. If the provider experiences a data breach, your stored passwords may be exposed.<\/li>\n<li><strong>Phishing and Social Engineering Attacks:<\/strong> Entering your login credentials on a fake website or revealing your login information to hackers and scammers can still compromise your accounts. Hackers are using Google Ads and Punycode to push malware. Be cautious about the sites you visit and the links you click and go to the vendors website instead of the sponsored ad.<\/li>\n<\/ul>\n<div class=\"col-sm\" align=\"center\">\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-keepass-site-uses-google-ads-and-punycode-to-push-malware\/\">Malicious Advertisments on Google Ads<\/a><\/p>\n<p>    <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/fake-keepass-site-uses-google-ads-and-punycode-to-push-malware\/\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/malwarebytes-malvertisements.png\" alt=\"example google search result link with malicious advertisement\" width=\"621\" height=\"609\" class=\"aligncenter size-full wp-image-1909\" srcset=\"https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/malwarebytes-malvertisements.png 621w, https:\/\/www.hawaii.edu\/infosec\/wp-content\/uploads\/sites\/24\/2023\/10\/malwarebytes-malvertisements-300x294.png 300w\" sizes=\"auto, (max-width: 621px) 100vw, 621px\" \/><\/a><\/p>\n<\/div>\n<h2>What should you do if your password manager is compromised?<\/h2>\n<p>If your password manager is compromised, take immediate action to ensure the security of your personal information and online accounts. Some password management providers keep your vault encrypted, giving you time to secure your accounts based on the strength of your master password. However, it&#8217;s advisable to change your master password and update all passwords in your vault, as any access to your vault should be considered a compromise. Additionally, any notes or credit card information stored within your password manager should also be considered compromised. It&#8217;s best practice to avoid storing such sensitive data in the manager.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What is a password manager, and why should I use one? Best practices state that you should use a strong, unique password for each of your online accounts, but as the world shifts everything to online it can be hard &hellip; <\/p>\n","protected":false},"author":86,"featured_media":0,"parent":70,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"page-onecolumn.php","meta":{"footnotes":""},"class_list":["post-562","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/562","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/users\/86"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/comments?post=562"}],"version-history":[{"count":12,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/562\/revisions"}],"predecessor-version":[{"id":1911,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/562\/revisions\/1911"}],"up":[{"embeddable":true,"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/pages\/70"}],"wp:attachment":[{"href":"https:\/\/www.hawaii.edu\/infosec\/wp-json\/wp\/v2\/media?parent=562"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}