2
A pentester told me my password manager setup was useless
I had been using a free password manager for about 2 years and thought I was being safe. Then a buddy who does penetration testing looked at my setup and said storing my master password in a notes app on my phone defeats the whole point. He showed me how easy it is for malware to scrape that data. I switched to a hardware key like a YubiKey for 2FA on my vault last month. Now I also keep a backup paper copy in my fire safe at home. Has anyone else had a security pro call out a blind spot like this in your routine?
2 comments
Log in to join the discussion
Log In2 Comments
the_julia1mo ago
Storing my master password in a notes app on my phone" - I used to do the same thing and thought I was being careful. Totally changed my mind when someone pointed out how basic malware could grab that in seconds. Now I just memorize it and use a hardware key like you mentioned, that paper backup in a safe is smart too.
6
abbyk101mo ago
The 10 seconds it would take for malware to scrape a notes app was the stat that finally got me to change my ways too, @the_julia. I used to think physical backups were overkill until I saw how quickly digital ones can vanish.
1