Risk
4/30/2013
12:48 PM
Dino Londis
Dino Londis
Slideshows
100%
0%

10 Top Password Managers

Tired of being stuck in password hell? Consider these password managers that balance security with convenience.
Previous
1 of 11
Next


In 2011, IBM predictedthat in five years we will not be using passwords to access secure resources such as ATMs and PCs. Instead of entering a PIN or typing a username and password into a PC, we will simply look into a camera or speak a name into a microphone, because our eyes and voices are unique, IBM says.

[Super-strong unique passwords are pointless! Join Dark Reading Radio on Wednesday, Sep. 17, 2014 at 1 p.m. ET for a grown-up conversation about passwords with Cormac Herley of Microsoft Research.]

Biometric recognition replaces the entry point for what password managers are already doing today. Companies such as RoboForm and LastPass provide a platform that requires only one complex password to access your secure websites, credit card information and even documents that you keep inside an encrypted database. Depending on the platform, the database could be stored locally, on the company's servers or even in Dropbox.

Some password managers use browser extensions that keep your data in a local profile, syncing with a cloud server. Because the data is encrypted and transferred through a secure connection, you can be reasonably confident that your data is safe.

Other password managers keep your data on a thumb drive you carry around from computer to computer. With this approach you always know where your data is -- as long as you don't leave it in a PC and walk away.

Some products are free and charge for a mobile premium; others are subscription-based or charge single flat fee. One product, Dashlane, rewards you when you use its service by awarding points you can use to earn discounts on future purchases.

Some password managers offer two-factor authentication, requiring a smartcard as well as your password to log in. With this type of two-factor authentication, even if your password is decrypted, hackers still can't access your account -- but neither can you, if you don't have your smartcard. That's why this type of authentication is usually offered as an option; most customers prefer a less-strict password management service.

All password managers do have one thing in common: They require you to remember one complex password. But complex should not mean hard to remember; it could be a sentence, for example. If you forget your master password, after all, you can't access your data -- and since the company that developed your password manager doesn't have it, you'll have to reset all your passwords and start over.

Password managers also generate complex passwords, provide import and export tools, allow for simple notes and automatically complete online forms for more efficient online checkout. Here are 10 password manager tools worth considering.

Previous
1 of 11
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
<<   <   Page 2 / 4   >   >>
yong926
100%
0%
yong926,
User Rank: Apprentice
12/18/2013 | 1:10:52 AM
re: 10 Top Password Managers
I want to recommend Efficient Password Manager which is freeware yet very powerful. You only need to remember one password from now on. You can see more info at: http://www.efficientsoftware.net/passwordmanager/
pepeleches69
50%
50%
pepeleches69,
User Rank: Apprentice
12/8/2013 | 5:23:00 AM
re: 10 Top Password Managers
PassVault is a easy and powerful app to manage password in a very reliable and secure way. Store in a cipher database all your passwords for Web, email, Social Media, Banking accounts, etc.
- All your data is fully encrypted with a strong, password-based, government-grade 256-bit AES cipher. This way your information is protected from unauthorized access by thieves, hackers and malware.
- FREE and without Ads.
- Backup your database to your favorite services (Google Drive, Dropbox, etc)

https://play.google.com/store/apps/details?id=com.singularapps.passvault&hl=es_419
SecurityManiacs
50%
50%
SecurityManiacs,
User Rank: Apprentice
11/28/2013 | 7:42:40 PM
Password Manager & Safe
I think, in article misses one interesting password manager - Sticky Password.


It is for PC and mobile too. (Google Play). On Google Play is free.
ColinJS
50%
50%
ColinJS,
User Rank: Apprentice
10/5/2013 | 8:01:58 AM
re: 10 Top Password Managers
The description of SplashID safe is misleading as it confuses two different products. The basic SplashID safe requires no hardware and works in a similar way to the other products described. The image and description refer to SplashID Key Safe. Though the text does also mention mobile and desktop - where it does require installation.
TC
50%
50%
TC,
User Rank: Apprentice
9/19/2013 | 9:47:09 PM
re: 10 Top Password Managers
Tried several, but, have settled on 1Password. Works seamlessly on every platform I own.
Laurianne
50%
50%
Laurianne,
User Rank: Apprentice
9/12/2013 | 5:42:59 PM
re: 10 Top Password Managers
Thanks for the additional app ideas, all. We'll keep our eyes on doing a follow up. Let me know any other choices that should be considered.
ctcusick
50%
50%
ctcusick,
User Rank: Apprentice
9/12/2013 | 4:13:24 PM
re: 10 Top Password Managers
You mean Master Laurianne.
ctcusick
50%
50%
ctcusick,
User Rank: Apprentice
9/12/2013 | 4:09:15 PM
re: 10 Top Password Managers
Ya you did! (err, me too)

Like most of us, our contacts were unknowingly taken from us by many other cloud services and online offerings years ago.

I rarely see a 'Submit' button anymore, it's been made unscrupulously the 'Post' button or similar, but that's what we are doing, submitting. We submit to our greedy masters while making ourselves subservient. We get neither liberty or security. Have you seen the movie "Terms and Conditions May Apply"?

http://www.youtube.com/watch?v...
kdillon148
50%
50%
kdillon148,
User Rank: Apprentice
9/12/2013 | 7:51:50 AM
re: 10 Top Password Managers
And then there are those asinine complaints about the asinine complaints about slides shows. ;-}
Next...
kdillon148
50%
50%
kdillon148,
User Rank: Apprentice
9/12/2013 | 7:50:27 AM
re: 10 Top Password Managers
Anything to make you happy Laurianne!
<<   <   Page 2 / 4   >   >>
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

CVE-2014-2716
Published: 2014-12-19
Ekahau B4 staff badge tag 5.7 with firmware 1.4.52, Real-Time Location System (RTLS) Controller 6.0.5-FINAL, and Activator 3 reuses the RC4 cipher stream, which makes it easier for remote attackers to obtain plaintext messages via an XOR operation on two ciphertexts.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.