Which password manager do you use?

There’s no reason to pay them anything at all really unless you need shared logins. Logmein didn’t screw anything up except their business model. Consumers are eating high on the hog.

Huh. Apparently I have over two years of premium left. I don’t quite know how that happened but I guess there’s no rush to cancel. Maybe they’ll come to their senses or add a genuinely useful premium feature.

I’ve got until Dec 2017 left on my LastPass premium. If they’ve not done anything useful to me by then, or given me a 50% off sale or something, I’ll just drop back to the free version. Although I may also look into using KeePass+Dropbox as an alternative, just in case LastPass starts cutting back on what’s available at some point in the future.

If you are on iOS, try out Mini KeePass - great companion app and have TouchID too.

Just remember fingerprints can be coerced/forced vs. a password is not.

  • You cant ‘change’ your fingerprints :)

That’s why I cautioned people not to use biometrics as a single authentication factor.

Lastpass allows you to unlock the vault with your passphrase and then use your fingerprint to open the app for X minutes afterwards. That’s what I do, and that’s what I recommend.

You can also pick a numerical PIN for the lastpass phone apps. If the PIN is long enough so reasonably secure (ie, 10+ digits), you may prefer that to typing in your passphrase. I don’t bother doing that personally, but it’s acceptable if you like it.

Yea, that is a pretty good idea, best of both worlds. I.e. “security” and ease of use in the same package. Not often you get that :)

Interestingly enough I just got my annual renewal notice from LastPass and it still shows $12, so I no sure if I’m grandfathered in or the increase will take effect next year.

Pin to unlock the phone, fingerprint to unlock Lastpass. Best of both worlds :)

Goes into effect on September 1, 2017

If you’re exclusive to Apple OS’s I’m not sure why you’d want to use anything other than Keychain unless you’re looking for interoperability with Windows, or have lots of specific websites than Keychain doesn’t recognize, or live exclusively in apps. There’s not a lot of technical information about Keychain out there, but I’d trust Apples fat sacks of cash to kee my privacy at this point.

Purchase an additional year before then, then.

key chain only works well if you have a Mac as well.

Right that’s why I said Apple OS instead of iOS or MacOS. But Keychain also doesn’t work through iOS apps, at least most of the time.

Surely a password or pin can be cooerced just as easily as a fingerprint if it really comes down to it. What kind of scenario are you thinking about here? Criminals threatening physical violence and demanding your fingerprint or password to access your phone and vault? You’re giving it up whichever method you use…

You can legally be compelled to provide your fingerprints, but not a password or PIN:

But really, who’s overly concered about stopping law enforcement from accessing your password vault?

I was more than happy to pay $12/year to support the product and to share my password vault w/ my wife.

At $24/year, I’m less than happy.

Yeah I have a long-standing $12 yearly sub with Lastpass too. If the mobile fingerprint feature is not behind a paywall, I’ll defintely reconsider the point of doubling that commitment.

Indeed - obligatory xkcd: