Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ok so:

1) not use any manager => bad

2) use a 3rd party => pretty crap as the article says

3) use a built-in => great

Why would you ever use 2? This is almost as bad as Bitcoin, which not only solves nothing but also destroys a ton of energy.

I have never used a manager except for the builtins. And I would have never expected them (prior to reading this article) to be such utterly junk solutions to just inject additional code into the website itself. I thought there's a dedicated browser API or something.



3rd party password managers have a bunch of useful features, which is why I use one. Here are the first few that come to mind:

- portability, if I use chrome on my desktop, firefox at work, and safari on mobile I'm out of luck.

- built-in password managers only work for websites - I store many non-website security credentials in my password manager

- extra details - I often add the security questions for a site into my password manager

- compromised password warnings (maybe some of the built in password systems do this now?)


> - built-in password managers only work for websites - I store many non-website security credentials in my password manager

The one integrated with Firefox supports integration with an Android stored password entry tool. As a manager it's of very poor quality - better to do all your actual management from desktop Firefox - but as a tool to enter a stored password into an app, or to save the password you just entered, it works quite nicely.

> - compromised password warnings (maybe some of the built in password systems do this now?)

Firefox does have that service


2, 3, 4 are handled by Chrome, for example. These really are trivial features that any decent corpo can get right.

1 obviously isn't.


Oh, yes, I forgot a pretty important one, I don't want to upload all my passwords to google. Offline storage, and direct device-to-device syncing.


Last I checked I couldn’t export Chrome passwords (aka offline backup), couldn’t add non site passwords, and couldn’t manage non site based passwords/secrets with chrome password manager. And that was a month ago?


You can import chrome passwords from other browsers so I think you can also export them for backup.

I agree that I don't think you can add custom secrets.


Sure enough, looks like I was wrong re: export. Thanks! Unfortunately other things are still an issue - https://support.google.com/chrome/answer/95606




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: