“But I don’t need a password manager app,” you say. “I use the same username and password for all my logins, so it’s pretty easy to remember.”
Congratulations. You have become what’s known in the online world as “a hacker’s dream”.
Why? Because once a hacker figures out your username and password on one site, they can use the same username and password to access every other site you use. And before you assume they couldn’t possibly know the other online sites you use, they can run a program that tries your username and password on hundreds—if not thousands—of sites in a matter of minutes. It’s not a question of whether they’ll find those other sites. It’s only a question of when.
“But it’s more convenient doing it this way,” you might say.
Sure it is. For now. But you may think differently when every online system you use—online banking, email, social media, etc.—has been compromised.
Even if you discover the security breach straight away, it can still take months—if not years—to recover. You could lose your savings, your business, or even your identity.
But there’s no point creating different usernames and passwords for each site if you’re just going to put them on sticky notes. Whether it’s a physical one on your whiteboard or an electronic one in your computer, they’re still incredibly easy to find and use without your knowledge.
How about storing them in a note-taking app such as Evernote or OneNote? Without any form of encryption, these apps aren’t much better than the sticky note app on your computer.
And for goodness sake, don’t email them to yourself so you can use a keyword search to find them. Not only will they be stored without any encryption, your email can easily be intercepted and read.
So, unless you have a perfect memory and can type incredibly fast, the only real solution to having unique, secure passwords is to use a password manager app.
1. You’ll no longer be “a hacker’s dream”. With password managers you only need to remember the username and password for the app. Then, whenever you access a secure website, it will look up the username and password you created for the site (which are securely stored online) and enter them automatically.
Because you don’t need to remember them all you can use a different username and password for each site, which is far more secure than using the same one for them all.
And if someone gets access to one of the sites you use, they still won’t be able to access any others.
2. You can use more secure passwords. The most secure passwords use a combination of upper- and lower-case letters, numbers and special characters. But when you have to remember them (and type them in over and over again), it’s tempting to use simple passwords that are less secure.
With a password manager, you can make them as long and complex as you want because it’s the password manager app that remembers them all and types them in for you. It can even create new passwords automatically, such as “Sp?45AqG&&l6p#BzK”.
These random, nonsensical passwords are far more secure than the names of your pets, family members, favourite movie or other commonly used passwords. And the chances of hackers guessing your password, even with the software they use to generate them automatically, is extremely low.
All you need to do is choose a strong password for your password manager.
3. Your login details will be encrypted. If you’re worried whoever created the password manager will have access to all your usernames and passwords, relax. All of your information is encrypted (scrambled), and only the strong password you use to log in can decrypt (descramble) that information. It’s the same level of security used with Internet banking, and a lot more secure than sticky notes.
4. You can use two-factor authentication for even better security. Let’s say someone works out the username and password you use for a website. That means they can log onto the site, enter your details and they’re in, right?
Not if you’ve set up two-factor authentication. Instead they’ll be asked to provide another piece of information only you can provide. It could be a random code to your mobile number via SMS, or one only your phone can generate. It may even ask for your fingerprint via your smartphone.
And without that other bit of information, they won’t get access.
Two-factor authentication can be used not only on websites, but also the password manager itself. And while some people find the extra step inconvenient, it’s an added layer of security that’s well worth considering.
5. You can share passwords more securely. Let’s say you need to give a staff member or contractor access to financial or other sensitive data (a common scenario when working with freelancers and remote workers). One option would be to give them a username and password, which they would enter to access the information. But what’s stopping them from writing them on a sticky note, or emailing the details to themselves (or worse, someone else)?
With a password manager you can set them up with a password that is never revealed to them. It will log them in, but they never see what it is, and therefore can’t share it or even write it down.
6. You can revoke a person’s passwords instantly. When people leave your organisation for whatever reason, you need to make sure they can no longer access your information. If they’ve written their passwords down somewhere you have no choice but to manually change or remove the password on every system they had access to.
But with a password manager you can revoke all of their logins easily—and instantly.
If you love evaluating apps and technology, check out the apps mentioned earlier and see which one best fits your needs.
But if you want to start using a password manager straight away, choose LastPass. It lets you have a Free or Premium plan for your personal accounts and an Enterprise plan for your business. You can even link your personal and business LastPass accounts so all your logins are in the your own LastPass view. This saves you having to log in and out of separate LastPass accounts whenever you need to switch from a business-related web app to a personal one.
And don’t worry. Even when you link your personal and business LastPass accounts, team members using your LastPass Enterprise account still won’t be able to see or access your personal logins.
It really is the perfect combination.