Which Password Manager Is Better? Standalone or Built-In?

Should you use a separate, standalone Password Manager, or the Password Manager built into your browser?

Tavis Ormandy is an Information Security Engineer from England currently employed by Google as a member of their Project Zero team.

After discussing various technical problems with Password Managers, and after downplaying the need for "nuance," Tavis says:

"If you want to use an online password manager, I would recommend using the one already built into your browser. They provide the same functionality, and can sidestep these fundamental problems with extensions.

I use Chrome, but the other major browsers like Edge or Firefox are fine too. They can isolate their trusted UI (user interface) from websites, they don’t break the sandbox security model, they have world-class security teams, and they couldn’t be easier to use."

Tavis also recommends writing down and securely storing passwords.

Standalone Password Manager applications offer consumers more features and greater functionality.

But 70% of internet users access the internet using the Chrome browser. Its built-in Password Manager is highly-regarded and may be featured enough for many users.

Is there a reason we *shouldn't* tell consumers to use the built-in Password Managers of the top 3 browsers? Do we have solid, convincing evidence to claim that built-in Password Managers are unsafe if used as designed?

I'm very interested in exploring this question, and completely open to thoughts and suggestions.

@taviso

https://lock.cmpxchg8b.com/passmgrs.html

#InfoSec
#TavisOrmandy
#PasswordManagers

Password Managers.

uBlock CSS-Injection: Angriff über Filterlisten

Tavis Ormandy und Gareth Heyes haben mehre Sicherheitslücken in uBlock entdeckt, die CSS-Injections auf beliebigen Webseiten erlaubten.

Tarnkappe.info
Lesetipps: Bayern & IT-Sicherheit, DB App trackt, neue EU-Datenbank

Heute bei den Lesetipps: Apple I für 1 Mio. $, WhatsApp, Gamestop, Amazon Ring Kameras, kritische Bugs in Bayern, es menschelt bei GPG etc. pp

Tarnkappe.info
What did the Virusscanner #AI #KI learn from all these example exploits? #TavisOrmandy is evil! ;-) https://twitter.com/angealbertini/status/1305777408809873408 If this string is included, it must be an exploit. Not wrong but also not helpful. :-)
👼 Ąż 杏 on Twitter

“"Tavis Ormandy" is the new EICAR ? https://t.co/ZlOsowIWQY”

Twitter
LastPass Fixes Bug That Leaks Credentials - The company has patched a vulnerability that could allow malicious sites unauthorized access to us... more: https://threatpost.com/lastpass-fixes-bug-that-leaks-credentials/148378/ #googleprojectzero #insecurepassword #vulnerabilities #lastpasspatches #passwordmanager #chromebrowser #googlechrome #tavisormandy #lastpass #privacy
LastPass Fixes Bug That Leaks Credentials

The company has patched a vulnerability that could allow malicious sites unauthorized access to usernames and passwords.

Threatpost - English - Global - threatpost.com