Password Managers

I had cause to think about remote Password Managers last week. My conclusions and notes.

  1. They are an attractive target, and if on the internet easy to reach
  2. They lengthen the code paths and thus increase the attack surface.
  3. They provide little defence against operating system & browser vulnerabilities and zero defence against social engineering or court ordered remediation.
  4. They ease the use of complex and strong passwords; they can through indirection ensure that real keys are not known (and thus contradict my statement that they cannot protect against social engineering attacks).



