24
The day I found out my password manager was the weak link, not my passwords
Last week I ran a security audit on my own accounts after a friend got hit with a credential stuffing attack, and I was floored to learn that 80% of data breaches come from reused passwords, not stolen ones. I'd been using the same master password for years thinking my complex 14-character passwords were enough, but the real risk was that I never enabled two-factor on the manager itself. Has anyone else checked their own setup after reading the Verizon DBIR report, or am I the last one to catch this?
1 comments
Log in to join the discussion
Log In1 Comment
paul_stone2920d ago
Look closer at that master password. Was it ever used on another site before you made it your master password? That's how most people get burned. Even a long password is worthless if it's been sitting in a data dump for years. I'd also check if your password manager even offers 2FA on the desktop app or if it's only for the browser extension. Some of them leave the desktop app wide open and that's a real easy hole to miss.
2