upvote
It is actually very hard to force password manager usage. You can encourage it, educate, but forcing it? How do you do that.
reply
Passkeys.
reply
Yeah. I prefer 2FA. My passwords look like 1bTsby#ZNaz1TJDDzglL&MmD&HOCMd^Cc and having a separate device with a TOTP token is more secure.

I won’t be victim of url jacking since the password manager feels the form. And if it can’t then the domain name is wrong.

And if you steal all the keys/passwords, unlike with pass keys, that’s not enough. I don’t like having all my eggs in one basket no matter how shiny.

reply
Passkeys are really long password locked to a domain, i.e. no different* than your setup.

Passwords are just a worse, hacky version of passkeys.

*They are private/public keys, so they can’t be MITM.

reply
How do you force password manager usage?
reply
Technically or socially? The second one is hard, the first one can be done easily - just require the passwords to be 14/16+ characters, multiple symbol domains and calculate tempo of input. Slower than 350ms between keystrokes - error message. Those who can type that fast already are using pw manager or you can just skip this 0.001%.
reply
Doing that will certainly get people to use a password manager.

But it doesn't say which password manager.

The most popular password manager is some text/word/excel document on the desktop.

reply
I have no evidence to back this hypothesis, but I wonder if that’s still more secure than using bad passwords.
reply
Everyone's password is now 1q1q1q1q1q1q1q1q1q1q!Q
reply