Question Is it okay to have your password manager not auto lock?

Help answer the author's question with clear explanations and useful steps.
I've been bouncing between different password managers and there's some I prefer over others, but I was wondering if it's fine for the average user to not have it auto lock or if it's a stupid idea
 
I've been bouncing between different password managers and there's some I prefer over others, but I was wondering if it's fine for the average user to not have it auto lock or if it's a stupid idea
It's a really bad idea for most people to turn off the auto-lock feature on their password manager.

Think of it this way, your password manager holds the keys to your entire online life. If your device (laptop, phone, etc) gets lost, stolen, or even just left open, anyone could access all your passwords if it's not set to auto-lock. Even stepping away for a second could allow someone to peek at your screen or quickly jump into your unlocked manager.

Plus, if your device ever gets infected with certain types of malware, an unlocked password manager makes it super easy for attackers to grab your credentials. Auto-locking adds an extra layer of defense, making sure you have to re-enter your master password or use biometrics (like your fingerprint) to get back in.

We all get sidetracked sometimes, and forgetting to manually lock your password manager is easy. Auto-lock simply makes sure that doesn't happen.
 
When your password manager autolocks, it also encrypts the passwords in memory, reducing the surface area for malware/other actors to copy the plaintext secrets from memory. The secondary (or primary for some) consideration is if you walk away from your machine without locking it first, leaving the password manager unprotected.

So the "safety" of leaving the password manager is nuanced. Copying from another process's memory on Windows can be done without elevated access. Although this is technically possible, AFAIK, this isn't the common way to attack third-party password managers. It's known to happen with elevated access for Apple Keychain. It has also happened with the Microsoft OS component lsass. If you can guarantee no malware and no intruder on your system, maybe leaving things unprotected would be fine.

In general, though, it's safer to at least lock your password manager with a PIN/biometrics or whatever other options it gives you. A fingerprint scanner on a Windows machine is a fantastic QOL investment.
 
When your password manager autolocks, it also encrypts the passwords in memory, reducing the surface area for malware/other actors to copy the plaintext secrets from memory. The secondary (or primary for some) consideration is if you walk away from your machine without locking it first, leaving the password manager unprotected.

So the "safety" of leaving the password manager is nuanced. Copying from another process's memory on Windows can be done without elevated access. Although this is technically possible, AFAIK, this isn't the common way to attack third-party password managers. It's known to happen with elevated access for Apple Keychain. It has also happened with the Microsoft OS component lsass. If you can guarantee no malware and no intruder on your system, maybe leaving things unprotected would be fine.

In general, though, it's safer to at least lock your password manager with a PIN/biometrics or whatever other options it gives you. A fingerprint scanner on a Windows machine is a fantastic QOL investment.
Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responses
 
Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responses
This depends largely on the password manager you use. Most password managers have a PIN unlock feature, using a short password or PIN through your Windows account use Windows Hello.
 
Last edited:
Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responses
I am familiar with three password managers. KeePassXC and Bitwarden offer Windows Hello as a way to unlock, allowing you to use either a Windows PIN or biometrics. Bitwarden also has its own PIN, without having to use Windows Hello.

The best-known brand is Kensington Verimark. Make absolutely sure that it is marked prominently as supporting Windows Hello; the descriptions are often confusing and tend to mix the capabilities of the device and Windows altogether. Cheaper, highly-rated Chinese scanners will work as well if you are comfortable using Chinese products.
 
I do not need autolock.
I open Keepassxc, autofill the credentials in browser, close Keepassxc immediately after autofilling.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top