Lad With a Dad
Level 1
I've been bouncing between different password managers and there's some I prefer over others, but I was wondering if it's fine for the average user to not have it auto lock or if it's a stupid idea
Open MalwareTips from your Home Screen or desktop. Follow discussions, find answers and pick up where you left off.
If you cannot find an install option, update your browser or use its bookmark option to keep MalwareTips close.
After installation, open the app and sign in. Enable push notifications in Preferences if you want alerts. On iPhone and iPad, push requires a Home Screen web app and iOS or iPadOS 16.4 or later.
Sign in to manage notificationsInstallation is optional. Your notification settings stay under your control.
It's a really bad idea for most people to turn off the auto-lock feature on their password manager.I've been bouncing between different password managers and there's some I prefer over others, but I was wondering if it's fine for the average user to not have it auto lock or if it's a stupid idea
Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responsesWhen your password manager autolocks, it also encrypts the passwords in memory, reducing the surface area for malware/other actors to copy the plaintext secrets from memory. The secondary (or primary for some) consideration is if you walk away from your machine without locking it first, leaving the password manager unprotected.
So the "safety" of leaving the password manager is nuanced. Copying from another process's memory on Windows can be done without elevated access. Although this is technically possible, AFAIK, this isn't the common way to attack third-party password managers. It's known to happen with elevated access for Apple Keychain. It has also happened with the Microsoft OS component lsass. If you can guarantee no malware and no intruder on your system, maybe leaving things unprotected would be fine.
In general, though, it's safer to at least lock your password manager with a PIN/biometrics or whatever other options it gives you. A fingerprint scanner on a Windows machine is a fantastic QOL investment.
This depends largely on the password manager you use. Most password managers have a PIN unlock feature, using a short password or PIN through your Windows account use Windows Hello.Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responses
I am familiar with three password managers. KeePassXC and Bitwarden offer Windows Hello as a way to unlock, allowing you to use either a Windows PIN or biometrics. Bitwarden also has its own PIN, without having to use Windows Hello.Are there specific fingerprint scanners you'd recommend for windows? Sounds much easier than having to type out a long password every few mins or hour. Also, I appreciate both of the fast responses
Members who viewed this thread in the last 5 minutes