The Cyber Security Review | Tuesday, November 29, 2022
Using a password manager is an effective way to protect passwords, but there exists a need to protect password managers.
FREMONT, CA: Without assistance, it is nearly impossible to create and remember a different, complex password for each account. And these days, a password manager is the ideal place to look for that assistance. Strong and complex passwords will be generated, stored, and used consistently by a decent password manager, protecting accounts.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
However, since the password manager is home to the sensitive login data for all accounts, individuals must protect the password manager from any potential breach. Any trustworthy password management vendor will encrypt their account data, but there are steps to be taken independently to keep an account secure.
As a first step, create a robust master password to protect the account from unauthorised access. The second choice is to enable biometric authentication for your PC and mobile device's password manager. Thirdly, if a password management account is ever compromised, it may block anyone from accessing it by turning on two-factor authentication.
To Create a Master Passphrase
A master password will eventually be requested when first set up as the password manager. As the first security line for all login information, both on personal devices and in the cloud, that password needs to be strong and complex.
The master password should be simple to remember and write, though, as it will occasionally need to be entered. Utilising a passphrase as opposed to a password because of this. The appropriate kind of passphrase, made up of several words or phrases, might be safer than a complicated password while also being simpler to remember.
Individuals must use a string of words or phrases that have meaning or significance to create a passphrase that can easily be remembered. Along with numerals and symbols, like to blend uppercase and lowercase letters in writing. Just be certain they can recall master passphrases.
Use Biometric Authentication
In particular, when used in conjunction with password management, biometric authentication offers a safe and practical password-operational alternative. Use a face or a finger to prove identity rather than entering the master password each time you wish to activate the password manager.
They should be able to use any sort of biometric authentication that is integrated into the device or operating system with the majority of password managers. That refers to Windows Hello on a Windows computer. That refers to Touch ID or Face ID on an iPhone or iPad. For an Android smartphone, that entails fingerprint or facial recognition. Look in the password manager's security settings for a switch that will enable built-in biometric authentication. To verify the switch, they must provide a master password.
From that point forward, you can use the preferred authentication method to open or activate the password manager. The master password can still be required from time to time or to make a specific modification.
Enable Two-Factor Authentication
They want to ensure that, should a hacker ever figure out the master password, users can't access the password manager account on one of their own devices. Two-factor authentication (2FA) for this, which the majority of password managers should now offer.
Check the password manager's settings to check whether there is a two-factor authentication or a one-time password option. If so, turn on that setting. The authenticator app is the safest option if one selects between email, SMS, and other options.
Later, will receive the one-time password via your preferred method the next time you attempt to use the password manager on a new PC or mobile device. When prompted, provide the one-time password to authorise the new device to access the password manager. Users may see a list of all the enrolled devices on the password manager's account page, allowing them to look through them for any questionable ones and unenroll those they no longer use.
Other than the three security measures mentioned, some password managers might provide more. The best course of action is to review the security options available for a particular product and use any that will assist in safeguarding account and login information against fraud or security breaches.
More in News