Part of my own approach to cybersecurity has been to use a password manager for close to two decades now. My first password manager was Oubliette, a very basic utility program from Poland that existed long before any commercial password manager services appeared. Now seems like a good time of the year to consider adoption of a password manager service if you haven’t done so already.

 About a decade ago I began using a UK service, My1Login, which, much like Gmail, remained in beta release form for years. At the peak I had almost 200 accounts managed within My1Login but I knew the writing was on the wall when the company began specializing in corporate security management.

Fortunately about a year ago I decided it was time to move my accounts to another, more mainstream management service. After some thought I settled on the Canadian company 1Password, which is generally rated as one of the top three password managers of the past half decade or so.

Unfortunately there was no easy way to migrate data from My1Login to another service such as 1Password and so after signing up for a trial of 1Password I began investigating its operation by adding a few accounts. I quite liked the interface and decided to proceed with an account-by-account addition.

 Along the way I made two discoveries. Firstly, I decided to investigate each account to see if it was still valid and usable. That led to a column I wrote at the time to report how surprised I was to find many companies had simply vanished. For some others, which I deemed no longer of use, I looked for ways to delete the user account. In almost every case I found that businesses are eager to sign people up but are very reluctant to provide a “delete account” option.

My second discovery was that there are three separate and distinct domains for 1Password. Yes, three: 1Password.com, 1Password.ca, 1Password.eu.

You wouldn’t easily know that. I certainly didn’t know until I’d migrated most of my login accounts to the trial version of 1Password.

As far as I can tell 1Password does not make this obvious when you create an account, or at least it wasn’t obvious to me when I set about testing the service. 

For regulatory reasons you may want to have your data stored in a domain other than the dotcom 1Password domain. Canadians leery of having their information stored on U.S.-based servers will want to use the .ca domain.

It is fortunate indeed that I moved to 1Password when I did as My1Login shut down my “unlimited” account without warning. That’s not a scenario you want with a password manager service. I may still have had a handful of accounts on My1Login that I hadn’t migrated, but they must have been of little consequence as I haven’t noticed their absence. 

I think there is a debate to be had over password managers that make use of Chrome extensions. We know that a couple of years ago Google shut down a very popular extension, The Great Suspender (which suspended inactive tabs in Chrome). I remember when Google did this. I typically have 40+ tabs open on my Chromebook and Windows desktops. I was on the Chromebook when suddenly tabs began “dying.” 

It was Google taking action after The Great Suspender, having recently been sold, was spotted reading all open tabs on Chrome devices. Very serious matter. 1Password can make use of a Chrome extension. If you use 1Password (or any other manager that uses an extension) that way, then part of your security practice should be to minimize the extensions you use and to cull your extensions every now and then. If you don’t remember why you installed a particular browser extension, it’s likely time to delete it. 

Today’s password managers in many cases are more than just that. They’ve become places to store documents (banking, licenses, passports, health records) and all sorts of additional contact details. I’ve certainly come to appreciate that aspect of 1Password.

It’s also important that whatever password manager service you elect to use, it be usable on all the devices where passwords may be needed: desktop computer, laptop, mobile, tablet. That way no matter what device you may be using when prompted to create an account for some new service you can let the password manager handle both the creation and the subsequent synchronizing with the other devices.

In recent years there has been occasional mention of an end to password use. Generally, that means having another physical device, typically a mobile phone, to handle user verification. This is not the usual two-factor authentication method using a text message. Such verification is still potentially problematic.

Rather, this approach uses a passkey, actually a pair of keys, a public and a private passkey pair. However this passkey model requires industry cooperation. The big three, Google, Microsoft, Apple, are on board. Recently Google said it was rolling out passkeys support for Chrome, but in a closer look the company release said that for Windows users at least, this would be restricted to Windows 11.

Given that the adoption rate for Windows 11 hasn’t exactly lit the world on fire, this makes it unlikely passkeys will be on everyone’s to-do list any time soon. 

In the meantime, 1Password and other manager services are preparing to add passkey support, signaling that while not imminent, passwords are set to disappear over time.

Irrespective, as we head into a new year, consider making use of a password manager service, if you aren’t already.

Follow me on Facebook (facebook.com/PeterVogelCA), or on Twitter (@PeterVogel).

pvogel@outlook.com

Click here to send us a letter to the editor about this or any other article.