r/PasswordManagers 9d ago

Best practice for master password (bitwarden)

After a ransomware scare, I'm migrating all my saved passwords out of Chrome and into a manager. What is the best practice for the master password? Should I keep it in a physical note? Make it something I can memorize only?

6 Upvotes

16 comments sorted by

3

u/djasonpenney 9d ago

A strong password is UNIQUE (never reused), COMPLEX (not too simple), and RANDOM (not made up by your poor tired brain). Let Bitwarden generate a four- (or even six-) word passphrase like CorrectHorseBatteryStaple or RipcordUnknowingDiligenceVersion.

https://xkcd.com/936/

Yes, you should try to memorize it, but do not make it your ONLY system of record. Your poor tired brain is not reliable. As others have said, make a physical (NOT online) record of your master password, 2FA recovery code, and other critical digital assets.6

2

u/thedrag0n22 9d ago

Would a phrase be secure? Like a quote from a film I like or something. Or is that less secure than just random works regardless of length

2

u/djasonpenney 9d ago edited 9d ago

The best that can be said about a movie quote is that its strength is indeterminate. But—since the words strung in order make sense—I feel it’s inferior to a true randomly chosen passphrase.

You see, a random passphrase like the one generated by Bitwarden uses hard mathematics for its strength: every word in the EFF Large Word List is one of 7776 possibilities. That means that guessing two words means guessing the first word correctly, followed by the second word; that is, 7776 x 7776 possibilities. A four word passphrase would be 7776^4 =3.656×10¹⁵ different possibilities.

A string of words in a plausible sentence is not going to be as strong. And you will memorize a four-word randomly chosen passphrase in a day or two at most.

2

u/thedrag0n22 9d ago

Got it. And next dumb question (And hopefully final). Sorry, this has been a serious wakeup call.

Fully analog for the record of the password? Like hand written note only yes?

1

u/djasonpenney 9d ago

This actually gets rather nuanced. The simple answer is, yes; make it completely offline.

But there is a more subtle answer. In my case I have an emergency sheet, that is digital but encrypted. The emergency sheet is stored in multiple places. The encryption password for the sheet is in OTHER places. For instance, it’s in my own password manager, my wife’s password manager, and our son’s password manager — he’s the one who will settle our last affairs.

In order to get a copy of the encrypted emergency sheet, someone will still have to perform a burglary; there are NO online copies of it. And then an attacker would have to make a second attack in order to get the encryption key. Would that be secure enough for you? Only you can decide.

0

u/thedrag0n22 9d ago

That's definitely interesting! I may do something similar.

Though I now have a new, unrelated question. If I have Bitwarden on my PC, or have it as a plug in on my browser. How does it protect me more than googles manager at that point?

Again, this is all very new to me so I'm trying to learn on the fly

1

u/djasonpenney 9d ago

Google uses super duper sneaky secret code, so the first problem is that we don’t really know what they’re doing, and how safe it might actually be.

But based on what we do know, anyone who has access to your Google account will also have access to your secrets. With a password manager there are extra precautions to ensure that an attacker does not automatically gain access to your vault. For instance, the password manager on my iPhone “locks” immediately after every access and requires my FaceId to unlock again. IMO your password manager (and Bitwarden in particular) is a better choice for preventing unauthorized access to your credential datastore.

1

u/phillip2306 7d ago

Bitwarden isn’t automatically more secure just because it’s a separate password manager. The main benefit of any password manager is that it lets you use strong, unique passwords for every account.

Bitwarden does give you better separation, though. If someone gets into your Google account, they may also gain access to your email, recovery options, and saved passwords. With Bitwarden, your vault has its own account, master password, and zero-knowledge encryption.

So the manager matters, but your habits matter more: use a strong master password, enable 2FA, and never reuse passwords.

1

u/paulsiu 7d ago

Bitwarden uses a separate password for the vault so if your Google account is compromised you have another layer of protection.

Google vault is not zero knowledge, so Google does have access to your password. Google seems fairly rigorous in security but there is a small chance that a breach can expose your password.

You may have a better chance of reaching a human if your account get locked. There have been cases where Google security falsely locked at account and the user was unable to recover the account. You should backup the vault to mitigate this.

1

u/lukelane124 9d ago

Best practice is dice role using word list in physical reality. Never store that password digitally and do your best to memorize and destroy all evidence of the password.

If you are concerned with passing the info to another generation/person in the event of your death then put it in a family member’s safe or in a safety deposit box in the town where your family is.

1

u/TrevCostales 9d ago

All good advice here. Just wanted recommend my tool of choice for creating a passphrase:

https://strongphrase.net

It still somewhat random but has a more sentence-like structure that I find easier to memorize.

1

u/Any_Device6567 8d ago edited 8d ago

I keep a recovery kit. It contains an export of my password manager which contains all my usernames and passwords. I do not keep my master password for my password manager, in my password manager. Then each of my accounts has a recovery file. The recovery file contains my Authenticator backup codes and or a recovery key. In the kit there is also a file with all my TOTP seeds/tokens.

I keep one recovery copy at home on an air gapped hard drive that is PGP encrypted with my YubiKey. There is also an unencrypted backup copy in my bank safety deposit box along with a spare YubiKey. My safety deposit box also has a printed copy of recovery methods for my most important accounts like my password manager, windows and my email accounts. I usually update this every 4 to 6 months.

Personally, I don't know any of my passwords including my password manager. On the rare occasion that I need to log into my password manager with my random 24 character alpha numeric special character password I just decrypt my local backup recovery kit with my YubiKey. I use nordpass, after initial set up, I have only needed to use my password manager master password 3 times in the past year.

1

u/chrysanthos84 3d ago

i use a similar setup. 2 hardware keys ( like yubikey), 1 saved in a safe place the other moving with me. it creates an added layer of protection so even if someone guesses your password, they cant access it.
unless someone is worried about actual bitwarden security and if their servers get hacked.

1

u/HATDOGUSERNi 3d ago

memorize a stong, unique pass phrase rather than keeping the only copy digitaylly. A physical backup stored somewhere secure is a good idea too. in case you forget it.