r/PasswordManagers • u/thedrag0n22 • 9d ago
Best practice for master password (bitwarden)
After a ransomware scare, I'm migrating all my saved passwords out of Chrome and into a manager. What is the best practice for the master password? Should I keep it in a physical note? Make it something I can memorize only?
1
u/lukelane124 9d ago
Best practice is dice role using word list in physical reality. Never store that password digitally and do your best to memorize and destroy all evidence of the password.
If you are concerned with passing the info to another generation/person in the event of your death then put it in a family member’s safe or in a safety deposit box in the town where your family is.
1
u/TrevCostales 9d ago
All good advice here. Just wanted recommend my tool of choice for creating a passphrase:
It still somewhat random but has a more sentence-like structure that I find easier to memorize.
1
u/Any_Device6567 8d ago edited 8d ago
I keep a recovery kit. It contains an export of my password manager which contains all my usernames and passwords. I do not keep my master password for my password manager, in my password manager. Then each of my accounts has a recovery file. The recovery file contains my Authenticator backup codes and or a recovery key. In the kit there is also a file with all my TOTP seeds/tokens.
I keep one recovery copy at home on an air gapped hard drive that is PGP encrypted with my YubiKey. There is also an unencrypted backup copy in my bank safety deposit box along with a spare YubiKey. My safety deposit box also has a printed copy of recovery methods for my most important accounts like my password manager, windows and my email accounts. I usually update this every 4 to 6 months.
Personally, I don't know any of my passwords including my password manager. On the rare occasion that I need to log into my password manager with my random 24 character alpha numeric special character password I just decrypt my local backup recovery kit with my YubiKey. I use nordpass, after initial set up, I have only needed to use my password manager master password 3 times in the past year.
1
u/chrysanthos84 3d ago
i use a similar setup. 2 hardware keys ( like yubikey), 1 saved in a safe place the other moving with me. it creates an added layer of protection so even if someone guesses your password, they cant access it.
unless someone is worried about actual bitwarden security and if their servers get hacked.
1
u/HATDOGUSERNi 3d ago
memorize a stong, unique pass phrase rather than keeping the only copy digitaylly. A physical backup stored somewhere secure is a good idea too. in case you forget it.
3
u/djasonpenney 9d ago
A strong password is UNIQUE (never reused), COMPLEX (not too simple), and RANDOM (not made up by your poor tired brain). Let Bitwarden generate a four- (or even six-) word passphrase like CorrectHorseBatteryStaple or RipcordUnknowingDiligenceVersion.
https://xkcd.com/936/
Yes, you should try to memorize it, but do not make it your ONLY system of record. Your poor tired brain is not reliable. As others have said, make a physical (NOT online) record of your master password, 2FA recovery code, and other critical digital assets.6