Ask
232
@coworking_cass ·

Is anyone just using the browser's built-in password manager and calling it done? Password Managers

I have been on the browser one for about three years, it syncs everywhere I care about, it is free, and it fills things without me thinking. Every thread I read tells me to move to a dedicated app and I cannot tell if that is genuine advice or the enthusiast default. I am one person, one ecosystem, no shared logins, and my threat model is basically credential stuffing rather than anyone targeting me. What would I actually gain by moving?

8 answers Share
Report

Answering anonymously — a moderator will review it first.

  • @passphrase_perry · last wk. · 3 replies

    For your description, honestly, not a huge amount, and the enthusiast default is a real phenomenon. What you gain is portability between ecosystems, sharing that is not a screenshot, storage for things that are not website logins, and a vault that does not unlock every time your browser profile does. What you keep is convenience so good that you actually use it, which is the feature most people abandon a dedicated manager over. Using the built-in one properly beats owning a better one you fight with.

    287
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @quiet_stacker · last wk.

      That is the crux. On a shared or unattended machine the browser vault is effectively open, and most people never set the extra unlock prompt because it is off by default.

      141
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
    • @pivot_table_pat · last wk.

      "A vault that does not unlock every time your browser profile does" is the part nobody thinks about, and most of us leave a laptop logged in permanently.

      96
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
  • @blue_team_bex · last wk.

    Turn on the reauthentication prompt for autofill and the breach alerts, whichever you stay on. Those two settings close most of the practical gap for a single-person, single-ecosystem threat model, and almost nobody enables them.

    126
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @invoice_ivy · last wk. · 2 replies

    One practical thing the built-in ones do less well is anything that is not a username and password. Recovery codes, software licence keys, the passport number you need at 6am, a note about which email address you used for a utility. I moved for that rather than for security and would not go back.

    148
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
    • @passphrase_perry · last wk.

      This is the argument that actually moves people and nobody leads with it. Almost nobody switches for the cryptography; they switch because they needed a passport number at an airport at six in the morning.

      104
      Share
      Reply

      Answering anonymously — a moderator will review it first.

      Report
  • @openkey_owen · last wk.

    The migration cost is what should decide it, and it is lower than people say. Export to a file, import, delete the browser copies, done in twenty minutes. The reason to do it before you need to is that the day you switch phone platforms or take a job on a different operating system, doing it under time pressure is miserable.

    173
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report
  • @parquet_pile · last wk.

    Do it before you have 400 entries, not after. Everything about this gets worse with volume and mine was a two-evening job by the time I got around to it.

    64
    Share
    Reply

    Answering anonymously — a moderator will review it first.

    Report