Use the “passwords” feature to check if one of yours is compromised. If it shows up, never ever reuse those credentials. They’ll be baked into thousands of botnets etc. and be forevermore part of automated break-in attempts until one randomly succeeds.


And when that password manager gets cracked?
Got any examples? Because I have…some…examples of password reuse being a real-life problem.
LastPass recently, check Addie Lamarr’s channel on YouTube.
LastPass is the maximum shit. They got hacked like 3 times in a year and my company‘s password notes got leaked.
We are now with Bitwarden and this was the biggest security hardening measure we have taken.
Make sure whatever password manager you use doesn’t store the key on their servers. Bitwarden does this correctly (if you lose your PW, Bitwarden can’t recover it), and I’m sure some competitors do as well. LastPass apparently didn’t.
Just as an example, 1Password has a secondary encryption key that they can’t even recover. If you lose it, you’re fucked. I doubt the chances of that being cracked are any good at all.
Bitwarden has no secondary key, and the master key is never sent to the server. All they get is an email address and encrypted data. If you forget your key, your passwords cannot be accessed, which means an attacker is screwed too.
There are tons of ways to give yourself ways to “recover” your password that don’t compromise you in a breach scenario:
Maybe that’s how 1password works, idk, but I do recommend verifying that there’s no password recovery option on whatever password manager service you use.
I seem to remember that the passwords were encrypted so, all they got was the passwords people use for their password manager which because people were using the password manager and therefore had random passwords it didn’t really matter hugely.