Monday, June 15, 2026

Security Boulevard Logo

Security Boulevard

The Home of the Security Bloggers Network

Community Chats Webinars Library
  • Home
    • Cybersecurity News
    • Features
    • Industry Spotlight
    • News Releases
  • Security Creators Network
    • Latest Posts
    • Syndicate Your Blog
    • Write for Security Boulevard
  • Webinars
    • Upcoming Webinars
    • Calendar View
    • On-Demand Webinars
  • Events
    • Upcoming Events
    • On-Demand Events
  • Sponsored Content
  • Chat
    • Security Boulevard Chat
    • Marketing InSecurity Podcast
    • Techstrong.tv Podcast
    • TechstrongTV - Twitch
  • Library
  • Related Sites
    • Techstrong Group
    • Cloud Native Now
    • DevOps.com
    • Security Boulevard
    • Techstrong Research
    • Techstrong TV
    • Techstrong.tv Podcast
    • Techstrong.tv - Twitch
    • Devops Chat
    • DevOps Dozen
    • DevOps TV
  • Media Kit
  • About
    • Sponsor

  • Analytics
  • AppSec
  • CISO
  • Cloud
  • DevOps
  • GRC
  • Identity
  • Incident Response
  • IoT / ICS
  • Threats / Breaches
  • More
    • Blockchain / Digital Currencies
    • Careers
    • Cyberlaw
    • Mobile
    • Social Engineering
  • Humor
Application Security Data Security Malware Security Bloggers Network Social Engineering 

Home » Cybersecurity » Application Security » Why we all Need a Password Manager

SBN

Why we all Need a Password Manager

by Nik Hewitt on October 10, 2022

What is a password manager?

A password manager helps users create unique and complex passwords and store them in an encrypted fashion, meaning each website, application, or program that needs login information can use a more secure string of characters, letters, and symbols. Users don’t have to remember multiple sophisticated logins, and this sets high standards of passcode complexity, giving each sign-in unique and optimal security. The user has one single, more simple login (or uses facial or fingerprint recognition) to gain entry to all their stored passwords.

It is possible to save passwords in your browser, which might seem like enough for the purposes of recall, but this isn’t ideal across multiple devices, and users may be sacrificing security. Password managers are invaluable in today’s digital security landscape, where we have logins on various devices – such as a Windows laptop, an OS mobile, online logins through browsers, on a tablet, or via a Linux desktop. They mean we only need to remember one password for everything – safely.

What is an account takeover attack?

Secure and complex passwords are needed to fight against the ongoing surge in account takeover attacks. Account Takeover (or ATO) is a type of attack where cybercriminals attempt to take control of online accounts by making use of stolen email addresses, username, and password combinations.

These are invariably sourced through phishing attacks (fraudulent messages designed to trick users into revealing sensitive information or to deploy the likes of malware), social engineering (manipulating users into revealing confidential information), or data breaches (security hacks and data leaks, where confidential information is directly copied or stolen). They are then sold in batches on the dark web, where they can be bought by cybercriminals for only pennies and cents. Cybercriminals then use this data to access accounts and buy goods, buy gift cards, steal personal information and digital assets like social media handles or URLs, or to steal currency.

A gift for cybercriminals

Password reuse is a gift to cybercriminals attempting account takeover. Whenever a password is reused, it gives a bad actor the opportunity to gain easy entry to a user’s other accounts and services, by using automated software to try that compromised password and username combination across thousands of other websites until they get the result they’re looking for. It’s also likely an account breach will be across multiple accounts, wherever the breached password details have been used.

Most people only use a handful of passwords, and if one account is breached or compromised this makes their other accounts each-pickings for black hat hackers. Different and complex passwords are important for everyone – individual users, businesses, family groups, everyone – in the fight against online fraud and the recent growth of ATO attacks. Using password managers makes it much easier to have varying passwords and optimal password configurations.

Password managers recommendations

There are quite a few password managers out there, but (having asked our helpdesk team for personal recommendations) here are a few we use ourselves.

Bitwarden is free, open source, and secure. It’s a great starting point, very user-friendly, and the perfect choice for anyone who doesn’t need all the extra bells and whistles of paid services. There’s also a paid version for family groups, meaning everyone has access to those elusive Netflix, Disney+, and Spotify logins.

1Password has a tonne of extras and is a paid-for service (only $3 pcm). It alerts users when passwords are weak or if they have been compromised and works in all operating systems and on all devices with web browser plugins. 1Password also has a group version, pro version, plus lots of extra features.

NordPass is another paid service, from the same team that brought us the world-renowned NordVPN. It also offers and family and business package, with all the features of 1Password, including a limited-feature free version.

The inconvenience and stress caused by breached passwords and hacked accounts aren’t worth it. Password managers are invaluable and, in this day and age, necessary in the quest to keep our digital assets safe. For a small investment and a little time in retrospectively setting a few new and better passwords, you can be far more secure and have the peace of mind of knowing your details are markedly safer against one of the biggest cybercrime attack vectors.

The post Why we all Need a Password Manager appeared first on Blog.

*** This is a Security Bloggers Network syndicated blog from Blog authored by Nik Hewitt. Read the original post at: https://www.imperva.com/blog/why-we-all-need-a-password-manager/

October 10, 2022October 10, 2022 Nik Hewitt account takeover, Application Security, Data Security, Digest, Industry Perspective, Malware, Phishing, social engineering
  • ← Data Security vs System Security and How Do You Protect Both
  • GUEST ESSAY: Privacy risks introduced by the ‘metaverse’ — and how to combat them →

Techstrong TV

Click full-screen to enable volume control
Watch latest episodes and shows

Tech Field Day Events

Upcoming Webinars

Agentic Software Delivery in 2026: How To Bridge The Gap Between AI Ambition and Delivery Confidence
Untangling the EU Cyber Resilience Act
The Software Supply Chain Just Got Harder to See
Building a Resilient Security Culture in the AI Era with AWS & Datadog
Toxic Flows: When Your Agent Skill Becomes a Supply Chain Attack

Podcast

Listen to all of our podcasts

Secure by Design

2 weeks ago | Jack Poller

Senator Sanders Wants to Own AI Companies — and Hand America’s Adversaries the Keys

3 weeks ago | Jack Poller

NIST’s Nine: The PQC Signature Race Moves to Round Three

3 weeks ago | Jack Poller

The Quantum Arms Race: Why Washington Just Wrote a $2 Billion Check to Nine Companies

4 weeks ago | Jack Poller

Beyond Moore’s Law: The Hyper-Acceleration of Autonomous AI Cyber Capabilities

1 month ago | Jack Poller

The Exception Economy: When Security Teams Stop Protecting and Start Negotiating

Press Releases

GoPlus's Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

GoPlus’s Latest Report Highlights How Blockchain Communities Are Leveraging Critical API Security Data To Mitigate Web3 Threats

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

C2A Security’s EVSec Risk Management and Automation Platform Gains Traction in Automotive Industry as Companies Seek to Efficiently Meet Regulatory Requirements

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

Zama Raises $73M in Series A Lead by Multicoin Capital and Protocol Labs to Commercialize Fully Homomorphic Encryption

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

RSM US Deploys Stellar Cyber Open XDR Platform to Secure Clients

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

ThreatHunter.ai Halts Hundreds of Attacks in the past 48 hours: Combating Ransomware and Nation-State Cyber Threats Head-On

Subscribe to our Newsletters

Most Read on the Boulevard

Oracle Issues Emergency Guidance as PeopleSoft Flaw Linked to Widespread Data Theft
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Futurum Group Report Sees Cybersecurity Spending Reaching $521.7B by 2031
HackerOne Unveils Agentic AI Platform to Discover and Validate Vulnerabilities Faster
Survey: Organizations Take Too Long to Fix Application Vulnerabilities
Atomic Arch npm Campaign Adds Malicious Dependency
Top 8 AI App Dev Platforms in 2026
CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive
South Korea Fines Coupang $400M Over Data Breach Affecting Millions
Cyberattack Shuts Down Major Australian Sugar Mills

Industry Spotlight

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
Cloud Security Cybersecurity Data Privacy Data Security Featured Incident Response Industry Spotlight Malware Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threats & Breaches Vulnerabilities 

Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks

April 12, 2026 Jeffrey Burt | Apr 12 Comments Off on Anthropic Mythos AI Model Strikes Fear in Trump Administration, U.S. Banks
The Day the Security Music Died
AI and Machine Learning in Security Cybersecurity Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight 

The Day the Security Music Died

April 8, 2026 Alan Shimel | Apr 08 Comments Off on The Day the Security Music Died
The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security
Featured Industry Spotlight Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Uncategorized 

The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

February 18, 2026 Jack Poller | Feb 18 Comments Off on The Lock, Not the Alarm: How Palo Alto’s Koi Acquisition Rewrites Endpoint Security

Top Stories

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams
Cloud Security Cybersecurity Data Privacy Data Security Endpoint Featured Identity & Access Mobile Security Network Security News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Threat Intelligence Threats & Breaches 

Google Sues Chinese Threat Group Using Gemini AI in Phishing Scams

June 14, 2026 Jeffrey Burt | 20 hours ago 0
ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances
Cloud Security Cybersecurity Data Privacy Data Security Featured Identity & Access Incident Response Mobile Security Network Security News Security Awareness Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Vulnerabilities 

ServiceNow Fixes Flaw That Could Lead to Unauthorized Access to Instances

June 11, 2026 Jeffrey Burt | 4 days ago 0
Zscaler Launches Industry-First Zero Trust Security for Agentic AI
AI and ML in Security Cybersecurity Featured News Security Boulevard (Original) Social - Facebook Social - LinkedIn Social - X Spotlight Zero-Trust 

Zscaler Launches Industry-First Zero Trust Security for Agentic AI

June 10, 2026 Jon Swartz | Jun 10 0

Security Humor

Randall Munroe’s XKCD 'Soniferous Aether'

Randall Munroe’s XKCD ‘Soniferous Aether’

Download Free eBook

[su_panel border="0px solid #ddd" radius="0" text_align="center" padding-top="0px" padding-bottom="0px"]
The State of Cloud Native Security 2020
[/su_panel]

Security Boulevard Logo White

DMCA

Join the Community

  • Add your blog to Security Creators Network
  • Write for Security Boulevard
  • Bloggers Meetup and Awards
  • Ask a Question
  • Email: [email protected]

Useful Links

  • About
  • Media Kit
  • Sponsor Info
  • Copyright
  • TOS
  • DMCA Compliance Statement
  • Privacy Policy

Related Sites

  • Techstrong Group
  • Cloud Native Now
  • DevOps.com
  • Digital CxO
  • Techstrong Research
  • Techstrong TV
  • Techstrong.tv Podcast
  • DevOps Chat
  • DevOps Dozen
  • DevOps TV
Powered by Techstrong Group
Copyright © 2026 Techstrong Group Inc. All rights reserved.
×

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.