WSJ: What Keeps People From Using Password Managers?
No pay wall: https://archive.is/HCtcT
Many of us are vulnerable to hackers and eager to secure our online accounts, but lots of us also refuse to use an obvious solution: password managers.
Why? Our research has found that the typical reassurances and promises about password managers just don’t work. Fortunately, our research also suggests there are strategies that can persuade people to get past the psychological barriers and keep their data safe.
[...] In a study I conducted with my Ph.D. student Norah Alkaldi, we found that the two most common methods of persuasion were ineffective in getting people to adopt password managers. The first is the “push” approach—the idea that by showing people the dangers of using simple passwords, recording passwords on their computer or using the same passwords at different sites, we would push them to adopt a safer approach. Users, we found, don’t respond to the push strategy.
[...] The other, “pull,” approach—focusing on the positives of password managers—didn’t deliver any better results.
[...] We discovered two types of “mooring factors” that keep people from changing their behavior.
[...] First, there was the effort required to enter all your passwords into the password manager.
[...] People also fear they will lose all their passwords if they forget their master password.
(Score: 0) by Anonymous Coward on Friday June 18 2021, @05:30PM
You have a lot of good points. I use a password manager, though.
I only use passwords on my computer at home, never on a mobile phone. If my computer breaks, that's why I have daily, monthly, and semi-yearly backups on separate USB hard drives stored in different locations. I store my passwords locally only, so I only have to worry about someone breaking into my computer, not some server somewhere. I've remembered my master password for many years now, and it's really in muscle memory by now.
The point is, for my use case a password manger is a good balance between risk and reward. My email does indeed show up on haveibeenpwned as part of several sites' data breeches, but the only thing I've lost thus far is that site's password... which I just change, because it's not used anywhere else so can't be used anywhere else.
As for "log in with x" services, I will never knowingly use anything from Google or Facebook (I even block google fonts). They are simply evil and anyone who trusts them is mad, IMHO.