Of course, password capture only works if the password manager recognizes that you're logging in to a secure site, so non-standard login pages can cause trouble.

Some products cleverly solve this problem by letting you manually capture all data fields on a page.

And if they breach one of your secure sites, stealing your username and password along with thousands of others, they can try that strong password on all of your other accounts. Your typical password manager integrates with the browser and captures the username and password when you log in to a secure site.

You need to use a strong, unique password for every site, and remembering that much information just isn't humanly possible. Enlist a password manager to both remember your existing passwords and to generate new, strong ones. The best password managers capture your credentials during account creation; when you change your password online, they offer to update the stored password for that site.

When you put all of your passwords into one repository, you had better be really, really careful to protect that repository.

Yes, your master password should be as strong as possible, but you really need two-factor authentication to foil any possible hack attack.

Many commercial password managers take advantage of this similarity and thereby streamline the process of filling forms with personal data.


