MAX: First it was like, “don’t tell anyone or write down your passwords, they all need to live in your mind”. And then it was “use a password manager”. If you’re trying to keep them in your mind, you’re doing it wrong. And then it was like, “you got to change your passwords all the time”. And now, we actually don’t think that’s a very good practice.
ROSIE: I’m Rosie Guerin and you’re listening to The Wirecutter Show.
ROSIE: Hey, it’s Rosie. Today, we’re talking about passwords.
Wait, wait, wait, wait, wait, wait, before you skip this episode, because how could a conversation about passwords possibly be interesting? I will say number one, my guest, Max Eddy is, he’s a staff writer here at Wirecutter and he writes about data, privacy, security, and how to stay safe online.
And number two, yes, this is one of those things that you can tell yourself it’s okay to ignore, but our lives are online. We bank online, we date online, we shop online, we share our credit card information, social security numbers, you get the picture.
So, if you’re going out of your way to retain your privacy, getting started with a password manager is a good start. More about those and a primer on passkeys with Max Eddy after the break.
ROSIE: Welcome back. My guest today is Max Eddy, Max is a staff writer here at Wirecutter who covers privacy and security. Max has been on the show twice now talking about the importance of traveling with a VPN, check that episode out if you haven’t, and another time to talk through an article published last year, that I really loved, called, I Tried and Failed to Disappear on the Internet. That was a banger. Welcome.
MAX: Thank you. Always happy to be here.
ROSIE: Good to see you. Today, we’re going to talk about three main ways to increase your online safety. So, password managers, two-factor authentication, and passkeys. I think people maybe generally know why passwords are important, but can you just, top line, what is the biggest risk you face if you don’t have good password hygiene?
MAX: I really like the way you put that, because hygiene is a habit, it’s something that you do all the time, and I think that that’s what you need to think about with security. You’re changing habits, you’re changing the way you live your life. And that sounds huge and complicated, but the nice thing about passwords, password managers, and passkeys, what we’re talking about here, this stuff actually makes your life easier. So, the biggest risk that you face if you don’t have good password hygiene is that your accounts could be taken over by somebody else, that’s what it comes down to. The main thing between you and your accounts online is passwords and other technologies around that.
ROSIE: And that could be anything from your bank to your whatever. I mean, anything.
MAX: I admit, my job makes my password usage a little insane for that how to disappear story, I discovered I have like 360 passwords.
ROSIE: That’s a lot of passwords.
MAX: Most people aren’t like that. But most people probably have dozens of passwords that you use for everything from banking to online shopping to your job.
ROSIE: So, we talk about hygiene, habit-forming, we also probably should talk about fatigue. I mean, there’s this thing you talk about security fatigue, and I think it’s real and it’s risky, but it’s also very relatable. Can you talk a little bit about it?
MAX: Over the last, let’s say 20 years, I think people have been feeling very jerked around by the advice that they’re given about how to be safe on the internet. First, it was like, don’t tell anyone or write down your passwords, they all need to live in your mind. And then it was, use a password manager. If you’re trying to keep them in your mind, you’re doing it wrong. And then it was like, you got to change your passwords all the time. And now, we actually don’t think that’s a very good practice. And then, it was you have to add two-factor authentication to everything. And then people are like, “What’s 2F? What are all these other systems you’re now asking me to learn?” And now we’ve got passkeys, and even newer technology. I really empathize with people who are burnt out on this, from my perspective, as someone who covers this, it’s exciting because we’re fixing a fundamental problem about technology. Passwords are a fundamental problem.
ROSIE: And talk about why they’re a fundamental problem.
MAX: Well, passwords are a fundamental problem because we’re bad at making them, and computers are great at guessing them. And if they are exposed, they cause all sorts of problems. And because we’re really bad at making them, we’ve come up with all sorts of shortcuts around that. So, a lot of people have told me, it’s like, oh, I don’t have a problem with passwords, I have one good password that I use everywhere, and I was like this. I remember when I was in college, I’m like, “I’m so smart, I’ve got a crappy password that I use for crappy sites, and a good password I use for good sites.” And if you plug either of those now into their calculators that’ll tell you how long it takes for that password to be guessed, it’s seconds and minutes.
ROSIE: Oh, man.
MAX: It’s bad. That is the problem.
ROSIE: What is it about reusing passwords that’s not good?
MAX: If you are reusing your password, if that password is exposed or stolen in any way, all of those sites are now vulnerable. Because the first thing that a savvy attacker is going to do when they get their hands-on credentials is to try them on multiple sites. And if it’s a more targeted attack, where they might have some kind of information about the sites where you might have accounts, and there’s a number of different ways to get that information, then they have something to work off of. So, great example, again, I’ll just air my dirty laundry here. So, there was this big data breach at a news site in its comment section, and that password was the same one I was using on Facebook. And when that happened, when that story broke, within a couple hours, someone was making posts as me on Facebook. And that’s annoying.
People are like, “Oh, what’s the worst that could happen?” Well, someone impersonates me to my family and gets money from them. You don’t need to be anyone special for that to happen to. And that’s really frightening, that does a lot of damage, not just your personal reputation, but everyone you care about. And this is another deep idea around security. We talk about it a lot in terms of protecting yourself, and if that doesn’t motivate you because of security fatigue or whatever, think about the people you love and the people you care about, because anything that affects you is going to affect them because if your email gets hacked, if your Facebook account gets hacked, it will be used against the people you care the most about.
ROSIE: Okay. So, to that end, we come to password managers. What is a password manager and why is it useful?
MAX: So, a password manager is an application that saves, replays, and creates passwords for you. It does everything with passwords that we are bad at. So, you can use it to create really, really, really long passwords. You can create unique passwords for every site and service you have, and then you don’t need to remember them when you go to those sites because the password manager pulls it up and fills it in for you. That fixes so much of the problem with passwords, it doesn’t fix everything, and there’s a lot of other problems that remain, but it is a very straightforward thing that people can do that will make you safer online. Password managers, two-factor authentication, those are the things that every security expert has been telling me my entire career. If people do these things, they will be objectively safer online.
ROSIE: I think it changed my mom’s life when I helped her get set up with a password manager, because prior to that she had an index card, fraying at the edges, and you couldn’t read them because the ink had bled, and it was just like there has to be a better way.
MAX: Yeah. There’s nothing wrong with having your own system, but there’s not a offline system that I can imagine like that is easier than a password manager.
ROSIE: Right.
MAX: It has its advantages. No one’s going to get that card, that card is the safest thing on the planet. But a password manager is more flexible. When you go to change your password, for whatever reason, the password manager should capture that information and update itself. And there’s other little things that when you start using a password manager, you get the benefit of. The main one of course is your security is better, you also don’t have as much cognitive load, you don’t have to remember your passwords, you just need to remember the password for your password manager. But smaller things like your password manager is configured to show the password for the site that you’re on, if you’re on a site and you know you have a password for it, and your password manager doesn’t show up, you might be on a phishing site.
ROSIE: Oh wow.
MAX: It’s a little thing like that. That’s not even really its intended purpose, but it’s another little clue that maybe you should slow down and take a look at what you’re doing.
ROSIE: I had not thought about that. Are there things you could expect a password manager to do beyond just storing your passwords and helping you fill in when you’re on a site?
MAX: One of the main ones is that it can store and retrieve any sensitive information. So, I put my known traveler number, the thing you’re supposed to use for pre-check when you go through airport security, I keep that in my password manager because I do need to pull that out periodically, and I will never remember where it is. So, it’s in my password manager. Credit cards are in there too. There’s a lot of other ways to do this kind of auto-fill stuff, but a password manager is very flexible and it’s always with me. So, that’s one thing that I use it for. One of the main things that password managers do is that they create complex, long, unique passwords. So, you don’t have to do any of that, and you don’t have to remember any of that. And you can change the rules for how that’s generated to whatever meets your needs at the time. They’re very, very flexible.
ROSIE: Like letters, numbers, special characters, extra special characters.
MAX: Yeah, exactly. And one of the features I love is some password managers will actually remove similar characters. So, is that a lowercase L or a vertical line? It gets rid of that so you don’t have to worry about that, or it will create past phrases that use whole words, or there are lots of different ways that you can adjust it to your situation, whatever makes sense. One thing I do recommend that people do is just go ahead and make it as long as the website will accept. I use 30 character passwords because why not? I’m not remembering any of this, that’s the password manager’s job, I’m paying it to do that.
ROSIE: Yeah. Okay. So, paying. That is I think a good segue into what your picks are. What does Wirecutter recommend in terms of password managers?
MAX: So, 1Password is the best password manager we’ve tested, and has been so for quite a while. 1Password is just very easy to use, almost a pleasure to use in many ways that it just blows the competition out of the water in that respect. It is just the simplest, friendliest way to use a password manager. It’ll walk you through the whole process of it, it also does some very unique things with how it manages your password to access it. It’s a little bit different than others, but it’s still pretty intuitive, and it’s more secure. And by and large, it seems that people are able to figure it out and work with it, which is great. We also recommend Bitwarden as a free password option, it also has a paid subscription, and that’s just another really good password manager. It’s open source, and it’s not as flashy and slick as 1Password, but it is very good at what it does.
That’s the one I use. A big truth in security in general is even a not good password manager is better than no password manager at all, and most password managers are good. So, if you’ve already been using the built-in password manager in Google, or in your iPhone, or what have you, that’s great, stick with it if you want to stick with it. But the password managers that we recommend have more features, they’re easier to use, and they can just do things that those default password managers can’t.
ROSIE: I’ve been using Dashlane for a while. It’s fine, I mean, it’s a password manager and it works.
MAX: Yeah.
ROSIE: I have thought about using something else, but I’ve been intimidated by the idea of migrating from one password manager to another. Is the best I can hope for there starting over?
MAX: No. To move between password managers is very straightforward. Every password manager will let you import and export passwords from another password manager. This was actually one of the things I tested in my most recent round of testing, was how easy was that process? What was hard about it for these products? Most of the time how this works is you hit export, it spits out a spreadsheet of all your passwords and login information, and then you go to your new password manager, you drag and drop it on there, and it does the rest. I will take this opportunity to just remind people something, delete that file afterward because that file has all your passwords in it, you really don’t want that.
ROSIE: Empty the trash.
MAX: Yes, absolutely. And then, I always encourage people to take their time with stuff. It often feels like you have to make big changes really fast. If you’re migrating from one password manager to another, try it out for a while. See if it got all the stuff that you needed. Do you have any problems? And then after however long you need, then you can start deleting and shutting down your old password manager. There’s no reason that you got to dump it all and do it all at once.
ROSIE: In addition to that, I’m wondering, because I use Dashlane, but I also use the password manager that comes on the iPhone, is there any reason I shouldn’t be using more than one?
MAX: I think that it’s just easier for you to know where your passwords are.
ROSIE: Organizationally.
MAX: Yeah. And again, if it works for you, it works for you, and I’m not going to tell you otherwise. But if you’re ever in a situation where you’re like, I don’t know where that password is, I know I have it, but I don’t know where it is, that can create a problem. And all the password managers that we recommend are cloud-based. When you have them stored on the cloud securely, they’re available on all your devices all the time. So, that gets around the problem you’re talking about, right? You know that it’s in the password manager and the password manager is on all of your devices.
ROSIE: So, when we talk about migrating slowly or even just getting started from not using a password manager to using one, do you need to change all of your passwords at once?
MAX: No, absolutely not.
ROSIE: That’s also intimidating.
MAX: It’s hugely intimidating. I actually think the best way to go about this is to prioritize the most important things, banking, social media, one that surprises people, your personal email, or whatever email you use the most, you absolutely should be putting the most amount of security on that. The forgot my password function on any website, if a attacker is able to get ahold of your email and then use that forgot my password tool, they can just start taking over all your accounts, and there’s very little to stop them. So, that’s number one, get your personal email sorted out. And then, I think it’s fine to move slowly as you go to websites, log out, log back in, let the password manager capture it as you go.
Most of the password managers that we recommend have very useful tools that can identify weak, reused, and breached passwords. So, use those tools. Start with the breached passwords, those are the ones that are out there somewhere. So, fix those, and then work down your list of stuff. And maybe set a day, like every Thursday I update five passwords or what have you.
ROSIE: Hygiene.
MAX: Yeah. If you tried to do it all at once, you’re going to burn out. And I think the worst thing that people can do with personal security is just give up. It always feels like we’re out of control and that these huge forces are pushing against us, but actually you have a lot of agency in this stuff, and it can actually really empower you.
ROSIE: OK, quick recap.
Passwords can be a real pain and password managers can help. They’re integrated in many phones now. And Max has some great recommendations on our website. Online security is always evolving. It’s very very real to feel fatigued. Baby steps! Using some measures is better than nothing. So try out two factor authentication, 2FA. Try out password managers. And stay as safe as you can.
Now Max, in your article on password managers, you have four additional tips to help get the most out of your password manager, so let’s run through them. The first you mentioned before, creating extra long passwords.
MAX: Yeah. Our password manager’s doing the heavy lifting, why not make it as long and as crazy as you want? The caveat here is that not every website is cool about this. There are to this day still websites that won’t let you do longer than eight characters, and I cannot believe these are still in business. That’s insane. But in general, make it as long as you can because you don’t have to worry about it. And the longer, the more complex, the better.
ROSIE: The second tip here is about securely sharing passwords and other information, talk about that.
MAX: Yeah. Password managers usually have tools built in to share passwords or any other information that you have stored in the password manager with other people. Typically, other users of the password manager. So, you might have to get your family on a family plan if you want to do this, but not all the time. And it puts some protections around it. Now, you always got to keep in mind that anytime something leaves your control, someone can do something bad with it. So, don’t share it with people you don’t trust, keep tabs on it, use the tools that they provide to limit its access, but just be aware that you only want to share it with trustworthy people. An extension of this is that some password managers are set up to actually help family members inherit passwords from people that have passed on. You don’t want to get locked out of your parents’ or grandparents’ accounts. This is actually a very useful thing to do.
ROSIE: You have, protecting your passwords from prying eyes, what did you mean by that?
MAX: A very understandable concern about password managers is that it’s like a single point of failure. If someone can get your password manager, they get everything, and that’s very understandable. There’s a lot of things you can do to keep that from happening. You’re going to put 2FA on your password manager so that even if someone gets your password, they’re not getting into your password manager. All the password managers that we recommend use end-to-end encryption so they can’t even access your data. These are the things that are out there to protect your information. Now, what happens when it’s on your phone and then your phone is not in your hands anymore? That’s a big problem. So, if your phone is confiscated or it’s not properly secured, you want to make sure you’re doing something about that.
So, look at how often your password manager requires you to re-authenticate, set that to something low that works for you, maybe it’s every day, maybe it’s every 44 hours, whatever works for you so that every now and again you do actually have to put your password into your password manager to prove that you’re you. Learn how to use the tools that help you track and secure stolen or lost phones. Both Apple and Google have this for their devices, they’re very powerful, they’re very useful. When you’re traveling, consider logging out of your password manager altogether, and logging back in when you get to a safe location. If you lose your phone or your phone is stolen while it’s unlocked, that can expose a lot of your information. So, just don’t even have that on there. 1Password has a similar tool called Travel Mode that lets you limit what passwords are available and what circumstances. We also recommend learning how to temporarily disable biometrics on your phone.
So, biometrics are really convenient and great, it saves you a lot of time, and they’re very secure, but it can be done against your will. Someone could snatch your phone, hold it up to your face, and then that could open your phone or someone could put your finger on the fingerprint reader. So, most phones now do have a way to deactivate biometrics temporarily, any situation where you think your phone is going to leave your person. So, like airport security, you’re in a really long line in a place you don’t know, you’re at a concert or something, why not just take a minute to disable biometrics temporarily? And once you put in the passcode, biometrics are back on. So, it’s very, very simple. But it’s always important to think about what happens to your devices. And this is beyond password managers, so excuse me. But you always want to think about what is happening to your devices when you don’t have control of them.
ROSIE: The last piece of advice here is enabling two-factor authentication, 2FA as you have referred to it, and passkeys on your accounts as you go through and upgrade your passwords. I want to pause before you explain those because you wrote another great article on the site called, Passkeys Are the New Passwords, You Should Start Using Them Now. And that goes into detail about what passkeys are and why they’re important. So, I want to take a quick break and dig deeper into that on the other side. We’ll be right back.
ROSIE: Welcome back. My guest today is Max Eddy, a staff writer here at Wirecutter, who covers privacy and security. This episode is about password hygiene and how to keep yourself a bit safer online. So, before the break, Max, we discussed the importance of using a password manager and all of the ways it can help you organize your passwords to stay safer online.
Now, I want to talk about two-factor authentication, 2FA, and a new tool I’ve been seeing and hearing about more and more, passkeys. So, tell me everything you know about two-factor authentication and why it’s useful. Or maybe not everything because you know a lot of stuff.
MAX: So, for most people, 2FA is another thing that you do after you enter your password. So, you’ll have to enter a code that’s sent to you on your phone, or generated by an app, or you’ll have to do some other thing. So, a lot of people look at it as like, oh, two-factor, it’s your second thing you have to do, and this is where it gets philosophical. It’s actually from this sort of theory of authentication, where there’s three different ways to authenticate yourself to anything else. There’s something you know, something you have, and something you are. So, something you know is a password. It lives in your brain, you know it. Something you have is like your phone. When you are using a 2FA app on your phone, like Duo, or Google Authenticator, or Authy, that is proving that you have your phone. That’s the thing you have.
And something you are is biometrics, like a fingerprint scan or a face scan. So, when we take two of those three and put them together, they’re different kinds of authentication, and it’s really unlikely that an attacker would be able to get both of them. And that’s two-factor authentication, two different factors to secure your accounts.
ROSIE: Professor Eddy. So, does 2FA have any limitations then to bear in mind? Because it sounds very, very secure.
MAX: It is very, very secure. And I really want to emphasize, like I said with password managers, we’re going to start talking about the drawbacks of 2FA, which are real and important to understand, but any 2FA is better than no 2FA, in the same way that even a mediocre password manager is better than no password manager. So, really want to underline, if you take nothing from this, please just get a password manager and turn on 2FA, I will sleep so much better if just one of you does it. So, the big drawback of 2FA is that if you don’t have your second factor, if that other thing is not available to you, you’re not going to be able to easily log in. So, if you are, for example, using an app on your phone to generate 2FA codes, and you don’t have your phone, then you will not very easily be able to log into your account.
A lot of caveats to this. One of the easiest ways to prevent this from happening is to create what are called backup codes. These are a list of numbers and letters typically that are generated on whatever site it is you have an account, and you store them someplace safe, print them off, put them in your password manager, someplace very safe, because you can enter these codes in an emergency, prove who you are, and get past a lot of the extra layers of security. Another big concern with 2FA is that some kinds of 2FA can be intercepted. So, for example, if you’re getting a code sent to your phone, it is possible that someone could intercept that and then use it before you can use it. So, in general, we tell people not to use 2FA over SMS, that’s by text message, whenever possible. For better or for worse, it is probably the most common kind of 2FA.
And again, bad 2FA is better than no 2FA at all. Along with a 2FA that can be intercepted, some 2FA can be phished. So, if I’m generating codes on my phone, if I put that into a phishing site, it doesn’t matter, now the bad guy has it, they can use it. There’s a time limit on these, but these attacks have been very well conceived, they will probably work. So, always be very careful about where you’re putting in this information. We said this earlier, but sometimes a 2FA could be done without your knowledge or consent. If it’s biometrics, your face could be read, or your fingerprint could be read without you necessarily wanting or knowing that that was happening.
ROSIE: I’ve seen that in the movies.
MAX: Yeah.
ROSIE: Okay. So, moving over to passkeys. I’ve been hearing about passkeys, I admittedly have not really waded into this yet. What is a passkey? How are they developed?
MAX: On a technical level, a passkey is a digital credential that uses asymmetric key encryption to securely identify you to a website. You don’t need to know that.
ROSIE: Well, that I know.
MAX: You don’t need to know that.
ROSIE: But what else is it? Yeah.
MAX: Yeah. And this is where it gets kind of tricky because much like The Matrix, no one can be told what a passkey is, you kind of have to see it for yourself. So, go to Google, where you probably already have an account, create a passkey, try it out. Go to our story on Wirecutter, take a look at the screenshots, we walk you through the whole process so you can see what it’s like. I really think that once people see it and get any kind of familiarity with it, the value becomes immediately obvious. A passkey is a lot like a password, it’s intangible, it lives in your devices and on the cloud. But unlike a password, you don’t interact with it at all anymore. So, it is a way to authenticate yourself to a website without using a password, it has a lot of benefits. The first and most obvious one is that it is a secure exchange. That passkey can’t be forgotten, it’s very difficult for that to be breached. If the website gets breached, they’re not going to be able to get your passkey. You’ve got that, that’s yours.
It requires additional authentication. You put your pin in, you do a scan or something so it’s more layers of security around it. And importantly, each passkey only works with the site where you created it. So, it makes it very difficult for that to be fished and it makes it very difficult for that to be cloned in any way.
ROSIE: So, you are going to, theoretically, have many, many, many different passkeys. You have the same number of passkeys as you would passwords.
MAX: Yeah, you’re going to have as many passkeys as you have websites at minimum, and it is just this way to have a completely secure exchange. The goal here, the thing that I think people need to take from it, bottom line, passkeys replace passwords, you don’t do passwords anymore. We leverage the technology that we have, that is very, very good at creating secure exchanges, and we use that instead of passwords. We cut out all of the gooey stuff in the middle that’s been causing us problems for as long as we’ve had passwords.
ROSIE: What is it going to look like when I’m on my phone or online and I encounter a passkey?
MAX: So, if you have a passkey already on your device, when you start the login process, either when you land on the login site or when you enter just your username, a little thing pops up and says, “Hey, you’ve got a passkey for this, let’s use that instead.” Or you might have to click a button and say, “I have a passkey,” and then it’ll use that instead. And then it just logs in. You’ll have to sometimes enter a pin number, but that’s it. I wish there were more steps because it would feel so much more tangible, but again, it just works. It’s kind of great.
ROSIE: So, how do you get started using them? Because that example, I already have a passkey for whatever website, how do I get my passkey? How do I get started?
MAX: Yeah, I think the best way to get started is to sort of try it out and learn how to use it. Google accounts are really good for this. A Google account will let you create as many passkeys as you want for an account. You can play around with it, it’s very, very simple and flexible. So, yeah, log into your Google account, go to your account settings, create a passkey, go through that process, and then try it out, and you’ll be able to work through that flow.
I feel like we’re not doing a great job of explaining this, and it is just because it’s very, very straightforward and simple once you do it. And we talked about security fatigue earlier, that it’s hard to conceptualize this. We’re so used to passwords, and this takes that away and can feel like you’re losing control, it can feel confusing, it is so different and that’s scary and weird, but once you start doing it’s like, this is so much easier.
ROSIE: Well, I’ve almost felt that it’s too easy because at least with a complicated password that exists in my password manager, I know that there are 15 dollar signs and capital letters and lower letters and it’s going to be complex. With a passkey, in my experience so far, it seems too good to be true.
MAX: Yeah. And it’s that intangibility of it, right? There’s nothing there. In your password manager, you could look it up and see the big long password and feel assured that it does something. And this is just this weird contradiction with passkeys, where if you actually saw any part of it, it wouldn’t make any sense at its technical level, but at the person level, it’s as seamless as can be. And this is by design. A lot of work has gone into making this fast, seamless, reliable. It’s supported by Apple, Microsoft, Google, it’s hopefully going to take off and become the new password. And it’s continuing to evolve, there’s changes happening to it, making it a little bit more flexible, a little bit easier.
The way passkeys are designed is that the sites you create passkeys on, they don’t have a copy of your passkey. So, if there’s a data breach on that site, that doesn’t affect you, your information is safe. This is part of why passkeys as a concept just are better than passwords. For passwords to work, you can be breached on the site where you have them.
ROSIE: Are there any limitations or disadvantages to using passkeys?
MAX: So, right now the biggest limitation about passkeys is that not all sites support it, and it’s a little bit frustrating because it is better for users, it’s easier, it’s more secure. In many ways it’s better for companies because there’s going to be hopefully fewer data breaches, and people not being able to log in. It should iron out a lot of those problems. But it’s still just not everywhere yet. Right now, I would describe it as when I can use a passkey, it’s like a pleasant surprise, but it’s not everywhere. So, you have to keep an eye out, you have to go looking for it.
ROSIE: Should we expect that it will continue to grow and become ubiquitous?
MAX: So, the people behind it certainly think so. You can just look at Apple, Google, and Microsoft putting their support behind this, into all of their platforms, they certainly think so. The advantages are there. Another limitation of passkeys though is that pretty much every site is still going to require that you create a password when you make an account there. Now, an idealized passkey utopia, you don’t even do that. You never touch a password anymore. But we’re not there yet, this technology is still rolling out. So, you’re still going to be using your password manager, you’re still going to be using 2FA on these accounts because you have to do that as part of the creation process.
ROSIE: So, ultimately it sounds to me like the advice is password manager, yes.
MAX: Yes.
ROSIE: Get it ASAP, use it, use two-factor authentication, 2FA, when you can, as often as you can.
MAX: Oh yeah.
ROSIE: And then if you encounter a passkey, try it out.
MAX: Yeah. The more you learn about using passkeys right now, the easier that transition will be. There’s a list on the FIDO Alliance site of sites that do support passkeys right now, if you want to go be proactive about it, look at that. Go look at the account settings for the sites that are most important to you. And the next time you see a little nag pop up on your phone that says, “Hey, do you want to create a passkey for it? ” Go for it, do it.
ROSIE: Max, thank you for the insight, always appreciated.
MAX: Thank you so much.
ROSIE: If you want to learn more about Max’s reporting on data, privacy, security, you can check out Wirecutter’s website. We will link his articles about passkeys and about password managers in our show notes. As ever, we so appreciate you listening and talk soon.
The Wirecutter Show is executive produced by me, Rosie Guerin, and produced by Abigail Keel. Engineering support from Maddy Masiello and Nick Pitman. Today’s episode was mixed by Catherine Anderson. Original music by Dan Powell, Marion Lozano, Elisheba Ittoop, Rowan Niemisto, Catherine Anderson, and Diane Hong. Cliff Levy is Wirecutter’s deputy publisher and general manager. Ben Frumin is Wirecutter’s editor in chief. And I’m Rosie Guerin, thank you for listening.
ROSIE: The most obvious question, the reason we created the show-
MAX: What’s my password?
ROSIE: Yeah, what is your password? What is your master password? No.
MAX: Coolguy59.
ROSIE: Yeah.

