<https://www.reddit.com/r/datacurator/comments/i0mlsa/keepass_structuring/fzwkygi/>

> I'm not sure what you're suggesting here.

I wasn't "suggesting" anything, I was directly responding to your comment that using poor security is often a good idea.  It is not.  So, yes, to the extent that a password manager might enforce the use of stronger passwords or reduce the reuse of passwords, they are a welcome tool.  But to the extent they lock you into the app or push *all* your passwords to be shared for the convenience of everywhere access, they should not be welcome.

> Most adults have enough highly sensitive and frequently accessed credentials (think email accounts and financial institutions) that memorization is difficult and a safe frequently inconvenient.

That has essentially nothing to do with password managers.  Email clients store your credentials themselves.  As do most apps or web browsers that you would use to access your bank.  Often times the remote servers impose rules that undermine whatever security gains could be had by using a password manager, too.

> What that means in my experience, is that people fall back on poor security practices: post-it notes on their desk, keeping credentials unencrypted as a note on their phone or on their desktop, or using easy passwords with lots of variations on a common theme.

Given the proper context, none of those are inherently insecure.  Just as with a safe, if the physical security of your office/desk is strong, simply leaving passwords in the clear may not be your greatest vulnerability.  Likewise, variation on a theme is not really a problem if you haven't been compromised enough for an attacker to make use of that info.

> I could say the same thing about your preferences: "What? You stored your passwords in a home safe? Didn't you know that there are 2.5 million burglaries per year in the US? What did you expect? You should have kept them in a safe deposit box in a bank. How could you be surprised? Did you think houses don't get broken into?!"

And you'd be right, *only* if you could show that home burglaries are a significant source of online attacks.  This leads to other thinking about the curation of credentials, like realizing that a password is really just part of a *key* that needs to be paired with an account name.  A couple years ago I semi-jokingly posted to my blog about how to [carry all your passwords in your wallet](https://impossiblystupid.com/node/1011/?content=here-are-all-my-passwords).  To the extent that password managers put all of your access info in one place, they fail to encourage best practices.

> Treating them with derision seems counterproductive to me.

It's not derision to be honest about their limitations and the potentially dangerous habits they encourage.  That's really what the topic of discussion is: how to structure your sensitive data in a secure and useful manner.  Simply using a password manager doesn't mean you get to turn off your brain when it comes to security.  The OP is wondering about what things should go into Keepass and get all grouped together.  My point is that once you start thinking deeply about it, you might come to the rational conclusion that a monoculture, however well engineered, is not ideal.

<https://www.reddit.com/r/datacurator/comments/i0mlsa/keepass_structuring/fzzxxv4/>
fa5aa4e47bf969d7e028ba1271fceaeb4333398fc2e58c6faa083a1c0dd21468
