Recently, there was a discussion thread on LinkedIn suggesting you can't use a password manager for internet banking. Why exactly wasn't quite clear, but it seemed to be an interpretation of "memorising" the passphrase versus writing it down.
This seemed odd, as password managers are everywhere, from web browsers to standalone apps, and built into operating systems. Security researchers recommend using password managers, and to be honest, with the ever-growing number of logins for services and apps, how could anyone survive without one?
Furthermore, how would a bank know that you're using a password manager?
It is an important point to clarify though, so I asked ASB. A spokesperson for the bank sent this response:
Under ASB’s Terms and Conditions, our customers must take responsibility for and protect their personal information and Security Credentials, such as PINs, log-in and password details.
Security Credentials should remain confidential to each customer and should be memorised, must not be written down or disclosed to anyone else. If a customer suspects their Security Credentials have been disclosed to another person, this must be reported as soon as the customer is aware or suspects the information has been compromised.
CERT NZ recommends using a password manager to keep data safe and protect passwords. We are supportive of using reputable password managers that encrypt data, alongside the other safety measures outlined by CERT NZ.
That's commonsense from both ASB and the government Computer Emergency Response Team (CERT).
If your bank grinds its gears over password manager use, it's a sign they haven't kept up with the times and should rethink their opposition to a tool that can enhance customer security.
How do password managers enhance security then? Any sensible service provider will set a password policy for access that requires a reasonably complex "Open Sesame" phrase that's difficult to guess, or crack as information security pros call it. If they don't, go somewhere else.
Now, if you want to make it harder for miscreants to guess your password, take a look at the below table:

As a related aside, a properly configured access system will slam the brakes on repeated passphrase guesses and when too many have been entered, lock the login and force an account reset.
Back to longer and complex passwords: they are not only difficult to guess, but hard for users to remember as well. The temptation here is to use a simple one (if the site in question allows it) or to reuse a password that you can remember. Both are really bad ideas, for obvious reasons, but there's a persistent, false assumption that "it won't happen to me".
On Apple's macOS, the built-in password manager offers a range of features that makes life easier and more secure. The tool creates complex, hard-to-guess passwords (natch) that are unique to each site, to avoid re-use of credentials. By tapping the Touch ID biometric fingerprint sensor on my MacBook, logins are painless and quick with the credentials being filled in for you.
Better yet, the macOS password manager audits existing passwords, and warns if they've been reused or found in data breaches.
You'll find similar features in other password managers but absolutely follow CERT NZ and ASB's recommendation to use a reputable one that encrypts stored credentials. As you can imagine, password managers are attacker targets and if they are breached, things can get scary.
It follows from there that having multiple safeguards to protect our digital lives should things go wrong is not a bad idea at all. Think of it like washing skyscraper windows, and being secured with more than one rope for when that inevitable miss-step happens.
Have a read of our piece on multi-factor authentication (MFA) with some thoughts on how to up your security game.
We welcome your comments below. If you are not already registered, please register to comment
Remember we welcome robust, respectful and insightful debate. We don't welcome abusive or defamatory comments and will de-register those repeatedly making such comments. Our current comment policy is here.