I just installed Roboform Everywhere and have a concern. If someone gets access to my computer, they can just log into all the sites for which I have saved a password! That seems awfully insecure. I take pretty good care of my laptop, but it might get stolen. Then I would have a real problem. I am considering uninstalling Roboform. Please tell me your opinion about this concern.
![]() |
Patch reliability is unclear. Unless you have an immediate, pressing need to install a specific patch, don't do it. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |
-
Concern about password manager
Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » Concern about password manager
- This topic has 27 replies, 15 voices, and was last updated 10 years, 5 months ago.
Viewing 15 reply threadsAuthorReplies-
Berton
AskWoody_MVP -
RetiredGeek
AskWoody_MVPOctober 12, 2014 at 4:55 pm #1470743Bill,
I don’t have RF Everywhere but I do use RF Desktop and it requires a master password I’d assume that RFE does also?
If so loosing your laptop should require the finder to know 2 passwords! Your Laptop’s logon password and your RFE master password. These should both be of sufficient length and complexity to make this almost impossible. If you have bitlocker available you can add another level of complexity as clearing the logon password isn’t all that hard for the knowledgeable PC user. HTH :cheers:
-
WSjwitalka
AskWoody LoungerOctober 13, 2014 at 10:49 am #1470862Bill,
I don’t have RF Everywhere but I do use RF Desktop and it requires a master password I’d assume that RFE does also?
If so loosing your laptop should require the finder to know 2 passwords! Your Laptop’s logon password and your RFE master password. These should both be of sufficient length and complexity to make this almost impossible. If you have bitlocker available you can add another level of complexity as clearing the logon password isn’t all that hard for the knowledgeable PC user. HTH :cheers:
The laptop’s Windows logon password is easily bypassed by any moderately knowledgeable thief.
Jerry
-
joep517
AskWoody MVPPaul T
AskWoody MVPOctober 13, 2014 at 12:13 pm #1470868RetiredGeek
AskWoody_MVPOctober 13, 2014 at 1:38 pm #1470872Jerry,
Didn’t I say that? :confused: :cheers:
WSyuehan123
AskWoody LoungerOctober 16, 2014 at 12:33 pm #1471347I imagined that what you are talking about is sitting down at your device, logging in and then- whatever- use your imagination.
the steps you might take are:
1. right click on the roboform symbol, at the top of the menu box select ‘logoff’ a symbol of a key.
2. ditto step one, part one, then select options, then select security, finally set up your “auto” log off. However you want it to be.The whole idea of a master password manager is convenience. If you sign in to RF and then get up and walk away, then beware.
WSkensmiles
AskWoody Plusbmeacham
AskWoody PlusWSrodsmine
AskWoody Lounger-
RetiredGeek
AskWoody_MVPOctober 17, 2014 at 10:38 am #1471467Actually, RG, RoboForm Desktop does not _require_ a master password. When it asks you for one when you install or update, clicking cancel at that window installs it without a master password.
Rodsmine,
Yeah but who would do that? 37551-headbang Oh yeah, all those people getting millions from Nigerian diplomats! 35623-ROTFLOL
-
Coochin
AskWoody_MVPOctober 20, 2014 at 8:05 am #1471844…Yeah but who would do that?…
Actually I regularly have to help customers who have forgotten passwords.
There are ways of discovering passwords previously used on a PC.
Am not going into detail (don’t want to make it any easier for the baddies) but it is not terribly hard to recover any passwords you have used on your computer – it only requires certain knowledge about how Windows stores passwords and how to access those stored passwords.
Advise against using “RoboForm” or any other “login manager” – they are too easy to “crack”.
Rather, keep a notebook for your computer in which you write down details of each login, but keep the notebook separate from your computer (especially if it is a laptop or other mobile device).
Since you must use a “password manager” such as RoboForm, etc., at least if you have maintained a separate notebook you can go in and change passwords in the sad event that your laptop (or other device) is stolen.
-
WSruirib
AskWoody LoungerOctober 20, 2014 at 9:50 am #1471856Advise against using “RoboForm” or any other “login manager” – they are too easy to “crack”.
Seriously? So you have software to easily crack AES 256 bit encryption coupled with a few thousand PBKDF2 iterations? You should post a technical article about that, I am sure it would have a huge impact in the field of cryptography.
-
Coochin
AskWoody_MVPOctober 20, 2014 at 9:37 pm #1471926Seriously? So you have software to easily crack AES 256 bit encryption coupled with a few thousand PBKDF2 iterations? You should post a technical article about that, I am sure it would have a huge impact in the field of cryptography.
Sorry, I didn’t explain properly.
What I meant was that it is not terribly hard to discover passwords stored on a Windows computer. Once the “master password” is discovered by an intruder, then the intruder can access any other login details (usernames & passwords) stored in programs like “RoboForm”, “Dashlane”, etc. By “intruder” I mean someone who has gained physical access to the computer, whether a thief, prankster, or other baddie.
When I am asked to help with lost or forgotten passwords, it most often involves email accounts, but sometimes Windows user account passwords.
-
-
-
WSDick-Y
AskWoody LoungerOctober 20, 2014 at 10:37 am #1471861I hope this is not off-topic, but I thought I’d post what I, a retired non-techie, do vis a vis a password manager etc.
I happen to use LastPass, but the principles are the same I believe:
I have a master password for LastPass.
All my sites that use a password are encrypted in Steganos Locknote.
I use LastPass to “remember” the sites I want to log-on to automatically.
For the other, I look them up in Locknote and copy the unencrypted password as neccessary.I keep a copy of everything that is in Locknote (copied to a Word document, in the clear) that I keep in my bank safe deposit box.
That way, if I pass, my wife and/or 2 kids (none of whom is very technical) can “take care of business.”
Still here, and gaining much useful information here at WindowsSecrets.
Best,
DickPS,
Periodically I run the “security check” that LastPass offers; and I make sure that I have no duplicate passwords, and they are all “strong.”Paul T
AskWoody MVPWSruirib
AskWoody LoungerOctober 20, 2014 at 9:51 pm #1471929Thanks for clearing that up.
Indeed the weak point of the password managers is the single password, even if it is one of its most valuable features – that is, the fact that such password is the only one a user needs to remember.
Some password managers allow you to configure the use of two step authentication, based on a mobile phone, to allow access to their stored passwords (and other data). That is a mechanism to add a bit more security and makes a password manager’s weakest link a bit stronger.
So, for normal use, I think password managers who have these features can be used with some advantage over alternative methods. I do use one and I couldn’t go back to the time where I didn’t use it. Plus the smartphone scenario adds a bit more complexity to the situation, unless the password manager is supported, which is very useful when it happens.
-
Trev
AskWoody Lounger -
Coochin
AskWoody_MVPOctober 21, 2014 at 5:00 am #1471955The essence of a Password Manager is the Master password, so if it is “not terribly hard to discover”, what is the point?
Maybe instead of just “not terribly hard to discover” I should have stated “not terribly hard to discover for a competent computer programmer/technician/hacker/other who has advanced skills and knowledge about how these things work”.
While I generally advise against using “password manager” programs I recognise that most ordinary users find advantages in using these programs, mostly simple convenience.
However, in certain situations failure to keep records of username/password details separate from the computer (e.g.: as I have previously stated, by writing them into a notebook kept separate from the computer) can easily result in serious inconveniencies.
Hypothetical scenario: you are using “RoboForm” (or some other password manager) on your laptop; you go on a trip somewhere, during which your laptop is stolen; if you don’t have a separate record of all those login details (usernames/passwords) do you really think it is going to be easy to recover? And in the meantime(while you are recovering) there is a strong likelihood the thief can access all those stored logins if the thief is savvy enough to discover your “master password”.
Is it really worth risking not keeping a separate record?
-
WSruirib
AskWoody LoungerOctober 21, 2014 at 5:26 am #1471957Is it really worth risking not keeping a separate record?
Again, some of the password managers allow access to your data from anywhere you can use an internet browser or even from your phone. In that case, the need for a separate record diminishes. There is also the possibility of exporting the data to a file, which you can maintain encrypted, using something as simple as WinZip (again using encryption like AES 256 bit) and store somewhere you know you can access even if a computer is stolen. I would favor this option over a physical notebook.
-
Coochin
AskWoody_MVPOctober 21, 2014 at 6:49 am #1471961Again, some of the password managers allow access to your data from anywhere you can use an internet browser or even from your phone. In that case, the need for a separate record diminishes. There is also the possibility of exporting the data to a file, which you can maintain encrypted, using something as simple as WinZip (again using encryption like AES 256 bit) and store somewhere you know you can access even if a computer is stolen. I would favor this option over a physical notebook.
Obviously for your purposes keeping a separate notebook would be somewhat superfluous. But most of my customers lack the degree of comfort with these newer technologies you obviously possess.
Typically, my customers have one computer (and maybe a touchpad), which is/are shared by husband & wife; usually either husband or wife takes overall control and the other partner is subservient.
All is fine until something goes badly wrong (HHD failure, “grandkids stayed the weekend”, virus infection, etc.)
Suddenly they can’t access their email, online banking, or some other functionality, because there is a problem of some kind with their login (usually password). This is why I say it is a very good idea to record such login details manually in a separate notebook kept somewhere conveniently accessible but not nearby the computer.
-
WSruirib
AskWoody LoungerOctober 21, 2014 at 7:01 am #1471965Obviously for your purposes keeping a separate notebook would be somewhat superfluous. But most of my customers lack the degree of comfort with these newer technologies you obviously possess.
Typically, my customers have one computer (and maybe a touchpad), which is/are shared by husband & wife; usually either husband or wife takes overall control and the other partner is subservient.
All is fine until something goes badly wrong (HHD failure, “grandkids stayed the weekend”, virus infection, etc.)
Suddenly they can’t access their email, online banking, or some other functionality, because there is a problem of some kind with their login (usually password). This is why I say it is a very good idea to record such login details manually in a separate notebook kept somewhere conveniently accessible but not nearby the computer.
Yes, I understand your point of view. I suppose we all need to adapt to the specific circumstances we need to deal with :).
-
-
-
wavy
AskWoody PlusOctober 21, 2014 at 5:07 pm #1472030Dick-Y
If you are cut&pasting out of your Steganos Locknote program may I ask you if you have encountered the situation where (presumably for security reasons :confused:) pasting does not work and if so if you have found a workaround?🍻
Just because you don't know where you are going doesn't mean any road will get you there.WSglendad
AskWoody Lounger-
WSruirib
AskWoody LoungerNovember 7, 2014 at 6:28 am #1474266I am so tired of writing down all the passwords I made up, then have problems finding them in the book I use.
Do I need to be a techie to use these programs?
thanks again for your input.
Glenda
You don’t need to be a techie. The one I use, LastPass, fills the information for you automatically, in most cases. It asks if you want to save any login details, when they change or the site is new and is not saved. It’s rather easy to use. I am a complete convert, now (I started using it around 2 years ago).
RetiredGeek
AskWoody_MVPNovember 7, 2014 at 6:23 am #1474265Glenda,
No you do not need to be a techie. However, you will have some learning curve as with any new program. Read the documentation be it printed or online and you’ll at least have the basics. Then of course you can always ask questions on the finer points here as well as the manufacture’s web site. FWIW my favorite is RoboForm, Desktop version as I personally don’t like the idea of storing my passwords on the cloud no matter how many assurances are given. 😆
HTH :cheers:
Paul T
AskWoody MVPViewing 15 reply threads -

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Global data centers (AI) are driving a big increase in electricity demand
by
Kathy Stevens
6 hours, 2 minutes ago -
Office apps read-only for family members
by
b
8 hours, 38 minutes ago -
Defunct domain for Microsoft account
by
CWBillow
5 hours, 30 minutes ago -
24H2??
by
CWBillow
39 minutes ago -
W11 23H2 April Updates threw ‘class not registered’
by
WindowsPersister
17 hours, 23 minutes ago -
Master patch listing for April 8th, 2025
by
Susan Bradley
10 hours, 37 minutes ago -
TotalAV safety warning popup
by
Theodore Nicholson
5 hours, 26 minutes ago -
two pages side by side land scape
by
marc
2 days, 6 hours ago -
Deleting obsolete OneNote notebooks
by
afillat
2 days, 8 hours ago -
Word/Outlook 2024 vs Dragon Professional 16
by
Kathy Stevens
1 day, 11 hours ago -
Security Essentials or Defender?
by
MalcolmP
1 day, 14 hours ago -
April 2025 updates out
by
Susan Bradley
9 hours, 8 minutes ago -
Framework to stop selling some PCs in the US due to new tariffs
by
Alex5723
1 day, 7 hours ago -
WARNING about Nvidia driver version 572.83 and 4000/5000 series cards
by
Bob99
21 hours, 36 minutes ago -
Creating an Index in Word 365
by
CWBillow
2 days ago -
Coming at Word 365 and Table of Contents
by
CWBillow
12 hours, 10 minutes ago -
Windows 11 Insider Preview Build 22635.5170 (23H2) released to BETA
by
joep517
3 days, 3 hours ago -
Has the Microsoft Account Sharing Problem Been Fixed?
by
jknauth
3 days, 6 hours ago -
W11 24H2 – Susan Bradley
by
G Pickerell
3 days, 8 hours ago -
7 tips to get the most out of Windows 11
by
Alex5723
3 days, 6 hours ago -
Using Office apps with non-Microsoft cloud services
by
Peter Deegan
3 days ago -
I installed Windows 11 24H2
by
Will Fastie
1 day, 6 hours ago -
NotifyIcons — Put that System tray to work!
by
Deanna McElveen
3 days, 12 hours ago -
Decisions to be made before moving to Windows 11
by
Susan Bradley
5 hours, 35 minutes ago -
Port of Seattle says ransomware breach impacts 90,000 people
by
Nibbled To Death By Ducks
3 days, 20 hours ago -
Looking for personal finance software with budgeting capabilities
by
cellsee6
3 days, 4 hours ago -
ATT/Yahoo Secure Mail Key
by
Lil88reb
3 days, 4 hours ago -
Devices with apps using sprotect.sys driver might stop responding
by
Alex5723
4 days, 13 hours ago -
Neowin – 20 times computers embarrassed themselves with public BSODs and goofups
by
EP
4 days, 22 hours ago -
Slow Down in Windows 10 performance after March 2025 updates ??
by
arbrich
21 hours, 35 minutes ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.