MFA Now Required for VPN

Please be advised that multi-factor authentication (MFA) is now required to connect to myVPN - Learn More

Setting Up a Password Manager

Staff member contemplating strength of password

For those who have never used a password manager, setting one up may seem daunting and complicated. It’s not – you can do this.

While it will take time to set up, populate and organize your new password vault, and learn how to quickly access your passwords, it will become second nature over time. The key is to just get started.

Action Plan

 

Step 1: Choose a password manager

Review features and pricing and choose an option that works for you. Using your desktop or laptop computer, download software (if available) and set up an account.

Refer to the Password Manager Options comparison grid below of some of the leading products. Which one you choose is less important than simply choosing one and using it.

Step 2: Create a master password

Your master password is a single, strong password that gives you access to your password vault. Make it long, strong and memorable.

  1. Use a passphrase - a sequence of random words and characters strung together to create a password (20-30 characters)
  2. Make sure the password is unique, and that you don’t use it for anything else
  3. If you change your master password, change it completely
  4. Test the strength of your master password – use an online tool such as bitwarden.com/password-strength
Step 3: Add browser extension

The browser extension will allow you to save all your favourite sites to your vault automatically, generate new passwords, and easily fill your login credentials.

Turn off the password manager built into your browser. They lack security and flexibility.
Step 4: Populate your password vault

Start gradually – there is no need to add everything all at once. Many password managers allow you to import passwords from your browser, a CSV file and other password managers. To more easily manage your passwords as the number of stored accounts grows, group or categorize your sites.

By simply logging into sites as you are browsing on your own, the browser extension will save them to your vault automatically - no need to add them manually.
Step 5: Download the mobile app

The mobile app will allow you to access your password vault from your mobile device.

Turn off the built-in password manager on your mobile. This way, you can be sure you’re only storing passwords in a single location.
Step 6: Perform a health check

Check for duplicate, weak, default and stolen credentials, and use the password generator to reset the passwords for those accounts.

You don’t need to change all your passwords immediately - start with sites that store high-risk information such as your email and banking, and ones that have been compromised.
Step 7: Plan for the futureInclude your master password and instructions on how to access your vault with your estate documents and other important papers.
Step 8: Go further
  1. Store other information you’d like to protect, such as credit card details, passport information, and notes/documents you don’t want anyone to see.
  2. Explore additional features like secure sharing of passwords and/or folders. Many password managers also allow you to save time online through automatic form filling.
  3. Review and update your security settings.
  4. Don’t forget other security measures to stay safe online, such as using multi-factor authentication (MFA) wherever available, and keeping your computer and mobile devices up to date.

 

Campus snow removal

Password Manager Options Password Manager Options

There are various factors to consider when choosing a password manager, including cost, desired features, number of users (e.g. personal vs. family plan) and just general aesthetics/usability. The grid below compares some of the industry-leading/popular options.

For departmental/faculty use of a password manager, a Privacy Impact Assessment (PIA) must be completed prior to use. A PIA is not required for personal use.

IT Service Owners or IT Administrators at UBC: Learn more about Privileged Access Management through UBC’s Enhanced System Access Management (eSAM) tool.
 
Features1PasswordBitwardenDashlaneKeePassRoboForm
PlansIndividual / FamilySingle / FamilyPersonal Free / Personal Premium / Friends & FamilyIndividualPersonal Free / Personal Everywhere / Family
Approx. price / per year (CAD)$45 / $72Free / $55Free / $55 / $83FreeFree / $25 / $50
Number of devicesUnlimitedUnlimitedFree – Limited to 1 / UnlimitedUnlimitedFree – Limited to 1 / Unlimited
Cloud-based storageYesYesYesNoFree / No / Yes
End-to-end encryptionYesYesYesYesYes
MFAYesYesYesYesFree / No / Yes
Biometric loginYesYesYesNoYes
Password sharingYesYesYesNoYes
Password generatorsYesYesYesYesYes
Password importYesYesYesYesYes
Security breach monitoring/alertsYesYesYesNo?
Encrypted file storageYesYesYesNo?
Autofill PasswordsYesYesYesYesYes
Website1password.combitwarden.comdashlane.comkeepass.inforoboform.com

Go Further...


UBC Crest The official logo of the University of British Columbia. Urgent Message An exclamation mark in a speech bubble. Caret An arrowhead indicating direction. Arrow An arrow indicating direction. Arrow in Circle An arrow indicating direction. Arrow in Circle An arrow indicating direction. Chats Two speech clouds. Facebook The logo for the Facebook social media service. Information The letter 'i' in a circle. Instagram The logo for the Instagram social media service. Linkedin The logo for the LinkedIn social media service. Location Pin A map location pin. Mail An envelope. Menu Three horizontal lines indicating a menu. Minus A minus sign. Telephone An antique telephone. Plus A plus symbol indicating more or the ability to add. Search A magnifying glass. Twitter The logo for the Twitter social media service. Youtube The logo for the YouTube video sharing service. Bell Warning