The contrarian take: Your password manager is a single point of failure
I love password managers. I really do. They're the first line of defense against the scourge of password reuse, and the fact that they can generate and store unique, random passwords for every account is a godsend (CISA, Secure Our World). But here's the thing: a password manager is still just a vault of passwords. If an attacker phishes you, they can get the password to your vault, and then they have the keys to the kingdom. That's why I'm here to argue that the single best privacy tool you can adopt is not a password manager—it's a hardware security key, a FIDO2 device that provides phishing-resistant MFA.
Now, before you close this tab, hear me out. I'm not saying password managers are useless. They're absolutely essential for password hygiene. But they don't solve the biggest threat: phishing. In 2024, the FBI's IC3 received 193,407 phishing complaints—that's the most-reported crime category (FBI IC3). Phishing is how attackers get your password, your MFA code, or your vault's master password. And once they have that, your password manager is just a convenient list of all your accounts.
So, in this head-to-head, I'm pitting the classic password manager against the modern hardware key. I'm going to compare them on three concrete criteria: resistance to phishing, ease of use, and cost. And I'm going to argue that while the password manager wins on ease and cost, the hardware key wins on security—and that's the criterion that matters most.
Criteria 1: Phishing resistance—the hardware key wins, no contest
Let's start with the most important criterion: how well does each tool protect you from phishing? Phishing is the #1 threat, so this is where the battle is decided.
A password manager, no matter how good, is still vulnerable to phishing. If you type your master password into a fake login page, the attacker gets it. Even if you use two-factor authentication (2FA) with an authenticator app, phishing can still trick you into entering that one-time code. CISA documents four ways traditional MFA is bypassed: phishing, push bombing (push fatigue), SS7 protocol vulnerabilities, and SIM swapping (CISA, Implementing Phishing-Resistant MFA). That last one is nasty: attackers can convince your cellular carrier to transfer your phone number to a SIM they control—that's SIM swapping, and it's a form of social engineering (CISA). With SMS-based 2FA, you're vulnerable to that.
Hardware keys, on the other hand, are designed to be phishing-resistant. FIDO2 keys use public-key cryptography that ties the authentication to the specific site. When you log in, the key verifies the site's identity, so it won't respond to a phishing site. CISA ranks phishing-resistant MFA (FIDO/WebAuthn and PKI-based) as the gold standard, resistant to phishing, push bombing, SS7, and SIM swap attacks (CISA). That's a huge win.
Microsoft says enabling MFA can block over 99.9% of account compromise attacks (Microsoft). But not all MFA is equal. If you're using SMS, you're not getting that protection. If you're using a hardware key, you're getting the best protection available.
Criteria 2: Ease of use—password manager wins, but hardware keys are catching up
Now, let's talk about the practical side. A password manager is a piece of software you install on your phone and computer. You unlock it with a master password, and it autofills your credentials. It's simple, and it works across all your devices. Hardware keys, on the other hand, are physical devices you have to carry and plug in or tap. That's a friction point.
But the friction is less than you think. Modern hardware keys support NFC, so you can tap them on your phone, and they work with USB-C or Lightning connectors on laptops. The setup is a bit more involved—you have to register the key with each account—but once it's done, it's a single tap to log in.
Also, you should have a backup key. If you lose your primary key, you're locked out. That means buying two keys. That adds cost, but it's a one-time expense. And if you're worried about the learning curve, consider this: the NCSC says writing a password down is acceptable if kept somewhere safe, and they recommend password managers (NCSC). But they also support passphrases—three random words like 'applenemobiro'—which is a great fallback if you're not ready for a hardware key.
Criteria 3: Cost—password manager is cheaper, but hardware keys are a one-time deal
Let's talk money. A good password manager subscription costs anywhere from $2 to $5 per month, depending on the plan. That's $24 to $60 per year. Over five years, that's $120 to $300. A hardware key, like a YubiKey, costs around $50 each. If you buy two (one as a backup), that's $100. So over the long run, the hardware key is actually cheaper.
But there are free password managers, so the upfront cost of a password manager can be zero. However, you get what you pay for. Free tiers often lack advanced features like encrypted file storage or family sharing. And the real cost of a password manager isn't the subscription—it's the risk. If your master password is phished, the cost is your entire digital identity.
Let me put this in perspective. The average loss per IC3 complaint in 2024 was $19,372 (FBI IC3). That's the average reported loss. So a $100 hardware key is a bargain compared to a potential $19,000 loss.
So who should use what?—My recommendation
Here's my take: if you're a casual internet user who wants to protect your personal email and social media, a password manager is a solid start. But if you're serious about privacy—if you're a journalist, an activist, a business professional, or anyone who handles sensitive data—you need a hardware key. That's the gold standard.
But I'm not saying throw away your password manager. Use both. Use a password manager to generate and store your passwords, and use a hardware key as your second factor. That's the best of both worlds. And if you can't afford a hardware key right now, at least use an authenticator app or mobile push with number matching, not SMS. CISA recommends app-based one-time passwords or mobile push with number matching when phishing-resistant MFA isn't available, and says SMS or voice codes should only be a last resort (CISA).
Here's a quick comparison table to summarize:
| Criterion | Password Manager | Hardware Key |
|---|---|---|
| Phishing resistance | Low—vulnerable to phishing of master password and MFA codes | High—FIDO2 resists phishing, push bombing, SS7, and SIM swap |
| Ease of use | High—autofill, works across devices | Medium—requires carrying device, setup, backup key |
| Cost | $0–$60/year subscription | $50–$100 one-time for two keys |
| Best for | Everyone as a baseline | High-value accounts, sensitive data |
And here's my shortlist of when to use a hardware key:
- Email accounts (your email is the key to everything)
- Cloud storage (think Google Drive, Dropbox)
- Financial accounts (banking, PayPal, crypto)
- Social media (if you have a large following or handle sensitive info)
Bottom line
Your password manager is not enough. The single best move you can make for your privacy is to buy a hardware security key and enable it on your most critical accounts. It's a small investment that protects you from the most common attacks—phishing, SIM swapping, and account takeover. Do it today.
Sources
- CISA (Secure Our World) - https://www.cisa.gov/secure-our-world
- CISA (Implementing Phishing-Resistant MFA) - https://www.cisa.gov/sites/default/files/2023-01/fact-sheet-implementing-phishing-resistant-mfa-508c.pdf
- FBI IC3 (2024 Internet Crime Report) - https://www.ic3.gov/Media/PDF/AnnualReport/2024_IC3Report.pdf
- Microsoft Security Blog (MFA) - https://www.microsoft.com/en-us/security/blog/2019/08/20/one-simple-action-you-can-take-to-prevent-99-9-percent-of-account-attacks/
Comments (0)
Please sign in to post a comment.
Don't have an account? Create one
No comments yet. Be the first to comment!