I use last pass with auto-log out, 2 step auth, and also require that the IP to login is my ip, i use a vpn that I am hosting myself so the ip remain same whereever i am/with what ever device i use.
I would never trust a text file on a computer, way too many virus are around that can steal all your document in 1 second.
I would never trust a encrypted file container, imagine, there is a virus that lock your computer you would lose the password.
I would never trust dropbox for anything other then file sharing.
I would never put password on my anti-virus as when there is exploit around and you get infected it is the first thing that get disabled.
I won't say i'm 100% safe with lastpass, but I am much more comfortable using lastpass then any alternative. I love to only have to remember one single password.
I also have paper copy of my last pass vault just in case as we never know..
As for BitDefender, when checking malware hunter website that post detected virus on virustotal, most of the time, ill actually say all the time, it is never bitdefender detecting a virus first. They are always very late on virus detection. Take care with it thinking your invinsible.
I though about only paper / postit.. but my last pass has over 200 accounts saved in(I use it since many years!!!)... am i gonna carry my paper/postit all the time with me when i am on the road/traveling??? I like that my pass are saved into my android, windows pc, tablet..
|