About this session
Cybersecurity researchers Andréanne Bergeron and Olivier Bilodeau, colleagues at GoSecure, stage a structured debate on whether standalone password managers actually help non-expert users, sparked by disagreement while co-writing a blog post on passwords. Bergeron argues adoption remains low, seventy to eighty percent of people don't use one, because of poor awareness, bad press around breaches like LastPass, extra effort layered on top of MFA, and the risk of a single point of failure if the vault, a device, or a master password is lost or stolen. Bilodeau counters with live demos showing password rotation, autofill and TOTP storage take seconds, argues security expertise should be centralized in dedicated tools the way legal expertise sits with law firms, and reframes the debate through threat modeling: most attackers are remote, opportunistic and after money, not physically targeting any one person. They agree standalone managers are imperfect but necessary, browser-based managers are a reasonable low-friction entry point despite XSS-based credential theft risk, and recommend a layered approach with separate low- and high-security vaults while waiting for passkey-based FIDO Alliance authentication to mature.
Key takeaways
- Segment your password strategy by threat model: low-friction browser-based managers for most personal accounts, a dedicated high-security vault for sensitive ones, since most attackers are remote and opportunistic, not physically targeting you.
- Print your master password, seal it in a tamper-evident envelope, and store it (or a way to find it) somewhere a trusted family member can access if you die or are incapacitated.
- Use TOTP-based MFA rather than SMS, and consider storing TOTP tokens in the same password manager to lower the adoption barrier, even though this creates a partial single point of failure.
- Enable full-disk encryption on laptops and phones so a physical theft does not automatically expose the password vault stored on the device.
- Do not rely on scheduled password rotation; generate strong unique passwords once and only rotate a credential when it is known to be part of a breach.
Speakers

Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an… Read moreRead less
Andréanne Bergeron, Ph.D., is the director of research at GoSecure, specializing in online attackers' behaviors. Her expertise delves into the intersection of criminology and cybersecurity. In addition, Andréanne holds an esteemed position as an affiliated professor in the Department of Criminology of Montreal University, bridging academia and industry. Involved in the cybersecurity community, she is a board member of the Canadian Cybersecurity Network and the co-VP of engagement and outreach for Northsec.

Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur… Read moreRead less
Olivier Bilodeau, chercheur principal chez Flare, possède plus de 12 ans d’expertise de pointe en cybersécurité, notamment dans les opérations de honeypots, la rétroingénierie de logiciels malveillants et l’interception de RDP. Communicateur passionné, Olivier a présenté lors de conférences telles que AtlSecCon, BlackHat, DEFCON, SecTor, Derbycon, et bien d’autres. Très impliqué dans sa communauté, il coorganise MontréHack, est président de NorthSec, et anime son Hacker Jeopardy.

