The problems with password hygiene are well understood to move beyond passwords, but recent recommendations to improve passwords may cause even more problems.

First, new research suggests that popular password managers, like LastPass, have major flaws that can allow attackers to attackers to remotely siphon plaintext passwords without notice. On the other hand, two Microsoft security researchers say it should be just fine to reuse simple passwords for sites with non-sensitive data.

What do security experts recommend for users that are concerned about password security?

