Weak passwords are effortless and quick to crack for malicious hackers. One solution to avoid them is to use randomly generated strong passwords but those are hard to remember. Plus, malicious actors will use the passwords revealed in data breaches to try to access other accounts. This is why having different passwords for each account is important. Combine the fact that people have on average 100 accounts protected by passwords and that it is impossible to remember strong passwords for each of them. For some, the solution is simple: use a password manager! However, previous studies have shown password managers (particularly stand-alone applications) suffer from low adoption rates, and especially among non-experts.This presentation is a hot debate between two seasoned researchers: one pro password managers and one against. Great arguments on both sides will be made but what's more important is the process of thinking about managing secrets. Does your organization have a clear policy on password managers? Should it have one?