4 ms·
Looks awesome! I've been using 1password, are there any big advantages that KeePass has over it?
by magicmu 11y ago
Looks awesome! I've been using 1password, are there any big advantages that KeePass has over it?
- xbryanx 11y agoIt's free
- JupiterMoon 11y agoIt's not just free it is FLOSS.
- geostyx 11y agoI forgot to floss this morning :(
- jug5 11y agoOpen source
- cmrx64 11y agoI'm not sure about "big", it all depends on how much you trust 1password and what your threat model is. For me, the advantage of keepass is that I don't need to upload my credentials anywhere, or trust some closed source blob running in the browser, etc. It has a XML format that enables things like this client to be created. 1password has the advantage of excellent platform integration on iOS, and various browser extensions with auto-fill.
- oneeyedpigeon 11y ago> the advantage of keepass is that I don't need to upload my credentials anywhere But if you want to sync your credentials across devices, you still have to upload them somewhere, right? Doesn't this just support sync via Dropbox? If so, aren't you then just playing the trust game between two third-parties?
- dorfsmay 11y agoYou are uploading a file that is encrypted using very strong encryption, not plain text password. An employee of that company, or if the file was leaked due to technical errors, a member of the general public won't be able to decrypt it. If one of the richest governments wanted to, they might be able to, but if you had reasons to be a target you'd know better than using this. Also, take a look at SpiderOak.
- oneeyedpigeon 11y agoIs strong-encryption something that 1password is fundamentally opposed to, or something they just haven't implemented yet? If I'm going to switch, the answer to question is pretty important.
- DenisM 11y ago>strong-encryption something that 1password is fundamentally opposed to? where did you this idea?
- oneeyedpigeon 11y agoThe comment I replied to which suggested that strong-encryption was a differential between keepass and 1password.
- DenisM 11y agoAs far as I can see, the comment you replied to contains no mention of these things. Can you quote the relevant part?
- oneeyedpigeon 11y agocmrx64: it all depends on how much you trust 1password and what your threat model is. For me, the advantage of keepass is that I don't need to upload my credentials anywhere oneeyedpigeon: But if you want to sync your credentials across devices, you still have to upload them somewhere, right? dorfsmay: You are uploading a file that is encrypted using very strong encryption, not plain text password I took that to mean: (with keepass) you are uploading a file that is encrypted ... not plain text password (as for 1password) dorfsmay has now confirmed that was their meaning in this comment: https://news.ycombinator.com/item?id=11177045 https://news.ycombinator.com/item?id=11177045
- supergreg 11y agoI use my own script to generate passwords. I don't store anything beyond a salt. The password is just a hash of the website name, the salt and a master password. Then I just copypaste the result. Simple is best.
- lorenzhs 11y agoI'm a big fan of FLOSS solutions, but I can't recommend KeePass/KeePassX/... over 1password. There are many people implementing KeePass-related things and most of them don't know much about secure development (nor do I claim to). 1password on the other hand has audits and professional security people. As long as they don't turn evil and give you a bad binary blob, I would bet on your passwords being more secure with them than if you were using one of the KeePass* tools.
- caskance 11y agoSure, in theory, 1password MIGHT have better private auditing and review. But there's no reason to believe they do. To the contrary, when asked about open sourcing 1password, one of their developers explained that they don't do formal code review because it's too expensive, and that none of the external experts they consulted with have ever performed a full review. https://discussions.agilebits.com/discussion/22686/open-sourcing-1password-was-security-question https://discussions.agilebits.com/discussion/22686/open-sour...