8 ms·
Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features: 1. Mac/Window/
by bluedonuts 10y ago
Long time unhappy user of Lastpass here. Would really like to hear what alternatives people are using that have at least the following features:
1. Mac/Window/Linux support
2. Ability to control accounts from an admin account. PW/2FA reset, export/wipe of accounts etc.
3. Reasonably secure
4. Not too terrible to use for Engineers/non-techies alike.
- marksomnian 10y agoNot sure about point 2, but 1Password seems to fit all the others. Really like it, personally.
- moyix 10y ago1Password didn't support Linux last time I checked. There are 3rd party libraries, but most of them don't support the newer keychain format. I still use it and just look up the password on my phone when I'm on a Linux system.
- nsm 10y ago1password has their opvault format spec on the website and https://github.com/OblivionCloudControl/opvault https://github.com/OblivionCloudControl/opvault can decrypt. Admittedly the UX is lacking.
- moyix 10y agoI've tried that library, actually. Last time I used it, it couldn't find some passwords in the vault, including (crucially) the one I use for SSO at work. It's totally possible I was just using it wrong – it would be nice if the repository had a demo command line tool or something.
- BenElgar 10y agoI believe 1Password only supports Windows and OS X on the desktop.
- bpicolo 10y agoI imagine 2. works if you buy the enterprise options?
- wazanator 10y ago1password along with seemingly every other mobile password manager slips up from time to time. Turn around time once something is disclosed is my main concern. https://team-sik.org/trent_portfolio/password-manager-apps/ https://team-sik.org/trent_portfolio/password-manager-apps/
- Sir_Cmpwn 10y agoI can't help you with #4, but I've been a pass user for a long time: https://www.passwordstore.org/ https://www.passwordstore.org/ It encrypts your passwords with your GPG key and stores them in a git repository. You can of course easily extend this to do a lot of different things. I also wrote this tool for automating password rotation: https://github.com/SirCMpwn/pass-rotate https://github.com/SirCMpwn/pass-rotate
- eli 10y agoIt's easy when you're the only user. Pretty tricky when you want to share entries among different groups of users.
- Sir_Cmpwn 10y agoIt's probably an afternoon project to get that functionality. Since it's just a git repo, that much is easily shared. GPG supports encrypting messages for multiple recepients. Since pass is simple and open source it should be quite easy to add what you need. Send your patches upstream, I'm sure that others would find them useful too!
- visualphoenix 10y agoAlthough I haven't tried it myself, it looks like pass already supports this using the PASSWORD_STORE_KEY variable in the set_gpg_recipients() function. [0] [0] https://git.zx2c4.com/password-store/plain/src/password-store.sh https://git.zx2c4.com/password-store/plain/src/password-stor...
- runejuhl 10y agoOr just put key IDs in a .gpg-id file: Initialize new password storage and use gpg-id for encryption. Multiple gpg-ids may be specified, in order to encrypt each password with multiple ids. This command must be run first before a password store can be used. If the specified gpg-id is different from the key used in any existing files, these files will be reencrypted to use the new id. Note that use of gpg-agent(1) is recommended so that the batch decryption does not require as much user intervention. If --path or -p is specified, along with an argument, a specific gpg-id or set of gpg-ids is assigned for that specific sub folder of the password store. If only one gpg-id is given, and it is an empty string, then the current .gpg-id file for the specified sub-folder (or root if unspecified) is removed. -- https://git.zx2c4.com/password-store/about/ https://git.zx2c4.com/password-store/about/ EDIT: Better formatting
- problems 10y agoKeePass recently got an Argon2 KDF and ChaCha20 as a cipher. I highly recommend it, good mobile apps, pretty simple UI, control over your own DB, sync it with your favourite tool, I use SyncThing as its Android support is excellent.
- snowwrestler 10y agoWhich mobile app do you use with KeePass? I use MiniKeePass and am pretty happy with it.
- ktta 10y agoI'm not the user you replied to, but that app looks like the only good app, atleast for iOS.
- problems 10y agoI use the open source Keepass2Android which is open source and supports the new crypto, has just about every utility I could want. https://keepass2android.codeplex.com/ https://keepass2android.codeplex.com/
- mihaifm 10y agoIt's a good app but as far as I remember the integration with Dropbox wasn't working properly. I think that's the main issue with KeePass right now - getting your passwords synchronized with your phone.
- problems 10y agoSyncThing solves this quite nicely on Android at least. For iOS, I'm not sure, Apple's restrictions make proper sync near impossible in the name of battery life - even while charging or on WiFi.
- ktta 10y agoI would suggest KeePassXC, which in my opinion, looks better since uses Qt rather than mono so has a more native feel. https://keepassxc.org/ https://keepassxc.org/
- gfsadhfsd 10y agoFlat text file on an encrypted volume. I use cat or vi for editing, and grep for reading. If it's ultrasensitive, I keep it on a non-networked device and type it in. Otherwise, normally, I grep and copy/paste from terminal to password field. I do security for a living. This technique is mocked by other so-called experts, but who's laughing today? I fully understand the security model I'm using. Lastpass users--and developers--clearly did not. Other password manager users should stifle the urge to laugh if they haven't fully reviewed their entire stack.
- gfsadhfsd 10y agoAlso, I do not keep the encrypted volume in the cloud. It's only on my trusted device. If it's important enough to secure the password, it's important enough to bring the device. Further, I've used variations of the same password for the past two decades for >90% of my accounts, e.g., the ones where my threat model is "do not give a fuck." When I sign up, I mentally consider whether I give a fuck the account is compromised. If I do, new random password for the list. If I don't, use the 20-year-old password.
- gfsadhfsd 10y agoIf it's really ultrasensitive, it's 12+ character random ASCII string committed to muscle memory only. No horse battery stapling bullshit.
- daveFNbuck 10y agoA 6-word diceware passphrase has more entropy than 12 characters of ASCII and is easier to memorize. In what way is that bullshit?
- gfsadhfsd 10y agoNope. 94^12 ~= 4.76e23 > 7776^6 ~= 2.21e23. And typing 12 characters from muscle memory is faster than learning and typing "limbdumaslaterjuramondohalf", which is what diceware^6 just gave me. The supposed mnemonic value of diceware is illusory. If it convinces people to use stronger passwords and it works for you, great.