5 ms·
http://keepass.info/ http://keepass.info/ is awesome. Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers. Keepass2Android works g
by johnjuuljensen 10y ago
http://keepass.info/ http://keepass.info/ is awesome.
Put your keyfile on Dropbox/OneDrive/whatever so it syncs to all your computers.
Keepass2Android works great and can read from most cloud storage solutions.
Don't know about iPhone.
Edit:
It also has a lot of neat plugins. I use one for storing ssl certificates, which also supports key forwarding to putty.
- el_benhameen 10y agoWould love to hear from someone who has an iPhone and uses Keepass or a derivative. That's my last barrier to using it.
- graedus 10y agoI do. I use the MiniKeePass app, which is free. You can export your KeePass database (.kdbx) from the Dropbox app to MiniKeePass.
- scott_karana 10y agoDitto. It doesn't make for a good _write_ experience, since you have to copy back to Dropbox manually, but I find that I almost exclusively _read_ passwords, so it's a non-issue for my use case.
- irrational 10y agoDoes this keep things auto synced up between all your devices? I'm constantly switching between different desktops, laptops, tablets, etc. and I'd love a replacement for LastPass that auto syncs just as well and also works on iOS.
- graedus 10y agoAs far as I know the system I described is manual only on iPhone. That is, if the database file gets updated on another device/computer, you have to manually re-import it from Dropbox to MiniKeePass to see the update there. On desktops/laptops, if you're pointing KeePass at a database file in a Dropbox-synced folder, then it's automatic.
- icc97 10y agoYou can also add in KeepassHttp + PassIFox. But I wonder if these might have similar vulnerabilities as they too would be handling decrypted passwords.
- compuguy 10y agoTrue, but there are a slew of security issues (and unknowns) with KeePassHttp: https://github.com/pfn/keepasshttp/issues/258 https://github.com/pfn/keepasshttp/issues/258 https://github.com/keepassxreboot/keepassxc/issues/147 https://github.com/keepassxreboot/keepassxc/issues/147 I've been looking for a alternative with somewhat parity with lastpass with a better security policy.
- kirushik 10y agoEnpass seems to be your (and mine) best choice at the moment. At least it's a standalone Qt application (not a JS-based browser one), with it's separate UI and without any autofills without asking. Bonus points for reasonably good integration with your usual clouds (Dropbox, GoogleDrive, OwnCloud, etc) for synchronization. Cons: NOT open-source, paid cellphone apps.
- icc97 10y agoThat #258 issue is for if you use it remotely - which by default it isn't and I don't. The other issue you raise is based on top of that. So as long as you're using KeepassHttp with localhost then you should be ok. So a slew is not necessarily accurate. But I take you're point, it's definitely a similar weak point that LastPass has.
- ekingr 10y agohttps://keeweb.info/ https://keeweb.info/ is also very nice. It has a very convenient Dropbox (& co) integration.
- avoutthere 10y agoPutting one's keyfile in the cloud just seems to me to be asking for it. You're essentially trusting a 3rd party with the keys to your kingdom.
- r3bl 10y agoNo. You're trusting the encryption of the password manager. No self-hosted password manager that I know of keeps your passwords in a clear text file.
- WorldMaker 10y agoA) You should presumably still have a good passphrase. B) You choose which 3rd Party to trust. There are many options with different security/trust/threat models. (Example: lately I've been using an encrypted share in Resilio Sync where the "cloud" option for me is a dumb VPS that can share the folder torrent but does not have decryption keys into the contents.)
- TorKlingberg 10y ago* Compared to completely cloud-based password manager like LastPass and 1Password, it's no worse. * The database in encrypted with your master password. * You can optionally also encrypt it with static "Key File" that are on all your devices but not in Dropbox.
- extra88 10y ago1Password seems to put saving to their cloud front and center but you can still choose to not save your passwords on their servers and use your own methods. My 1Password vaults are encrypted with my master password and synced between devices using Dropbox, I think there's also an option for directly syncing between smartphones and computers.
- deleted 10y ago[deleted]
- Johnny_Brahms 10y agoI don't trust dropbox, but I do trust the encryption of my password manager. Depending on how you measure, my key is somewhere between 100-150 bits, and even if that was feasible to brute force, I am not that important.
- Veratyr 10y agoI tried Keepass but couldn't find a Mac compatible port that supported import from CSV, which kinda kills it because I already have all my passwords elsewhere and there are too many to move manually.
- fencepost 10y agoI may be misremembering, but I thought this was the method used by at least one other app. 1password comes to mind but I can't check it right now. I ran into this when checking unexpected files on a client's system.
- iKlsR 10y agohttps://www.enpass.io/ https://www.enpass.io/ is better, does the same, you sync the wallet across your machines and devices, also has browser integration. https://www.enpass.io/security/ https://www.enpass.io/security/
- mderazon 10y agoLooks nice but no sharing options
- irrational 10y agoI would like to know this as well. I tried setting up keePass on iOS, but was never able to get it to work so it seamlessly kept things in sync between all my devices (two desktop computers, three laptops, two tablets and an iphone). I then tried LastPass and so far it was worked flawlessly for me across all devices. Now I read this and I'm not sure what to do. Prior to LastPass I used the same six character password for everything. Now many of my passwords are 30+ characters long. That seems more secure, but if someone can just grab my passwords while I'm browsing then maybe it's time to go back to the same 6 character password that I can remember.