8 ms·
> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that
by sprice 9y ago
> I recommend 1Password, and there's currently no other commercial password manager that I recommend.
Are there any open source password manager products that you would recommend?
- dahart 9y agoTotal aside here, because I know what you mean, but it's interesting that many people include open source software in their definition of "commercial" software, the DOD and other government agencies, for example. https://www.dwheeler.com/essays/commercial-floss.html https://www.dwheeler.com/essays/commercial-floss.html
- cyphar 9y agoA very large number of free software projects are commercial (either because distributions sell support for them, or the project itself costs money). The license for a piece of software has nothing to do with whether you sell it or give it away for free. Richard Stallman used to sell copies of GNU Emacs back in the day.
- dahart 9y agoVery true. But what's interesting and non-obvious about the way the DOD defines "commercial" is that it doesn't depend on money exchange (or lack of money exchange) at all, and that's what that article by David Wheeler is trying to say. The DOD defines software commerce as anything available to the public and used for any non-government purposes. http://dodcio.defense.gov/Open-Source-Software-FAQ/#Q:_Is_open_source_software_commercial_software.3F_Is_it_COTS.3F http://dodcio.defense.gov/Open-Source-Software-FAQ/#Q:_Is_op... So to take your comment one step further, for some organizations, the definition of commercial also has nothing to do with whether you sell it or give it away for free, even though many people reasonably assume commerce==sales.
- kronos29296 9y agoKeepass and its various forks are open source. Keepass itself uses dotNet so Linux guys need mono which not all people like. Those people use KeepassXC (a fork of KeepassX which is Keepass in C++ and is unmaintained). I use Keepass. Reasonable security but ugly gui in linux due to mono. Has plugins. Completely offline.
- cat199 9y agoditto. + kpcli for TTY use, keepassdroid for android, sync to owncloud, voila. If you are extra concerned with security after storing your file remotely, you can have it use an addtional external keyfile in addition to the which you manually copy to 'authorize' devices
- bmurphy1976 9y agoIf you can stomach an electron app Keeweb is a nice keepass compatible alternative.
- 6ak74rfy 9y agoThis looks nice. How has your experience with it so far?
- s_chaudhary 9y agoI have been using keeweb on mac, it's a delight.
- kronos29296 9y agoI can't. Atom has given me electron trauma (older versions about a couple of years back).
- devcpp 9y agoThen forget about it. Keepass2 and KeepassXC (depending on your OS) are the best of the best.
- 9y ago
- tallblondeguy 9y agoIt's not quite ready for prime time yet, but my company is working on Passit[0], which is going to do open source cloud-based password management. Feel free to check it out; we hope to do a 1.0 release soon. I've been working on the marketing a bit, and the sense I get in this space is that, like home security, password security is a series of trade-offs. One size doesn't fit all; different situations require different needs, and everyone tries to balance the safety they want to feel with convenience that they desire. So, in our case, there are a couple of good options. You could operate on a hosted service and get the cloud-based benefits without needing to worry about infrastructure or updates, or you could self-host and trade a bit of hassle in exchange for trusting the host and verifying that the updates will do what they say they're going to do. [0]: http://passit.io http://passit.io
- bqe 9y agoI use pass, written by zx2c4 of WireGuard fame: https://www.passwordstore.org/ https://www.passwordstore.org/ My favorite thing about it is that it uses standard tools I understand, and I can back it up and version it with git.
- atmosx 9y agoIt doesn't have a browser plugin and will not work with my iPhone... So it's a no-go for me and I guess many others.
- ekimekim 9y agopass has a variety of 3rd party browser plugins and phone apps that work with it. Admittedly, it's not a turnkey solution and so is unsuitable for a non-technical audience. I recommend website-based password managers to my non-technical friends because they're easiest to use and therefore most likely to actually BE used, and the security vulnerabilities noted in the article are very small compared to not using a password manager at all.
- bqe 9y agoI wouldn't let any password manager touch my browser. Giving attackers access to your password manager's APIs via JS or DOM elements is how most (all?) of the dozens of severe LastPass bugs have happened.
- ViktorEvil 9y agoPass - Password Store by Mingshen Sun https://appsto.re/gb/DY13hb.i https://appsto.re/gb/DY13hb.i
- curun1r 9y agoAs a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cloud storage services and their monetization strategy seems pretty reasonable (desktop is free, mobile costs $9.99). I'd encourage any disgruntled 1Password users to give it a test drive. [1] https://www.enpass.io/ https://www.enpass.io/
- tptacek 9y agoHave you put much energy into making sure that Enpass is secure? Do you know who's reviewed it, and what their review looked like? It bothers me when people point to other password managers as alternatives to 1Password because of packaging and pricing issues. It's easy to find other commercial password managers that have attractive packaging and pricing! That's not the hard part! I happen to like 1Password as a product, but that's not why I recommend it.
- curun1r 9y agoSince neither of them are open source, I haven't put energy into making sure either of them is secure. Not being a security researcher or having access to either product's code, I'm not sure how I could be expected to perform that level of evaluation, but I've built systems that have passed security reviews and, from a non-privileged access point of view, I see little difference between the two. Enpass does seem to handle security incidents in a pretty responsible fashion. They post blog updates on vulnerabilities (e.g. https://www.enpass.io/blog/an-update-on-the-reported-vulnerability-of-enpass-for-windows-pc/ https://www.enpass.io/blog/an-update-on-the-reported-vulnera...) after releasing fixes. It's great that you recommend 1Password based some other criteria, but I'm not sure why your recommendation should mean anything to me unless you've been given some privileged access to their code that the rest of the world doesn't have and if you have been given that type of access, it's irresponsible of you to denounce other products unless they've denied you similar access. What I can see is that 1Password is pushing users towards a model that's fundamentally insecure. Their web-based products require a level of trust in 1Password (the company) that none of us should be willing to place in any company. What we've learned from Snowden is that any cloud provider can be secretly made to bend to their governing body's will. Running closed-source software on our own computers involves a level of trust in the authors of that software. That's just a fact of life when software isn't open source. But when code is pushed out into the world, it can, at least, undergo some scrutiny/testing by people outside the company. This is not true of software running on the company's servers. In so much as the security of 1Password requires executing a single, line of code on servers controlled by 1Password, the product is insecure and fundamentally unauditable because that line of code can be changed at any time without users being made aware. The other point that should probably not get lost is that we're dealing with levels of security. In advocating for password managers, the interface absolutely does matter. Most computer users haven't adopted any password manager yet. When comparing a secure but difficult to use password manager, a potentially insecure password manager with an easy-to-use UI and a combination of insecure passwords, post-it notes and all the other terrible ways that users have of "managing" their passwords, the middle ground is likely to come out ahead for all but the most technically adept users. Need proof? PGP/GPG passes security reviews but has terrible UIs...what percent of emails are PGP/GPG encrypted? We shouldn't let the perfect be the enemy of the good. There can be different classes of security products for those that need protection from state-level actors and those that don't. Because people who are worried about that level of attack are generally willing to undergo a lot more pain to stay secure than your average user is.
- remy_ 9y agoPassbolt, give it a try! https://www.passbolt.com/ https://www.passbolt.com/