6 ms·
Has anyone done a thoughtful comparison of PW managers? I moved on from keepass because it was a huge hassle to use, but LastPass and 1password both have some
by Thriptic 8y ago
Has anyone done a thoughtful comparison of PW managers?
I moved on from keepass because it was a huge hassle to use, but LastPass and 1password both have some detractors as well.
- walrus01 8y agoI specifically use keepassx and v2 format keepass file db, separately, because it is not integrated with any browser via extension or plugin. Keeping things compartmentalized reduces risk in my opinion. And unless I copy the locally stored .kdbx file somewhere manually, it has zero interaction with any network, cloud based service, or third party beyond my control.
- com2kid 8y agoI was tired of browser plugins that just didn't always work quite right. Keepass, on whatever platform using whatever client, just uses the clipboard. 100% chance of working, although not safe against certain types of spyware.
- zokier 8y ago> Keepass, on whatever platform using whatever client, just uses the clipboard. 100% chance of working, although not safe against certain types of spyware On Android the preferred way of using Keepass is with custom keyboard, which protects against clipboard sniffing.
- GordonS 8y agoIt's not all clipboard based - Keepass has an RPC plugin that can be used with browser extensions for Firefox and Chrome. I also use Keepass2android for (duh) Android, and while you can use copy/paste it also has a custom keyboard you can use instead.
- com2kid 8y agoTrue, there are other options, but the fact that it works really well as a simple list of my passwords is what I like most about it. Between Chrome's cross-platform autofill, Firefox's autofill, and browser plugins, I have too many things telling me what my password should be. s
- bad_user 8y ago1Password is the best and I tried them all. A little pricey, but I've got important data in it and I use it every day, so at the moment I consider it to be worth the ~36 EUR per year. Previously a standalone license user, I've finally switched to their subscription model. Some people are afraid of storing that encrypted data on their servers, however I don't see the threat model as being any different than synchronizing with Dropbox, which I was doing anyway, plus it makes it easier for me to have a digital last will for my family.
- rodorgas 8y agoI paid a one time license fee of 1Password, then I use it offline on laptop and iPhone. I sync them through wifi regularly. This offline use option is not very disclosed on the website but it’s possible and in my opinion it’s more safe. I’ve tried open source password apps but the problem it’s they are all from independent developers. These developers can’t afford security reviews and I can’t tell if the version on the App Store is the same of the version on GitHub. If there’s a vulnerability and passwords leak, a company can be legally responsible, it’s not the same with independent developers. And it’s not practical to install an app and its updates from source on iPhone. So I went with the closed source 1Password because it’s a big company and everybody is looking at them.
- cevn 8y agoI'm using 1password the same way as you are. Their linux support is poor though.
- zebrafish 8y agoWirecutter has done a comparison of them. https://thewirecutter.com/reviews/best-password-managers/ https://thewirecutter.com/reviews/best-password-managers/
- toyg 8y agoAnd they picked the one that has had several high-profile security breaches... Not very credible.
- gowld 8y agoWhich ones have fewer breaches? Is there a comparison writeup somewhere? Lots of grimness: https://www.theregister.co.uk/2017/02/28/flaws_in_password_management_apps/ https://www.theregister.co.uk/2017/02/28/flaws_in_password_m...
- kapep 8y agoKeepass' copy&paste/autotype always felt like a hassle to me and also a bit insecure. When I was looking for alternatives for Keepass 2 I discovered the Kee [1] plugin for Firefox which communicates with Keepass via the RPC plugin. It's great and made me stay with Keepass. Login fields are automatically filled reliably without any issues. Registering accounts is easier too: just choose a username, let Kee generate a password, submit the form and then click the button to save the entry - all without having to use the Keepass UI at all. [1] https://addons.mozilla.org/de/firefox/addon/keefox/ https://addons.mozilla.org/de/firefox/addon/keefox/
- forapurpose 8y ago> Has anyone done a thoughtful comparison of PW managers? I think a valuable comparison would not be of features but of the security, and therefore a person comparing them would need real security expertise. I'd worry about bad information from non-experts. In the past, at least some security experts on HN have recommended 1Password. All these people storing all their secrets in one place creates an exceptionally valuable target that I expect, IMHO, will attract well-resourced attacks. Find a way to crack Lastpass, and imagine what you have - it's the ultimate breach (and if you are smart, nobody will know). To be a net gain in security, a password manager needs very effective security for itself. If the user wants something to ease the burden of managing all those exposed passwords, then perhaps features are the issue.
- gkya 8y agoI have in the past, but not written it down. My criterion was: - FOSS (totally indispensable) - Offline (totally indispensable, data you put on others' servers is not yours anymore) - Can be used from the CLI as well as some interface - Can be synced to Android With this, you have 2 options: pass, or keepass. The latter is a bit confusing, w/ many apps around one format and it's hard to know which one to use. Also the file format is proprietary, which means it's harder to use from scripts. pass on the other hand uses the filesystem, gpg and git, which are tools I always have around and know how to use. It's totally FOSS and totally local (Keepass is like this too), it's version controlled by default, can use it on android w/ Password Manager and OpenPGP apps (available from both the play store as well as FDroid), and it's easy to script (I've written my own Emacs fronted in no time), and while there are many third party frontend apps, there is one program that's blessed by the community as the default one, which is the pass(1) cli. One criticism on pass is that it leaks metadata because the file names usually contain the website domains. I think that's a non issue because usernames and websites are already known by many other parties (the website itself, and millions of people if it's sth like a social network), and we should not rely on hiding public information for security. Use long passwords and 2FA where available. But encrypting your hard drive would be more secure in the first place anyways. edit: formatting