6 ms·
I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.
by buildzr 7y ago
I'm avoiding the browser extensions, they seem to be a security nightmare. KeePass and similar are a better way to go, if slightly more labor intensive.
- proaralyst 7y agoWhat is your phishing protection? Making sure you read the URL?
- Globz 7y agoJust add the original URL into the specified field and copy paste it each time you need to access said website. KeePass is the best at what it does and stays local as any password manager should do. If you need more security & portability encrypt the DB with VeraCrypt, sync with whatever service you trust.
- kencausey 7y agoJust a note that URL is the one field in Keepass where you may not need to copy/paste. As long as your default browser setting is set to the browser you want to use for the URL double-clicking on the URL in Keepass opens it in said browser.
- sixothree 7y agoI wish keypass didn't feel so awful to use. I hate that you can't change the font of the notes section, especially since it's the only section I use in their entry type.
- tobib 7y ago> KeePass and similar are a better way to go, if slightly more labor intensive. Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.
- soulofmischief 7y agoIf you don't require real-time diffing, i.e. only one user modifies the file at a time, dropping your keyDBs in a Keybase shared folder might solve your problems.
- jdmichal 7y agoI've had my KeePass file stored in the cloud for years. I use the KeeAnywhere plugin on my Windows boxes for syncing there. And the Keepass2Android app natively supports cloud syncing also. Both even handle merging if the underlying file changes since load.
- tripzilch 7y agoI didn't know about merging! That's really cool. I'd want to test it out before trusting on it though.
- mbromilow 7y agoFor just over a year I've been using Syncthing with a folder specifically for KeePass, and it's worked really well - I just have a raspberry pi running 24/7 so my phone and PC pick up the changes whenever I reopen my database. I imagine it's similarly hassle-free with a self-hosted cloud like Owncloud, too.
- gnud 7y agoI store the keepass file in a cloud sync service. The file is encrypted. The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button. Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.
- js2 7y agoPasswordWallet can auto-type across split login screens since it can be configured to pause between username/password.
- Someone1234 7y agoAnything that isn't context aware (i.e. knows which website you're on so can provide the relevant information) is doomed to failure right out the gate. I'd prefer people are using any password manager than go for perfection and then quit completely because it was a terrible UX. KeePass may be more secure against certain specific attacks, but it is largely irrelevant if people are going to contrast it against using no password manager at all because it was too cumbersome.
- kerng 7y ago>> Anything that isn't context aware (i.e. knows which website you're on so can provide the relevant information) is doomed to failure right out the gate. Sorry, not doomed to fail. I'm not gonna use a password manager that is "context aware" and has the capability to auto-fill for sensitive sites - that's just my threat model. I'm okay with context aware storing of less critical passwords.
- jsutton 7y agoThe vast majority of people don't have the same threat model, and unfortunately just want the product to work, or they won't use it at all. If you can't provide relevant information for the current website, you just won't be able to succeed as a password manager outside of niche markets.
- reilly3000 7y agoYes, but that's the essence of the whole problem: there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Diabling autofill pretty much eliminates the whole vector though, without breaking UX that hard.
- dsissitka 7y ago> there are ways to spoof what the current website is, causing your context-aware password manager to spit out data it shouldn't. Can you give an example?
- smilbandit 7y agoyep, keepass is my preferred password manager. i have the database in a dropbox folder to handle syncing between my desktop and android phone.
- bad_user 7y agoKeePass isn't a solution in case you want to share passwords with family or team members. KeePass is barely decent for personal use only, and only for the desktop. The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically unmaintained, barely usable and does no sync so you'd better watch out for conflicts.
- blahyawnblah 7y agoI've used keepass in a team before. We just kept the file in a synced shared folder. Worked fine.
- bwblabs 7y agoI use KeePassXC in multiple groups with different synchronization software (Dropbox, self hosted client side encrypted Seafile, etc.), for each group I use a different .kdbx and .key (of course that one not synchronized). There are multiple .kdbx apps, like MiniKeePass on iOS, which is decent, but it's lacking active development at the moment.
- farisjarrah 7y agokeepassdx for android works great
- arunc 7y agoWe use Keepass2Android[1] on Android and KeePass Touch[2] on iOS, synchronize it via Google drive and share it with family across various devices on Linux and Windows. Separate DB for family outside the country and it works beautifully. [1] https://play.google.com/store/apps/details?id=keepass2android.keepass2android https://play.google.com/store/apps/details?id=keepass2androi... [2] https://apps.apple.com/us/app/keepass-touch/id966759076 https://apps.apple.com/us/app/keepass-touch/id966759076
- limuc 7y agoThere is no KeePass-app for iOS (in the sense of the one/official). I think you mean MiniKeePass. There is Strongbox on iOS and it's by far the best mobile KeePass-experience i've ever had.
- triceratops 7y agoUse Lastpass but not the browser extension. Keep a different browser just for opening the Lastpass website and copy-paste the passwords from there.
- tripzilch 7y agoCrazy amount of hate on KeePass in this thread ... I really don't get why it's not a more common solution on HN, it's free and open source and leaves the syncing to you, and doesn't live inside a browser extension ... it literally ticks all the boxes that a good password manager should have. I don't know if the iOS client is that bad, but the Android one is just fine.