5 ms·
KeePassXC 2.5
- jumelles 7y agoWhat sort of CLI interface does XC have? Can I finally replace keepassc?
- louib 7y agoRight now the best doc about the CLI would be the manpage I think https://github.com/keepassxreboot/keepassxc/blob/develop/share/docs/man/keepassxc-cli.1 https://github.com/keepassxreboot/keepassxc/blob/develop/sha...
- Evidlo 7y agoI wrote an interface that takes inspiration from pass: https://github.com/evidlo/passhole https://github.com/evidlo/passhole There is also keepassxc-cli and kpcli.
- mikece 7y agoThe “backup to paper” option is intriguing and I thought at first this would be as a series of QR codes instead of plain text. Will definitely be looking into the CLI options as well.
- AdamGibbins 7y agoIt's just a HTML export, nothing particularly special.
- breadandcrumbel 7y agoI was only familiar with Keepass. What are the differences between all the different products? KeypassXC, KeepassX and Keepass?
- AdamGibbins 7y agoKeepass uses .NET, so is dependant on the mono framework etc on non-Windows. KeepassX is no longer maintained. KeepassXC is maintained and more featured, it's also not dependant on .NET.
- apta 7y agoWouldn't this sort of software be better written in a safe language like C# as opposed to C++?
- moocowtruck 7y agono how else would we get your passwords?
- sha666sum 7y agoIt runs locally, and if the attacker has that much access, in most scenarios there isn't anything stopping your adversary from just logging your keystrokes and curling the keystore to a remote server.
- sebazzz 7y agoYes and no. In a language like C++ you might have more control on encrypting and zeroing out sensitive memory.
- tunesmith 7y agoFor mac users, there's also MacPass (https://macpassapp.org https://macpassapp.org), which is Keepass compatible.
- random3 7y agoSeeing the issue for Yubikey still open after 6 years, it doesn't inspire any confidence https://github.com/MacPass/MacPass/issues/90 https://github.com/MacPass/MacPass/issues/90
- kijiki 7y agoKeypass is written in C#, so requires a .NET runtime. KeypassX is a rewrite in C++, using QT. KeypassXC is a fork of KeypassX, as KeypassX was felt to be unmaintained.
- JohnTHaller 7y ago> KeypassX was felt to be unmaintained KeypassX was abandoned 3 years ago
- bscphil 7y agoActually it's still receiving commits, the maintainer just doesn't have a lot of time for it. https://github.com/keepassx/keepassx/commits/master https://github.com/keepassx/keepassx/commits/master
- JohnTHaller 7y agoNot sure if a single commit of two includes in the last two years really counts.
- delibratamateur 7y agoHey bscphil, if you'll recall you made a comment about 5 months ago saying that you were playing around with augmenting CarpalX to allow moving around the symbol keys in the model. I am interested in breaking down the model. Is there a place I'd be able to contact you?
- rolltiide 7y agoDoes this one have auto-saving of the key store after adding an entry? I've lost a lot from KeepPassX by being spoiled by other auto-saving managers over the majority of this century.
- mackrevinack 7y agoyea theres an option to save after every change
- maheart 7y agoAFAIK, that feature has been available for some time (I've been using it, and can confirm that it works flawlessly). You can find it under Tools -> Settings -> General -> File Management -> Automatically save after every change.
- simcop2387 7y agoXc does have that feature. Definitely a good thing
- ta0987 7y agoAnyone here have opinions on or pointers to the KeePassXC team's rep, creds or track record? I've been using KeePassX partly because Tavis Ormandy said it "looked sane" in a tweet once. How careful is the XC team when adding features?
- mehrdadn 7y agoWhat kinds of issues are you expecting? Short of actively writing malicious code, I feel like it's hard to get things terribly wrong in an offline password manager when adding a new feature? There are various mitigations you can put in against some potential attacks, but they're generally secondary lines of defense that require other breaches to occur first.
- ta0987 7y agoI don't know, that's why I'm asking the question. I've seen enough security bugs that I don't want to trust the gut feelings of a non-expert, such as myself. One example I can think of is another password manager that used random numbers incorrectly putting a bias in the random passwords it was generating.
- mehrdadn 7y agoWell something like that is core to the password manager, and already introduced into the product since the beginning. If the maintainer has been competent enough to use (say) a secure RNG until now, he's not going to suddenly mess it up when adding a new feature. Which is not to say it's a bad idea to get expert vetting for something like this (it's obviously an ultra-safe approach), but it helps to try to put things in context yourself, so that you don't have to find an expert every time you need to make a security decision. In the context of a desktop password manager, there isn't a terrible lot that can go wrong by accident and suddenly result in password exposure once the core product is formed and secure. If it happens, it'd be almost certainly due to a new maintainer coming along and somehow checking in unsafe code, rather than the current maintainers (say) suddenly forgetting they shouldn't call rand() or accidentally saving plaintext passwords on a disk.
- hirundo 7y agoIf I can't use it on my phone I need to run two different password managers, which is awkward at best. Seems like iOS/Android versions could help a lot with traction.
- yorwba 7y agoKeePassXC is just a GUI for a particular password database format. There are mobile apps supporting the same format: https://keepassxc.org/docs/#faq-platform-mobile https://keepassxc.org/docs/#faq-platform-mobile
- rex_lupi 7y agoThere are many keepass compatible apps available on F-Droid. I'm using KeePass DX, it has a clean ui, autofill support and fingerprint auth. https://f-droid.org/app/com.kunzisoft.keepass.libre https://f-droid.org/app/com.kunzisoft.keepass.libre
- panpanna 7y agoThat app looks good, thanks for sharing!
- sdan 7y agoIs this better than pass?
- jlgaddis 7y agoThat, of course, depends on your requirements and how you define "better".
- Tajnymag 7y agoTheoretically, you could consider it better. KeePass saves passwords in a single encrypted file by default. This means that an attacker has no idea about the structure of your entries and usernames. Plus, it's easier to setup on multiple machines, as you don't need to export/import your PGP keys from your initial machine. Features and ease of use are subjective to each user.
- pacomerh 7y agoI'll definitely use the monospace option. Does anyone know how to use the CLI version?, is it a separate app?
- maheart 7y agoAt least in Debian-based distros, the CLI version ships with the ``keepassxc`` package. I've used it on the odd occasion for password retrieval, and I can confirm it worked for my needs. You can find the manpage to give you some indication of what's possible: http://manpages.ubuntu.com/manpages/eoan/man1/keepassxc-cli.1.html http://manpages.ubuntu.com/manpages/eoan/man1/keepassxc-cli....
- all_blue_chucks 7y agoCan it auto-fill passwords on mobile apps?
- aaronax 7y agoI've been happy with Keepass2Android, which would be compatible with KeePass XC files.
- nichos 7y agoI used the keepass format for years up until a few months ago. I switched over to bitwarden, mostly for the sharing. Important accounts are sharedd between my wife and I, and I back everything up to my NAS regularly. For work, we're looking in to vault by hashicorp.
- donedealomg 7y agofor a split second I thought you said `my wife and I back everything up to the NSA`
- keepassxcoddity 7y agoShould I be concerned that upon installing 2.5 on MacOS it requested permission to Screen Recording?
- Nerada 7y agoThat's needed for the Auto-Type to find windows. https://github.com/keepassxreboot/keepassxc/issues/3675 https://github.com/keepassxreboot/keepassxc/issues/3675