4 ms·
how is your experience in a browser? I honestly tried to use Bitwarden, paid for premium for one time key feature and browser extensions comparing to 1pass are
by tarasmatsyk 6y ago
how is your experience in a browser?
I honestly tried to use Bitwarden, paid for premium for one time key feature and browser extensions comparing to 1pass are much less convenient. For instance, an ability to manage multiple website (e.g. google) accounts is priceless
- sigzero 6y agoI never had any problems using BW and my multiple gmail accounts?
- mikece 6y agoA habit I carried over from using KeePassXC is that I don't use a browser extension. Call it paranoia but I don't want the browser process to have the ability to reach into my password manager. What I do is pin the Bitwarden tab open and just copy & paste where needed. For the desktop app it would be awesome if it had an auto-type feature like KeePassXC (something that mystifies coworkers who see that in action for the first time, even remotely). Even though my employer has a corporate LastPass account for shared production passwords I insist on using KeePassXC for non-shared credentials. I've told those who need to be notified and there is general indifference what password manager I use for non-shared credentials (AWS login, GitLab credentials, storing SSH keys, etc) as long as it's secure.
- delroth 6y agoBrowser extensions have the benefit of being more resilient against phishing (since they can perform origin checks), which I would definitely recommend for most users.
- selykg 6y agoYou're losing out on certain types of phishing protections by doing this. You're also potentially opening yourself up to any apps/tools that are keeping an eye on your clipboard if you're copying and pasting. Auto-type might help with that, but I also wouldn't hold my breath for such a feature coming.
- mikece 6y agoThat is the one thing that worries me about iOS (okay: the BIGGEST concern, not the ONLY concern) now that's it has been shown that TikTok and LinkedIn (apps not on my phone) have been shown to be copying the contents of the clipboard. I had not thought of using a browser plugin to avoid clipboard scavengers on non-mobile OSes: I'll have to give that some thought now.
- TonyTrapp 6y agoAnd at the same time you win by not falling victim of "oops, there is a bug in our browser add-on that accidentally leaks arbitrary login data to websites", as it has happened in the past. Leaking all my credentials certainly sounds more concerning to me than leaking the credentials to a single page.
- selykg 6y agoEh.. I'm going to go a different route. Compromising everything is easier, it means you have to change the password for everything and know it was compromised. If only SOME stuff is compromised then you don't know what was compromised so you end up having to change everything anyway. I mean, that's at least my approach. I'd rather know I needed to keep an eye on everything rather than some things. At least then I know I can take appropriate precautions.
- john-shaffer 6y ago
- vbezhenar 6y agoI'm doing similar thing with KeePass. While there are browser extensions to work with KeePass, I decided to not use those. I'm using Ctrl+B, Ctrl+V for user name and I'm using Ctrl+V which sends keystrokes into browser to fill password. Actually most of websites remember my login information for a long time, so this is not a problem at all. And I like to keep some sense of control over my private data.
- Latty 6y agoAs pointed out elsewhere in this thread, there is a danger here that you have to manually verify the origin of the page you are on, which makes you far more vulnerable to phishing attacks, which are common and can be very sophisticated (things like pages that look like normal content but change to a fake Google log in page when you minimise the page, so when you come back, it is there waiting).
- Latty 6y agoKeePassXC has a thing where it asks you before it will give the browser the password the first time for a given URL. I don't know if you can force it to always prompt you, but that would seem a better solution—as others have pointed out, copy/paste and even auto-type opens you up to more attacks.
- selykg 6y agoBitwarden supports multiple accounts. If you have two logins for the same service with the same URLs they'll appear in the browser extension with the username shown by the title. If you're instead talking about using the same login credentials on multiple sites, it can do that as well, just edit the item and add a second URL to the site. Now that item will appear on both site URLs
- paulryanrogers 6y agoKeePass can support that too. If it sees more than one match when auto typing it'll prompt you to choose.
- tarasmatsyk 6y agoYep, I saw that, the feature I was trying to describe is a popup on a username that gives you a list of all accounts tied to this domain, which is quite handy. In Bitwarden I have to either right click or copy/paste from the extension. A bit awkward IMO