5 ms·
Their messaging was pretty poor here imo. The email they sent me gave no clear indication that Firefox would have this ability in it's body.
by trebcon 5y ago
Their messaging was pretty poor here imo. The email they sent me gave no clear indication that Firefox would have this ability in it's body.
- swdunlop 5y agoDitto. I came to HN after seeing the email, looking for the best way to migrate my passwords out of Lockwise. Well, still looking. They are outta here.
- Spivak 5y agoBitwarden is my goto. If you're the selfhosting type bitwarden_rs (now vaultwarden) is free and easy to setup. If not BW's cloud hosting is also fine. Vaults work offline just fine, apps on every major platform, biometric unlock if you care about such things, and autofill on browsers/ios/android. And they have a snazzy officially supported CLI tool.
- ulimn 5y agoAnd if you pay $10/year, it has 2FA as well. And you can add notes and such. It's definitely worth using (and paying imo).
- YXNjaGVyZWdlbgo 5y agoWait so it lets you store your 2FA secrets and your password in the same place? That sounds counterintuitive.
- jfrunyon 5y agoIt's super useful for a few sites I visit frequently who require 2FA but I don't need that security. But yeah, otherwise it's a pretty remarkably bad idea.
- scrollaway 5y agoWhen you sign in to a website from your phone using a saved password and use that same phone for 2fa, it's pretty much the same thing. The whole meme that saving the 2fa seed to password managers is a bad idea needs to die. Most of the advantages of 2fa are still present when using a password manager.
- jfrunyon 5y agoIt's the other way around. Literally all of the advantages of using 2FA are not present when you store both factors together.
- scrollaway 5y agoYou are wrong. The primary advantage of 2fa is the OTP part, which wards against keyloggers and password reuse.
- jfrunyon 5y agoUnless of course the keylogger also has access to the OTP. If your device is compromised, your device is compromised. It doesn't matter what the advantages of 2FA are. You don't have 2FA ("two-factor authentication") if your factors are stored together.
- KennyBlanken 5y agoKeepass + your choice of file sync. Keepass's database has file-based locking so it's safe to sync just via filesystem. I like KeepassXC one Android and MacOS; Keepassium free-tier on iOS works great. On Android you can use syncthing, but syncthing doesn't work on iOS, so I use NextCloud to sync everything now.
- Firehawke 5y agoKeepass2Android supports Dropbox, Onedrive, and a few other ways of direct sync. https://play.google.com/store/apps/details?id=keepass2android.keepass2android&hl=en_US&gl=US https://play.google.com/store/apps/details?id=keepass2androi... For Windows 10/11 users who use a MS account, put a portable copy of Keepass on OneDrive and it'll be there right after a fresh reinstall plus sign-in, and you can access it from the Android app using OneDrive sync built into K2A.
- kenniskrag 5y agoKeepass2Android also supports webdav, http, ftp, sftp and nextcloud directly
- emaro 5y agoFor iOS I can also recommend Strongbox.
- anmipo 5y agoFor Syncthing on iOS there is Möbius Sync. However, it struggles with background updates (due to iOS restrictions).
- orhmeh09 5y agoSafe even on NFS? ;)
- thinkloop 5y agoNo-one seems to ever mention LastPass for some reason when this comes up. It's a complete solution, locally-encrypted, backed-up to the cloud, auto-fill, apps, all platforms, etc.
- ziddoap 5y agoNot open-source, 3rd-party trackers in the android app, no easily accessible 3rd-party audits (that I can find), an unintuitive UI (no easy 1-button copy, clunky item entry*, etc.), and roughly 1 security incident every 1.5 years. Are they the worst? No. Are there better ones? Yes. *The number of people at work which put their username in the URL field is astounding. We also have people saving personal passwords into shared folders without realizing it. This speaks to UI issues.
- agolliver 5y agoI'd also say it's integration with Firefox on Android is just a broken, miserable experience. (I mostly blame FF for this, because it used to be great) https://github.com/mozilla-mobile/fenix/issues/9773 https://github.com/mozilla-mobile/fenix/issues/9773
- reiichiroh 5y agoLastPass has stagnated last few years after being bought out and raising prices for no additional benefit
- jonchang 5y agoThese are the first paragraphs of the email I got: > On December 13th 2021, the Firefox browser will be officially "resorbing" Firefox Lockwise. Don't worry, all your saved Lockwise passwords will still be available through the Firefox browser using a Firefox account. > The Firefox Lockwise app will no longer be updated and supported by Mozilla and will not be available in the Apple App and Google Play Stores. After that date, current Lockwise users can continue to access their saved passwords and their password management in the Firefox desktop and mobile browsers. It seems pretty clear-cut to me.
- vorticalbox 5y agoi am not sure this is the same, lock wise let you fill in passwords on any application not just in the browser
- Vinnl 5y agoIt is the same; I'm using Firefox Nightly to prefill passwords in other apps.
- OJFord 5y agoIt's the same, I panicked at first then found the setting thanks to a fellow commenter. Search my name in this thread and I detailed it in response to someone else. Sibling says it's working in Nightly -- I'm using the regular stable release on Android and it's there. Haven't even updated it for a few weeks at least. (I just didn't know it existed before now, I was using Lockwise.) All in all it makes sense tbh - Lockwise used FF account and sync... Who would have one with synchronised data and not be using FF on their phone (esp. Android) anyway?
- OJFord 5y agoIf I got an email, I haven't read it yet. But I have seen this on the site via HN (make of that what you will...) and it's completely unclear. It says the functionality is coming to FF for iOS in December, but fails to mention that Android already has it (doesn't mention it at all) or if there are any differences at all to be aware of.
- 5y ago