3 ms·
I trust a local password manager, namely KeepassX running on my linux laptop. It's an open source dedicated piece of tech running on the local box, so I figure
by downsplat 5y ago
I trust a local password manager, namely KeepassX running on my linux laptop. It's an open source dedicated piece of tech running on the local box, so I figure my trust model extends at least this far.
Otherwise, no, I wouldn't trust a commercial password manager with automatic sync on to someone else's servers. I also don't trust the browser enough to put an extension in it that has the keys to my password database.
It's a tradeoff. I get a nice level of security, but it's not 100% seamless. Without autofill, I often need to start up the password manager, search for a site, copy and paste password into the browser. (I just had to do this to log into HN.)
For some sites, I let the browser also save the password, which I treat as just a cache of low-value passwords. And the encrypted password manager database gets occasionally synched into gdrive, so I can also access it from my smartphone using the appropriate app.
Been doing this for 5+ years at this point, and it works for me... can't even remember what on earth I did before. Probably passwords in tiny plain text files.