4 ms·
KeePass looks nice. Currently I'm using pass but I will investigate KeyPass either as a recommendation for others or possible alternative to my current solution
by presto8 4y ago
KeePass looks nice. Currently I'm using pass but I will investigate KeyPass either as a recommendation for others or possible alternative to my current solution.
I set up pass (on Linux and Mac, using brew) with two GPG keypairs, a soft keypair and a YubiKey. The YubiKey goes in a physical safe along with instructions for next of kin (and as an ultimate backup for me). YubiKey is protected with PIN.
For daily use, use the soft GPG key and gpg-agent to cache it. PassFF on Firefox (or see github passforios for iOS) or command-line tools (easily can build hooks with dmenu/rofi as well).
pass stores the gpg-encrypted passwords in a Git repository. Set up a private remote repository and push to it for offsite backup. There is some leakage of info as the names of the sites become the filename, e.g., ycombinator.gpg. This can be mitigated with some plugins like tomb, but then PassFF and passforios won't work.
- stjohnswarts 4y agoLook at KeepassXC and vaultwarden as well before you decide on a final app.