16 ms·
I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to
by 40four 4y ago
I know password manger services are super convenient, and probably worth the cost for most, especially non technical users. But my preference has always been to manually manage my own local KeyPass database.
Sure it’s more cumbersome when it comes to syncing between devices, but it’s really not a big deal. One or twice a month I will combine my DBs from all my devices ok one machine, use the built in ‘merge’ functionality, and redistribute the I updated DBs back out to each device. It might take 10 minutes.
But I can rest assured that I’m the only one who has a copy of my DB/ key files, and a breach of _blank_pw_manager_ service can’t compromise my secrets. Highly recommend KeyPass. It’s free and open source, with high quality community ports available on every platform. https://keepass.info/index.html https://keepass.info/index.html
- m101 4y agoWhy not use OneDrive to keep your files synced? That's what I do with keepass
- dgrin91 4y agoHere is my problem with KeyPass: its unclear to me how it deals with emergency family access. Last year my father unexpectedly passed away. All his stuff was on lastpass. Thankfully we had emergency access setup, and I was able to get into all his accounts 2 days later. It was an exceptionally important part of the transition phase, and without it we would have experienced significant financial harm. How would KeyPass deal with the same type of situation?
- tyfon 4y agoMy wife and I have the password to our vaults in each others vaults, however I am not sure what would happen if both of us die. Edit: as a site note, have used keepass + file on my (vpn reachable) synology for like 10 years, never had any issues. I use it in linux, android, ios and windows.
- rietta 4y agoHave to plan ahead and have the keypass password in an envelope in the safe deposit box.
- linuxlizard 4y agoYes. I do this. I have all my financial account numbers and passwords written on a piece of paper stored in my safe deposit box. If anything happens to me (knocks wood), my family will still be ok.
- irrational 4y agoWhat else is in your self deposit box? I thought only rich people with gold and jewels and spies with fake passports and ready currency used safe deposit boxes.
- NikolaNovak 4y agoWhen we first immigrated to Canada my family kept some of our documents such as birth records etc. It was super cheap and my family felt security was beneficial. I don't have one currently but perhaps I should.
- drexlspivey 4y agoMost people in here are rich.
- wmeredith 4y agoI'm middle class. We have a safe deposit box where I keep stuff that would be a pain in my ass to replace in the event of a fire/flood/etc. Said items are titles to my vehicles and home, my marriage license, the will of a family member I've been entrusted with, birth certificates for my self and family members, and a couple of keepsakes for the kids that I'm very long on. It only costs me about $80 per year, and it brings me a lot of peace of mind. I have photocopies of all those docs at home, because you rarely need the real thing.
- rietta 4y ago
- simoncion 4y ago> How would KeyPass deal with the same type of situation? You give someone a copy of your password, your key file (that is, your long-ass password), or both, if both are required. If you want to duplicate the "Give people time to refuse the request for access" part of LastPass's feature, then retain a lawyer to hold the copies for you and -after receiving a request for them- release them after an agreed-upon period of time (or if they get a proper death certificate or whatever).
- dkarl 4y agoThis is the reason I went with LastPass, because they have a feature designed and designated for recovery after death, with support, and 1Password would require me explaining to my family how they would use the emergency kit after I died, and they would likely 1) be pissed at being asked to understand it, and 2) not even try it after I died, and suffer all the inconvenience of not having access to my accounts. It's frustrating, but the fact that 1Password's emergency kit is primarily intended and documented for me to use, and incidentally happens to enable account recovery for my heirs as well, means that they won't use it. One look at the documentation and they'll write it off as techie stuff that I was into that they won't be able to understand. With LastPass, there's stuff online specifically explaining that it's intended to provide access for family members in case of death, and I think that is reassuring enough that they'll stick with the process until they figure it out.
- roblabla 4y ago> 1) be pissed at being asked to understand it, and 2) not even try it after I died, and suffer all the inconvenience of not having access to my accounts. Your family sounds fun to be around. 1Password emergency kit is pretty well-designed, all things considered. It's a neat, single-page PDF with all the necessary information[0] (URL to login, email address/password, and the security key as text or QR Code for easy setup). I guess a link to a sort of tutorial/guide of how to use it to recover the account would be a welcome addition, but I find the format to be pretty solid. It's pretty hard to find information on lastpass version of the feature. What does it look like? According to their documentation of the "Emergency Access" feature, it claims to be a one-time access[1]? What happens after that access, do you just lose your access forever? That seems much worse than the 1password emergency kit! [0]: https://i.1password.com/media/1password-emergency-kit.png https://i.1password.com/media/1password-emergency-kit.png [1]: https://www.lastpass.com/features/emergency-access https://www.lastpass.com/features/emergency-access
- Nullabillity 4y agoThat sounds like a huge anti-feature to me. The few services that a next-of-kin should realistically need access to (banking and... that's pretty much it) will already have a process in place for handling this. The rest of my accounts should die when I do.
- SamuelAdams 4y agoYes, most services have a “death process” that typically involves the next of kin sending the death certificate and some type of document confirming they are in charge of the deceased’s estate. They might then set you up with your own login, or send you paper copies of all the info you need to an email account or mailing address.
- irrational 4y agoAll of our family pictures and videos are in a place that only I have the password to. If anyone wants anything, they come to me. That is another password I would want passed on. I also pay all the bills. My wife would need access to all of the utility accounts, the mortgage payment account, the credit card accounts, the insurance accounts, the retirement fund accounts, etc. There is way more than just banking.
- Nullabillity 4y agoBut those are things that are worth solving _now_, not just once you die.
- dgrin91 4y agoI used to think that, but then reality struck. For the financial companies, the process varied greatly by company. Some were OK, others were terrible, some flat out didn't work. The bottom line is that this isn't a super common business flow for them and its not something they make money on, so it gets very little attention. When you actually need to go through it you realize its a very difficult process. Oh and it always takes a LONG time, even with the better companies. Easily months to get everything fully done.
- rkagerer 4y agoOne option (albeit not the simplest): Shamir shares + a few trusted individuals or locations (eg. family, lawyer, safe) + "in the event of my death" instructions enclosed with your will.
- kilolima 4y agoWith KeePass, the trivial solution for this situation could just be a second subset database of relevant accounts on a thumb drive, with the password known to family individuals. That seems easier than relying on a cloud provider and some sort of half-baked insecure emergency access mode.
- SamuelAdams 4y agoFYI, thumb drives die. The longest I’ve hand one work was about 7 years, more recent thumb drives tend to only last 3-4 years. For longevity a CD / DVD might last longer, but even then those are 30 years on average.
- wazoox 4y agoI still have my first 128MB thumb drive, bought in 2001 or so. Works fine. Holds a kdbx file fine :)
- davidjfelix 4y agoI'm not really sure how this anecdote is relevant. Are you denying that flash drives fail? Are you endorsing not having a backup plan? Just to offer a counter anecdote, I had a flash drive fail with my kdbx file on it and it was a monumental pain in the ass to recover from because I didn't have backups. Have backups. Especially for critical passwords that lock you out of everything. Flash drives do fail. Statistical failures SPECIFICALLY mean that some people will not fail, but that doesn't mean failures don't happen or that they're unlikely/uncommon.
- wazoox 4y agoI have backups, thank you. My kdbx is in my Nextcloud, synchronised across my 4 PCs and Mac and my phone. So I have 6 copies (one on Nextcloud, and one on each device) at any time. Then I have backups on secondary storage (like external drives). I only have very low end flash drives (like the free ones you get at trade shows) fail on me. None of the decent ones I've bought (Kingston, generally) ever failed. I still have my various 4G, 8G, 16G, 32G drives I've bought along the years, all still work fine. The only one that failed were used continuously plugged, or to write a lot (like recording audio), and very low-end with that.
- Beaver117 4y agoExcuse me if this seems impolite, but is there a reason you need his passwords? Financial institutions have a very regulated pipeline for access of deceased accounts to relatives. And for personal email and stuff, well I think that should remain private unless the deceased explicitly wanted to share.
- justsomehnguy 4y agoWhere I live it could take months (or even years if thr heirs of a deceased doesn't agree on the terms) to have the access to the money. It would be quite illegal to knowingly use the money of a deceased person, but things happens.
- blagie 4y agoThis is a place with significant cultural differences. I can't imagine my parents wanting me to be locked out, and I can't imagine wanting my children to be locked out. Things like personal correspondence usually stop being private once someone is deceased, and indeed, are one of the few ways to get you know your ancestors. I'm not American by birth, but I've lived in America long enough to understand both values. I don't think either way is better, but this strong emphasis on privacy (with family) is a very Western phenomenon. In most places, families have far fewer internal secrets. What's especially odd is how much more Google and other corporations are allowed to know about Americans than families. For me, it's backwards.
- UncleMeat 4y agoOne of my parents neighbors died suddenly of Covid. She ran a small business as a vacation planner. Her husband did not have her email password. This was a huge pain and a source of stress when he was arranging the funeral because he was unable to inform people who expected her to be managing their upcoming vacation that she died. Sometimes timely access is valuable.
- CJefferson 4y agoHaving going through this experience, there is often lots of little things. Maybe there was a shared domain registered to your email account. Closing or moving Netflix, or Disney+, or your vegetable subscription service, is much easier if you can just log in and close the account -- this can be done by writing to the companies, or if you just stop paying and responding, but everything is just easier with email access.
- counttheforks 4y agoIt's KeePass, not KeyPass. And it's designed to be secure. If you want emergency access, tell someone your master password.
- insanitybit 4y agoWrite the password on a piece of paper. Give it to your bank and/or lawyer.
- krsdcbl 4y agoWith KeePass you'll have to manage said emergency access. Either by sharing that master pw directly or maybe if it concerns business matters by keeping those records in an own db and employ a notary to manage such emergency access. Anyway even delegating it to a notary imho isn't near as much of a possible security issue than having an SaaS store all your auths online & them having a system in place to grant third party access.
- the8472 4y agoIf one uses an offline password manager then you want the stored passwords to be approximately as secure as memorized passwords. So how do you deal with emergency family access to memorized information in the deceased person's brain? Same deal.
- 40four 4y agoFair question, but since it's not a service, I don't see how that is KeePass' responsibility. But, It's really just a simple as making sure your dependents have a copy of your master password. If I remember correctly, the native Windows version has a step to print of a sheet to share with family members when you create a new database (I could be wrong, it's been a while). Either way it would be trivial to type up a word document to print off. If you use a key file as well, it a little more complicated. Depends on if you're assuming folks have access to your machine or not. As someone else suggested, a thumb drive could be a good solution. Whatever you choose they need to have a copy of the DB file, master pass, and key file and you're good :)
- janalsncm 4y agoPrint password and detailed access instructions. Put instructions in safe deposit box. Allocate access to safe deposit box in your will. Emergency access is a human problem. Seeking a technical solution to a human problem is just asking for trouble. This is why lawyers and customer service will always be necessary.
- balaji1 4y agoWhat about just using chrome’s saved passwords and syncing? It would be great if someone can succinctly destroy that idea :D
- balaji1 4y agoMore info about browser password management in https://news.ycombinator.com/item?id=34149738 https://news.ycombinator.com/item?id=34149738
- ok_dad 4y agoThen you're stuck with Chrome forever. Same with Firefox or Safari. I wish browser vendors would agree on one password sharing protocol that's just some end-to-end encrypted blob that you could download from any browser and unlock with your password. You login to your Firefox or Google account, add passwords, and if you want to use those from the other browser you just get some http link that points to the encrypted blob and then the other browser downloads the blob and you unlock it with a password.
- eshack94 4y agoYou can export your passwords as a CSV file and import to other browsers (obviously if one chooses to do this, they should delete this file securely after it's been imported). Firefox, Chrome, and Edge also allow you to import passwords between browsers natively. I'm not saying that I recommend relying on the browser-based password manager (personally I use KeePassX), but I wouldn't advise against it for the reason you're describing. Just sharing some info! Please let me know if I'm mistaken on any of this.
- ok_dad 4y agoSure, but if I have a Macbook with Safari and a Linux workstation with Firefox and a Windows gaming PC with Chrome, then I have to use a 3rd party service, right? I don't mind that personally, I'm just an old man yelling "You should have better interoperability between similar competing software services!" at clouds (in the literal and figurative sense).
- wazoox 4y agoI've been using Dropbox, then Nextcloud to keep the database synchronized on all my devices for years and years. Absolutely no problem at all, and dead simple.
- waboremo 4y agoDoesn't this create the same problem, albeit on a different pain point? Now the service/methods you use to sync and store your DBs are a problem without much benefit? I've seen people use keepass and then google drive, which just seems silly at that point if you're going to negate keepass' benefit (local management) just to attempt to gain some of the benefits of managed services like bitwarden in very clunky ways.
- mackrevinack 4y agounlike the others where your only option is a single database, some keepass apps allows you to have multiple databases open at a time which means you can split up your sites/passwords depending on how important they are and have a different levels of security for each one. i have 1 vault with any important things and the other one just has everything else and i don't need to worry as much about the security of it or worry about where its stored and if that's secure. its also great not having to type in a long master password just to get the login details for some small forum where it really wouldnt be a huge deal if somebody got access that vault. half of passwords in that vault are there mainly because i want them to be autofilled, not because i need to keep them secure
- krsdcbl 4y agoI've actually ended up syncing my KeyPass db & sharing it with my team via our own gitlab instance. I'll have to pull changes if anybody added entries but: - Db lies on our own encrypted servers instead of someone elses cloud - access within the team is easily managed via ssh - I'll have a commit stream telling me if anybody added sth and what - can't easily fuck anything up in those shared records, have to consciously commit changes - when we rotate master pw we clean the repo
- didntreadarticl 4y agoI always struggled to find a decent Keepass implementation for my friend who uses Macs. Any recommendations?
- mdaniel 4y agoKeePassXC is excellent on macOS: https://keepassxc.org/download/#mac https://keepassxc.org/download/#mac
- perlwle 4y agoAlso a long time keepass user. The db file on my Mac is shared with iCloud and is acted as the master file. All updates happen on the mac and the rest of the clients just sync and do read only. It has been working well. All my website passwords are saved in firefox account so I rarely need to update the db file.