4 ms·
Can anyone recommend some “offline only” password generation tools? I don’t see why passwords need be stored on a server at all. Something with mobile support
by ostenning 4y ago
Can anyone recommend some “offline only” password generation tools? I don’t see why passwords need be stored on a server at all.
Something with mobile support would be ideal
- viraptor 4y agoIf you have more then one device, how are you going to generate the same password for the same site that's different from other people, but same for you? (There are some existing ideas, but they often rely on the domain/url staying the same and that's often not the case in practice)
- deleted 4y ago[deleted]
- bramblerose 4y agoKeepass. You can still have sync between computers/phones using Dropbox while not having any unencrypted data in the cloud.
- wereallterrrist 4y agosyncthing (or private git repo on trusted server) + pass/gopass/prs (with gpg key on Yubikey or similar hardware CCID/OpenPGP hardware) It's not for everyone, but it's trivial to conceptualize ALL of it - you decrypt/encrypt plain text files in a dir, and something else syncs them. Your "manager" then becomes a tool with a nice CLI that just does `gpg -e`/`gpg -d` under the covers. (I'd really like to see a tool that can take a publicly-shareable config file (email, name, country, origin date, keysize, seed) + a secret BIP39 phrase and spit out a GPG secret key, or better, just provision a new Yubikey from the phrase. Then my cold storage could just be my BIP39 phrase, rather than being my BIP39 phrase and an encrypted copy of my GPG key backup.)
- SahAssar 4y agopass/gopass/passage and KeePassXC can be offline-only, but usually you use some sort of tool to sync/backup the password store. I use gopass with keys stored on yubikeys, which I think is secure enough. For syncing I use git, but since decoding the synced archive requires a key that is impossible to extract from my hardware keys I'm not that worried about leaks from the syncing.
- nix23 4y ago+1 for pass and KeepassXC
- torstenvl 4y agoIn my opinion, Enpass has the best balance of privacy, open-source, offline-first, etc. It's essentially a proprietary UI over a sqlite/SQLCipher database (fully open source CLI available: https://github.com/hazcod/enpass-cli https://github.com/hazcod/enpass-cli). It can - but needn't - be sync'd any number of ways (iCloud, Dropbox, Google Drive, OneDrive, WebDAV), if that's what you like. Because it has WebDAV sync support, you can use it with ownCloud or NextCloud without much fuss, and not have to trust a third party at all.
- selfmodruntime 4y agoI second Enpass. There is no online server involved. Syncing can be done with proprietary cloud solutions, Wi-Fi, or just manually using files. But what I love best is their payment plans: the have the rare option for lifetime plans.
- chlorion 4y agoOn my desktop I have a python script that selects N random words from the list I obtained from the eff website (link below). Something to note is that the regular "random" standard library module in python is not intended for password generation or cryptographic purposes. Modern python has a module called "secrets" that provides secure random functions using randomness from the OS's CSPRNG. If I need something like a binary key I just use /dev/urandom directly. You can pipe urandom through something like "tr" to remove non-printable bytes, or remove everything that's not in a set that you provide such as "a-zA-Z0-9!@#$%^&*()". On Android I use the "pass" app, but I generate the passwords on my desktop and then share them with the phone after encrypting them with the phone's GPG key. (wordlists) https://www.eff.org/dice https://www.eff.org/dice