7 ms·
As a Proton Unlimited subscriber & general supporter of the company: I don't care who it is hosting it, I don't want my password manager connected to the inter
by devnullbrain 3y ago
As a Proton Unlimited subscriber & general supporter of the company:
I don't care who it is hosting it, I don't want my password manager connected to the internet. There is cognitive dissonance when this community that distrusts IoT, call-home LLMs, URL bars that send data to Google and 5G-connected vehicles is willing to connect their most critical private data to a single, profit-seeking source-of-failure.
The password generation and encryption is an easy, solved problem that you can get for free! For any of these services, you're only paying for the UI, backup and internet connectivity. Companies have failed at this before and will fail again.
- Mindwipe 3y agoYep. If they had built a fully local solution then that would be interesting. If I'm not hosting it then it isn't.
- webstrand 3y agoHow do you sync your password manager between computers, out of curiosity? Most people put that file online somewhere they can copy it to other computers. Or is the ad-hoc nature of this usage a defense? I use KeepassXC though, I'm still not terribly confident that I haven't lost data from forgetting to merge another modified database before overwriting it.
- orev 3y agoCodeBook allows peer to peer syncing over your local WiFi network. It’s a great password manager and works on desktop and mobile.
- malermeister 3y agoI feel like I can't trust a password manager that's not open source.
- orev 3y agoThey make and use SQLCipher, an OSS extension to SQLite. The whole thing isn’t OSS, but it’s also not completely proprietary either.
- fodmap 3y agoI use Syncthing to sync KeepassXC db. It works flawlessly.
- toastercat 3y agoI've thought about doing this as well, but I really like the password manager integration in Firefox. How does the Keepass Browser Extension work? Is it as seamless and do you need to have Keepass running in the background at all times?
- fossislife 3y agoI have the same setup, Syncthing + KeepassXC with the add-on: it's not quite as seemless as the Firefox password manager. You have to pair the add-on with the KeepassXC program once. Whenever you visit websites that you have saved passwords for, you are asked (via popup) if you want the add-on to fetch the login name and password (because it can handle multiple login combinations for the same websites). Then you have a second click on a small symbol next to the login form which then actually fills in your login data.
- fooqux 3y agoI personally use pass which out of the box uses git, meaning it's trivial to sync to as many devices as I want. And obviously merging is a solved issue there.
- andrewla 3y agoI can't answer for OP, but for me, I just don't. I prefer an entirely offline password manager, and that's the way I use mine (I use enpass). Except for backing up to the cloud, it does not really use the network. When I need a password, on my computer or on my phone, I look it up and transcribe it (I'm reluctant even to allow it to hook into the password autocomplete in IOS; I prefer to copy/paste because I don't really want any leak in the knowledge of where my passwords are stored). I would actually prefer an even less feature-rich password manager. I've thought of trying to fork something like KeePass for my purposes (or use a restricted subset) but I haven't been willing to devote the time and effort necessary.
- UberFly 3y agoThis is also what I do. 99% of the passwords in Keepass on my PC I don't need when out and about. The 10 that I do need I just keep updated in a vault on my phone. I don't like the feeling of my 'keys to everything' being hosted somewhere.
- lcnPylGDnU4H9OF 3y ago> is the ad-hoc nature of this usage a defense? In a way, actually. If I use a self-hosted service for hosting the file and keep it open only to myself, then someone who wants that file is targeting me specifically. That's not something I'm particularly worried about. (Obviously someone worrying about that might reconsider this as a line of defense.)
- ementally 3y agohttps://old.reddit.com/r/ProtonPass/comments/12su1vq/proton_pass_a_fully_encrypted_password_manager_is/jh0iky2/ https://old.reddit.com/r/ProtonPass/comments/12su1vq/proton_... They claim that using it as cloud service prevents brute force.
- devnullbrain 3y agoI would consider a targeted attack to be less of a risk than a systemic attack on a password manager provider. Local invasive vs. remote non-invasive.