5 ms·
Password managers are those proprietary programs that you need to install, give full access to your computer, register an account and trust their word that your
by codedokode 1y ago
Password managers are those proprietary programs that you need to install, give full access to your computer, register an account and trust their word that your passwords are uploaded to the cloud securely? No thanks.
Also they are too complicated for an ordinary user. A physical key is much simpler and doesn't require any setup or thinking, and can be used on multiple devices without any configuration. And doesn't require a cloud account.
- blkhawk 1y agouh no - a password manager is an open source application you can compile and install yourself if you want. Its nothing more than a small specialised database with a excel like interface. Personally I think that the argument that things are "too complicated for the average user" eventually gets gets you users that find breathing and sphincter function too complicated.
- Hackbraten 1y agoI’ve been observing this space for two decades and haven’t come across a single open-source password manager that actually works, is properly maintained, has an acceptable security track record, and comes with a similarly well-maintained browser extension that protects both my clipboard and myself from phishing.
- rpdillon 1y agoI've been using Keepass for two decades and have never had a single issue. I would never recommend a browser plug in (too much attack surface area), and instead simply check the URL before having KeePass autotype. No clipboard. I think you're rejecting good solutions out of hand. Meanwhile...millions of users trusted LastPass. Twice.
- Hackbraten 1y ago> simply check the URL before having KeePass autotype. I’m not going to rely on myself never making a mistake. I want a solution that protects me even during stressful moments where I have a lapse of judgement and forget to check.
- simoncion 1y agoIf you're not using KeepassXC's browser plugin (or are using KeePassX, which -IIRC- never had a browser plugin), then its autotype feature will check the title of the window that has keyboard focus when deciding which entry to use. If one or more matches are found, it will [1] also ask you to confirm which entry you're about to have the software punch in. If no matches are found, it will alert you to that fact. You might find the KeePassXC docs about the feature [0] to be informative. If you're going to complain that all a phisher has to do to capture a password is create a website with the same title as the official one, then my reply would be something like "Duh. That's what the browser plugin is for.". [0] <https://keepassxc.org/docs/KeePassXC_UserGuide#_auto_type https://keepassxc.org/docs/KeePassXC_UserGuide#_auto_type> [1] ...optionally, and on by default...
- Hackbraten 1y agoNot sure how you got the impression that I was unwilling to use a browser plugin. I’m absolutely looking for a browser plugin. I would refuse to use an auto-type feature that only checks the window title instead of, as a browser plugin would do, the site’s domain.
- simoncion 1y agoI'm not sure how you got the impression that I had the impression that you're unwilling to use a browser plugin. I have absolutely no idea whether or not you're willing to use a browser plugin. I was mentioning how auto-type worked because it's useful information for those who either are unwilling to use a browser plugin, or are like myself and simply have no need for one.
- rpdillon 1y ago
- simoncion 1y agorpdililon mentioned KeePass. What have you (that is, Hackbraten) found wrong with the KeePassXC offshoot of it? /me wonders if this is a "recommend me a nice open source, offline password manager" question in disguise.
- Hackbraten 1y agoI don’t remember why KeePassXC didn’t make my list last time I checked. That was years ago, so I’m going to check it out again. Thanks for the pointer. Update: One thing that stands out immediately is a confusing mess of three different projects, two of them unmaintained, which all call themselves KeePassX or KeePassXC, sometimes linking to each other’s documentation. How do I even tell I’m facing the correct KeePass(X(C)?)? project? Yes, I’ll figure it out eventually but until then, it’s confusing. Also, if a password manager project needs to be forked over and over and over again (how can a holder of the keys to the kingdom possibly go MIA on three different occasions in basically the same project?), then does that tell us something about how the project is governed?
- simoncion 1y ago> How do I even tell I’m facing the correct KeePass(X(C)?)? project? Well, [0] lists a single project called KeePassXC, with [1] as its homepage. Search engines list [1] and [2] as the top results for the query KeePassXC, for whatever that's worth. [3] > Also, if a password manager project needs to be forked over and over and over again ... then does that tell us something about how the project is governed? No? KeePass is Windows-only software. So, some folks decided to write KeePassX, which ran on Linux, OSX, and Windows. They got bored of that after a decade or so, called it quits, and one of the preexisting forks [4] became the widely-used one. > how can a holder of the keys to the kingdom possibly go MIA on three different occasions in basically the same project? In addition to the history I wrote above, you are aware that KeePass is still receiving stable releases? According to [5], it looks like 2.59 was released just last month. EDIT: Actually, where are you getting this "confusing mess of three different projects" from? When I search for "keepass", I get the official home pages for KeePass and KeePassXC as the top two results, the Wikipedia page, and then the Keepass project's SourceForge downloads page. When I search for "keepassx", I get the official homepages for KeePassX and KeePassXC, the wikipedia page, the KeePassXC Github repo, and an unofficial SourceForge project page for KeePassX. [0] <https://keepass.info/download.html https://keepass.info/download.html> [1] <https://keepassxc.org/ https://keepassxc.org/> [2] <https://github.com/keepassxreboot/keepassxc/releases https://github.com/keepassxreboot/keepassxc/releases> [3] And -because I'm a Linux user- not only do I have KeePassXC in my package manager, I also know that [1] is listed as its project homepage. [4] ...which started like four years before KeePassX's final stable release... [5] <https://sourceforge.net/projects/keepass/files/KeePass%202.x/ https://sourceforge.net/projects/keepass/files/KeePass%202.x...>
- odo1242 1y agoWhat about Bitwarden?
- mangodrunk 1y agoIt’s annoying how people are gaslighting you into thinking this is a solved problem. As if password managers don’t have issues themselves and even if they did solve that aspect, it’s only a part of the whole problem.
- const_cast 1y agoPassword managers are both significantly simpler to use than just passwords and more secure. Passwords have always been bad. The problem is that users can't remember them. So they rotate, like, 3 passwords. Which means if fuckyou.com is breached then your bank account will be drained. Great. On top of that, the three passwords they choose are usually super easy to guess or brute force. With a password manager, users only need to remember one password, which means they can make said password not stupid. You can automatically log in too with your new super secure passwords you never need to see. Its the perfect piece of software. Faster, easier, more secure, with less mental load.
- mangodrunk 1y agoAnd if the password manager is compromised, then again everything is lost. I doubt people are indeed using good passwords for it, and does this assume you only use one device that you will always use?
- const_cast 1y ago> I doubt people are indeed using good passwords for it I don't, but even if I do, the simple fact remains that remembering one password is easier than 300. If you have to remember 300 passwords, youre gonna choose 'password1' - 'password300'. Because we're not living hashmaps. But with one password, I can easily make it even 40 characters and remember it. And anybody can do that. If you DON'T use a password manager, you don't solve the problem of "everything is lost". Because people just reuse passwords as noted above. So Experian gets breached, which is WAYYYYY more likely than your encrypted password manager getting breached, and now your bank is also open, and your Gmail, and your IRS.gov. whoops. > does this assume you only use one device that you will always use No, password managers work on all your devices and auto sync. How is it done so securely and without any hiccups? Because they're super simple pieces of software. You just take the passwords, derive a key from the master password, and encrypt all the passwords. Then dump it in whatever online storage. I could write a password manager in a couple hours.
- nobody9999 1y ago>Password managers are those proprietary programs that you need to install, give full access to your computer, register an account and trust their word that your passwords are uploaded to the cloud securely? No thanks. cf. pass(1)[0][1] [0] https://www.passwordstore.org/ https://www.passwordstore.org/ [1] No, it's not hosted in the cloud (i.e., on someone else's servers) and that's a good thing. It's FOSS and can be compiled for Android/IOS (and has, see [2][3][4], least for Android). The DB (just a GPG store) can also be shared across multiple devices. [2] https://f-droid.org/packages/app.passwordstore.agrahn/ https://f-droid.org/packages/app.passwordstore.agrahn/ [3] https://play.google.com/store/apps/details?id=dev.msfjarvis.aps&hl=en-US https://play.google.com/store/apps/details?id=dev.msfjarvis.... [4] Not sure about IOS versions, I don't have any Apple devices.