3 ms·
Hm, I've been using KeyPass/Dropbox for quite a while now. Not sure what advantages this method has over mine? Yes, I have to remember my KeyPass master passwor
by Random_Person 13y ago
Hm, I've been using KeyPass/Dropbox for quite a while now. Not sure what advantages this method has over mine? Yes, I have to remember my KeyPass master password... but then you'd have to be logged into one of my machines to get access to it anyway... or on my mobile, which everyone seems to be using for 2 factor anyways, so it's moot if my mobile is compromised.
Not sure what the advantage is.
- mey 13y agoThis is the solution I currently use. I have found KeyPass problematic on OSX but since that isn't one of my primary computing environments it works well. I am putting a lot of faith in the security of KeyPass, as I don't put a lot of faith in DropBox to keep the file secret. If DropBox's sync system wasn't so simple/unobtrusive I'd use something else. Then as a last step measure, there are backups of the keepass file in case a machine or dropbox have issues.
- patrickk 13y ago> If DropBox's sync system wasn't so simple/unobtrusive I'd use something else. Perhaps consider using Bittorrent Sync[1] for synchronisation. For practical purposes, it's similar to using DropBox, the key difference being that instead of syncing with DropBox in the cloud, you are syncing folders across hardware you control. The hardware could be different computers, phones, tablets etc. [1] http://labs.bittorrent.com/experiments/sync.html http://labs.bittorrent.com/experiments/sync.html
- digikata 13y agoI use KeyPassX on OSX & Linux with no problems. There's several iPhone compatible apps that will push/pull the Keepassx datafile from dropbox too.
- GlennS 13y agoI use the KeePass/Dropbox combo also at the moment, but I have some concerns about it and may switch away. Dropbox keeps historical versions of your files. My concern is that, if an adversary can get multiple versions of my Keepass file which they know are a sequence with small changes between them, then they are much more likely to be able to devise an attack. I haven't looked into this any deeper yet.
- seniorsassycat 13y agoHis setup is basically the same as yours, doubly if you use keepass with a key file. His short password is a knowledge credential, and a yubikey is an ownership credential. I've been working on my net security as well and I've had a hard time compromising security vs convenience and fault tolerance. My situation is made a little more complicated because I don't have a smartphone which rules out mobile based key vaults. I want a minimal set of dependencies to access necessary accounts, like my gmail. No file I can lose, or password I might forget. I've decided to rely on an ok password and google's two factor auth. Less important accounts are stored in keepass protected by a key file and password, but I'm worried about losing the key or vault file.
- jmcphers 13y agoThis is what I use. As an extra safeguard for KeePass, I use a key file in addition to the password. The key file I also keep in cloud storage (in case any of my machines die in a fire), but on a different cloud storage provider. That way I can always reconstruct my password environment, but it would require compromising two cloud stores and keylogging my password to open the safe. (Or access to one of my local machines and a keylogger, but in that case I'd be hosed anyway.)