5 ms·
I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't
by devindotcom 13y ago
I've been meaning to switch to a password organizer rather than rely on my browser's built-in one (I know)... I've seen a few discussions on here but I haven't seen a clear victor. In your opinion, is LastPass the one I should go with? Or Keepass or OnePass or one of the others?
Edit just to say I think this is a very nice feature by LastPass and thanks for posting.
- zippergz 13y agoI use both LastPass and 1Password (in different contexts). I find 1Password more polished and nicer to use, by LastPass works fine too.
- mayneack 13y agoIn a vote for lastpass (I haven't tried the others) - they just added auto filling passwords for the android app. It works pretty well (typing their generated passwords into apps that blocked copy/paste was my biggest gripe until then). I'd say that it's pretty easy to get duplicate entries for a single site which can get annoying, but it's relatively easy to delete ones if you don't get mixed up with which is the "correct" entry first.
- cheald 13y agoI use and really like LastPass. In particular, its integration with browsers (and my smartphone) with the random password generation means that my passwords are all unique and non-rememberable (and thus unphishable, since I rely on LastPass to fill the password for me, which it only does on a domain match). Things like their security check are just icing on the cake.
- rschmitty 13y agoYou are likely not to see a clear victor in this thread either. People who use/like LastPass will say so, and those who use others will throw in the vote there. You can also google 'Option 1 vs Option 2' and get a bunch of results. Best you try them yourself and see which one you like! I use LastPass Premium
- swlkr 13y agoI use pass http://www.zx2c4.com/projects/password-store/ http://www.zx2c4.com/projects/password-store/ You could store your passwords in a git repo to get a sort cross-platform thing going on.
- ClashTheBunny 13y agoThis is what I'm going with. Something simple enough that I can understand what's going on and get to my passwords and create new passwords without the program. It works on EVERY platform because gpg is available for EVERY platform and it's just a bunch of files in a hierarchy, so however your sync files, you sync these. It has as strong a master encryption as your gpg key and git is a great way of versioning your passwords: "wait, I used to have the same password for gmail and yahoo mail, but then I stopped using yahoo mail and changed my gmail password to something really secure, but now I need to get into yahoo for some reason (yes, literati, I still love you). git log --grep accounts.google.com".
- frewsxcv 13y agoUsed to use LastPass, but I've disliked some of their recent decisions. Their Android app is getting bulkier by the update; it includes a full blown web browser inside the app. Their Firefox extension seems to be no longer maintained as well. I switched to KeePass + Dropbox and have been enjoying it. If you use OSX, I strongly recommend http://mstarke.github.io/MacPass/ http://mstarke.github.io/MacPass/
- pwman 13y agoWe've always had a full blown web browser in the app -- it's been the only viable way to fill passwords in for years. Literally the first option we added. We also have an extension into Dolphin, and you can utilize Chrome utilizing our fill method -- if you don't like them there are options to disable them too reducing the perceived extra bulk.
- frewsxcv 13y ago"it's been the only viable way to fill passwords in for years" Call me old fashioned, but I'd rather copy/paste than rely on the web browser within the app. The lack of attention for the desktop Firefox extension is what drove me to alternatives. After switching away, I realized I was paying for a payed proprietary system with no real benefits from an open source solution.
- pwman 13y agoRegarding firefox -- Are you speaking of the fact that Mozilla refused our Firefox updates for over a year? We're happy you found a tool that works for you -- that's what we want everyone to do -- it doesn't need to be LastPass but people need to use something -- reusing passwords constantly is just painful.
- frewsxcv 13y agoOut of curiosity, what were their reasons for refusing the updates? I have my own gripes with the AMO team, but I've never had an extension update refused
- ryeon 13y agoI use Dashlane and its been great! Surprised not seeing too much support for it around here...
- zeroexzeroone 13y agoI use Dashlane as well, have for about 2 years now, I love the app as an extension in firefox and the mobile app with secure notes.
- dfc 13y agoJust taking a guess but the lack of Linux support might be the culprit.
- keypusher 13y agoI use LastPass and definitely recommend it. It will generate a random password for you based on definable criteria, which I like and use almost everywhere. The primary vector of mass attacks these days seems to be one compromised database leaks out, and then they use those cracked passwords to get into other sites where you used the same email/pass combination. Keeping track of hundreds of unique and secure passwords without a manager is untenable.
- plg 13y agoOK I'll bite ... why should I not use my browser's built in pw manager? (e.g. Safari on OS X Mavericks) I can see an argument about cross-platform use but is there another reason or reasons? thanks,
- philwebster 13y agoThere are some sites that try to disable the ability to save passwords and 3rd party password managers usually override this. Another thing that's really nice is having the LastPass extension on Firefox, Chrome, and Safari on the same computer and not having to worry about if they are using the system keychain or not. In my experience, form filling with credit card information has been less error prone with LastPass as well. I thought at one point Safari was requiring the CVV number to be manually entered too. I could be mistaken.
- kijin 13y agoI don't know about Safari, but the built-in password manager in most browsers are very light on features and have abysmal security. AFAIK Chrome still refuses to let you set a master password to protect your other passwords. Firefox is better, but the user interface is bare bones compared to a dedicated password manager. I suspect that the password manager in most browsers have received less attention than it deserves, partly because all the vendors been trying very hard to get people to drop passwords altogether. Mozilla pushed Persona, Google pushed Google accounts, Microsoft pushed Microsoft accounts. I wonder if Mozilla will start paying attention to the password manager now that it has given up on Persona. LastPass et al. have a lot of additional features that make a lot of sense once you accept that you'll be stuck with dozens of passwords for the foreseeable future. For example, LastPass offers to generate a random password for each site, recognizes when you change your password, helps you organize websites into categories, and alerts you to weak passwords.
- deleted 13y ago[deleted]
- kingnight 13y agoThe OS X Keychain, which is used by Safari, can be cracked via John The Ripper.
- 27182818284 13y agoMy biggest problem with LastPass, and this is a small problem, is that it fucks up on a fair amount of input fields. So for example, it still works, but its icon is too huge for site example.com so it is awkaward or it thinks it is a username and password form but it is actually a signup form with username password1 password2. I'd still recommend it, despite those problems.
- platz 13y agoNot a huge problem since you always have access to your credentials in about two clicks from the right-mouse context menu.
- Spittie 13y agoWith a question like this, you're probably going to get a lot of biased options. Not because people want you to use an inferior product, but because obviously one think that what he uses it the best. For example, as a current KeePass user, I'd suggest it. Lastpass overall is comfy, you do everything within your browser, it sync without much problems and you can use it on the go with the official applications and addons. One downside is that everything is closed source. The other one is that I find their addon is trying to do too much, and it's not polished enough (at least, their Firefox one). I've had tons of annoyances with it. Keepass instead is awesome because it's opensource and you own your data. But you can feel that not everything is nicely integrated. I use a Firefox addon (PassIFox) for filling username/password, and it works pretty nicely, but you have to set it up (and it's kinda a pain to get it working on Linux). I use an application on Android (Keepass2Android) which has a different UX, and doesn't have the fancy input method that the lastpass app has (instead you just copy/paste, and there is a keyboard for autofilling but I find it mostly annoying). The integrated sync support only ftp/webdav, and not everyone has a server providing those around (and I never got webdav to work anyway). Sure, you can sync the file with dropbox or other "cloud" solutions, but this implies even more software in your chain. I never got to try OnePass sadly, as there's no Linux version. Anyway, I'd say: Try both, and see which one you prefer. Keepass is libre, and lastpass has a free tier, so you don't have to put any money in it. Just use them for a bunch of sites for a bunch of days, and then decide.
- gnud 13y agoA tangent: Have you tried KeeFox, as opposed to PassIFox?
- Spittie 13y agoI have. KeeFox is good, and it's more akin to LastPass (feature-wise). I went with PassIFox because all I want is a simple "fill username & password" in the right-click menu, I'm fine with managing my passwords directly within KeePass.
- blueskin_ 13y ago>The integrated sync support only ftp/webdav There are KeePass addons for (from memory) SCP, SFTP, and FTPS (does anyone still really use FTP?), as well as others.
- davexunit 13y agoIt's a bad idea to trust your secrets with a proprietary web service. Free software is a prerequisite for digital security. Best to use a free software password manager that you can run on your own computer.
- keypusher 13y agoAnd what do I do when I have 3 or 4 devices? Home desktop, work desktop, laptop, tablet, etc?
- sliverstorm 13y agoCouple options 1) Dropbox 2) USB stick
- kcorbitt 13y agoI keep my KeePass database synced between devices using a Dropbox-like service that I self-host, so the file is never out of my control. But even if someone grabs the database off my machine or in transit, it's no good if they don't know my master password.
- tokenizerrr 13y agoKeePass ftp sync, or what sliverstorm said
- _jwo_ 13y agoI've been using http://www.zx2c4.com/projects/password-store/ http://www.zx2c4.com/projects/password-store/ which handles that by integrating with Git, encrypted passwords are stored in a Git repo and all changes are recorded as Git commits. It's no more difficult than using a centralized third-party service, provided you have somewhere to host a Git server for it.
- blueskin_ 13y agoKeePass has a basic builtin sync, with addons for more/better protocols, or if you primarily use one device with others as more readonly, you can just copy the file yourself.
- fletchowns 13y agoAnother one to consider using is the no-frills option of Password Safe. It's designed by the man himself, Bruce Schneier. http://passwordsafe.sourceforge.net/ http://passwordsafe.sourceforge.net/
- MichaelGG 13y agoI recently went over this and went with KeePass. It's open source, although apparently not with a public repo (just source zips). I'm in the process of verifying it and building it for myself. I used to use PasswordSafe, but I think I have a higher chance of missing a backdoor in C than in C#. (I removed all the native stuff from my copy of KeePass.) For critical stuff, I want to minimize the amount of proprietary stuff. I already have Windows (as a VM host), Lenovo and VMware to trust - but at least that's not directly connected to the Internet[1]. Why add a third party that could suffer a remote compromise or worse? 1: Host runs VMs, has no protocols bound to NIC but passes it through to a gateway VM which acts as a router for the other VMs. KeePass can run on the host, so a VM compromise is somewhat limited.
- MaKleSoft 13y agoIf you're looking for an open source alternative that is easy to use and not as clunky as KeePass, 1Password or LastPass, you should take a look at Padlock: http://padlock.io/ http://padlock.io/ It's still in alpha but will be released on all major platforms once its ready. Disclaimer: I'm the developer
- enoch_r 13y agoLots of recommendations already, but I'll throw in a vote for Pass[0]. It's simple, cross-platform, and doesn't require trust in any service--although you do need to trust yourself not to lose your gnupg private key. [0] http://www.zx2c4.com/projects/password-store/ http://www.zx2c4.com/projects/password-store/
- _jwo_ 13y agoI've been using this too, highly recommended. Very simple and usable command-line interface, integrates with Git to share all encrypted passwords across machines.
- slowmotiony 13y agoI use LastPass for years now and I definitely recommend it. I tried to set up KeePass and god what a nightmare that was. You need a PhD in setting up the thing before you can use it comfortably.
- blueskin_ 13y agoKeePass if you don't trust third parties and security is top priority, so you want an open source product that isn't web-based. (Disclosure: I use KeePass personally). LastPass if sync/mobility is most important and you're fine trusting a (US?) company.