6 ms·
1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least. I have all
by vhost- 12y ago
1Password and last pass are pretty awesome. Some people don't want to use a 3rd party and for those, I suggest KeePass databases at the very least.
I have all my two-factor reset keys in KeePassX at home and all normal passwords in last pass.
I actually lost a two factor code for Linode when I lost my phone with the Google authenticator app on it and having those reset codes in KeePassX was a life saver.
- flinkblink 12y agoAgreed. Keepass + A fileshare service to sync your database to all devices is heavenly.
- kyrra 12y agoI've seen this argument come up before and I don't understand it. Why do you trust KeePass more than 1Password? In both cases you are sharing the datafile however you'd like (Dropbox, thumbdrive, etc...). The primary difference is if you have access to the source code or not. If KeePass purposefully injected a vulnerability, it would just be that dev/project that would fail. If 1Password were to do the same, that company and all the people that work for it would go down. I'd personally see this as more of a reason to trust 1Password over KeePass. The primary argument is that the code is open and you can audit it, but in reality that doesn't really happen unless there is a real drive to do it (like we saw recently with TrueCrypt). I trust/distrust both about the same amount. But 1Password has more resources behind it so they are doing more to try and secure the data within the encrypted store.
- r00fus 12y agoWell, Keepass is free as in beer too, so from a licensing perspective, that's a factor (mainly for adoption) though, 1Password is a totally affordable and solid investment for 99%+ of folks on this board). Free allows much more organic adoption - I can recommend a friend to use KeePass without worrying a bit that he doesn't think 1Password is a good investment. I can mandate it for my team at work without having to get it expensed.
- eridius 12y agoFree as in beer is a reason to be more distrustful of the software. Sure it's more convenient, but this seems to be an area where it's really worth investing money in getting the more reliable solution.
- jimlei 12y agoWhy do you assume paid software is more reliable?
- eridius 12y agoSee this other comment I just posted: https://news.ycombinator.com/item?id=8264450 https://news.ycombinator.com/item?id=8264450
- pyre 12y agoAre you by chance a purchasing manager for a large corporation? Do you feel that signing a $100K-$1M Oracle contract is worth it because "if MySQL or PostgreSQL were worth something, then they would charge you for it?"
- eridius 12y agoThanks for the straw man and entirely manufactured quote. We're talking about paying $50 for software that manages your passwords for everything, not paying hundreds of thousands to millions of dollars.
- pyre 12y ago> Free as in beer is a reason to be more distrustful of the software. > this seems to be an area where it's really worth investing money in getting the more reliable solution. You're stating that "Free as in Beer" == "Less Reliable" and the fact that something costs money implies with 100% accuracy that it is reliable. Neither of these are true. Arguing that I'm bringing up a strawman because I said "Free vs. Millions of Dollars" instead of "Free vs. $50" is beside the point.
- vhost- 12y agoI was just offering it as a suggestion. Some people like to keep things on their own computers (or servers) and keepass offers that. I use Lastpass, which is hosted and I trust them with my passwords. I simply use keepassx to store two factor reset codes. I do this because if I store my reset codes in the same system as my passwords, then it's not very two-factor anymore, is it?
- kyrra 12y agoI completely understand. When people ask me which they should use, I outline the pros/cons of Keepass, LastPass, and 1Password. If you want password management for free, KeePass rocks. If you want to pay, it's definitely a tossup between LastPass and 1Password. I think they are all awesome tools.
- teach 12y agoThis is an aside, but your comment reminded me to check why I've never even considered using 1Password and happily pay for LastPass. A brief visit to their website later and I remembered: 1Password doesn't have Linux support. It's a shame; it looks really nice and I don't mind paying for good software.
- MichaelDickens 12y agoMy concern is that 1Password could shut down at any time and stop being supported, and I may lose access to all my passwords. KeePass is open source, so even if the current maintainer quits, it's likely that others in the community will step up to continue maintaining it. If absolutely necessary, I can edit the source code myself.
- Accelerata 12y agoThat's not how 1Password works. All passwords for 1Password are stored locally in an AES encrypted file. They never see, touch, or have any control over your passwords on their end. Even if they suddenly shut down tomorrow, all your passwords would still be accessible unless you chose to delete the application and have zero backups to restore from. They even have an export function to dump the passwords (unencrypted) into a plain text or CSV file, so you can easily migrate the data to a new manager if needed.
- Dobbs 12y agoYou are 100% correct. To add to this all syncing on 1Password is done using 3rd party vendors. You can use dropbox, iCloud, Google Drive, etc to do the actual syncing of the encrypted files.
- mikepurvis 12y agoI use Dropbox, but my password for Dropbox itself is stored inside 1Password. The escape hatch is that the 1Password sync folder is shared publicly, and the URL is copied to a slip of paper in my wallet.
- newman314 12y agoWhy would you ever expose the sync folder publicly? Just keep a copy on a local computer with Dropbox if need be.
- 12y ago
- oinksoft 12y agoWhy do you assume every KeePass user is storing their passwords on a server somewhere? I would never send my password file over a network, and I don't consider USB storage "sharing."
- deciplex 12y agoThe password file itself is an encrypted DB. Unless you choose a weak password for that, it's pretty secure.
- oinksoft 12y agoThe more tightly you control copies of your password DB file, the less vulnerable you are if somebody "purposefully injected a vulnerability" in the software as parent suggests, that's the only reason I brought it up.
- BallinBige 12y agoare there any known vulnerabilities for 1Password?
- BallinBige 12y agoare there any known vulnerabilities for 1Password?