3 ms·
Ask HN: Recommend a secure password manager
This week alone we've been discussing:
* KeePass – questionable security
https://news.ycombinator.com/item?id=9727297
* LastPass Security Notice
https://news.ycombinator.com/item?id=9721212
I currently use KeePassX which is synced on my Dropbox and also have a key file on my USB.
From your experience, which password manager is the good choice? And what syncing, additional security layers (like key files, YubiKey...) could be used to gain maximum protection of the sensitive information?
- otar 11y agoLinks to related threads: * KeePass – questionable security https://news.ycombinator.com/item?id=9727297 https://news.ycombinator.com/item?id=9727297 * LastPass Security Notice https://news.ycombinator.com/item?id=9721212 https://news.ycombinator.com/item?id=9721212
- sarciszewski 11y agoThe first one is KeePass2. KeePassX is still good. https://github.com/keepassx/keepassx https://github.com/keepassx/keepassx
- detaro 11y agohttps://news.ycombinator.com/item?id=9727592 https://news.ycombinator.com/item?id=9727592 ?
- stephenr 11y agoWhat are your platform (OS/device) use requirements?
- NeutronBoy 11y ago> From your experience, which password manager is the good choice? And what syncing, additional security layers (like key files, YubiKey...) could be used to gain maximum protection of the sensitive information? Every time someone asks 'which one has the best security', the first question you need to ask is - what's your threat model? Because that will impact what your requirements are. Personally, my threat model includes people physically getting hold of my laptop or phone, people using my computer when I'm not around, keylogging/malware, or websites having their passwords breached. It doesn't include the NSA, nation-state adversaries, spear-phishing attacks. This impacts which software I use, how I've set it up, and my use cases.
- Blackthorn 11y agoI don't really see anything wrong with Lastpass. The secrecy of your vault (the encrypted passwords) depends on the strength of your master password. If you have a strong master password, the fact that someone managed to make off with some hashes should not bother you. To use a horrible simile, it's like when you have a bank vault filled with a lot of valuable stuff and three doors. Someone tried to rob it, put a dent in the first door, but couldn't get through them. Some people are flipping out that the door got banged on, but I don't really understand that because the door is still doing exactly what it was designed to do. Maybe there's something I'm missing here, but I don't really see the trouble right now.
- J_Darnley 11y agoPassword Safe? http://pwsafe.org/ http://pwsafe.org/ Originally designed by Bruce Schneier: https://www.schneier.com/passsafe.html https://www.schneier.com/passsafe.html I have found it to be good enough for me but then I only use it on one Windows desktop with occasional syncing to a laptop.