KeePassXC here. Locally encrypted, Locally stored, cloud backup of an encrypted file, synced with SyncThing to mobile devices. I will never trust nor recommend a cloud based manager with all the breaches.
Yeah, KeePassXC + SyncThing all day every day. Can’t in good conscience trust someone else with my sensitive data, even if I encrypt it before it gets to their servers. My database is keys-to-the-kingdom level shit.
This is the way.
Oh yeah, someone, finally :D KeepassXC on PC, KeepassDX on Android, Syncthing for synchronization. I like when my password is just one file, that I can easily backup, not some cloud thing 🙂
This is the way.
Everyone should be using a password manager. Every service should have a different password (and some service should have several passwords) and it’s impossible for the average person to keep track of all of those. Every time I hear about someone losing control of an account it’s because they were using the same password as another service.
I recommend:
- KeePassDX: Can be completely offline. Probably the most secure but can be a little awkward to use sometimes.
- Bitwarden: Cloud based but open source. You could run a server but the main service offers MOST of the features for free.
Your mileage may very with some of the proprietary platforms. However my job uses 1 Password and it seems to be fairly safe.
Yes, do it! Now! It’s the safest way, but only by choosing the right and trusted ones. Examples:
- The expensive but good one: 1Password
- The free, geeky and difficult one for normal users: Keepass.
- The simple and free and beloved one: Bitwarden
- The don’t try it ever because they will leak your data: Lastpass.
Bitwarden, all the way.
I use keepass synced with internxt. Works so so , but internxt will hopefully improve
Check out Syncthing. It works pretty painlessly.
Thanks completely forgot about it , used it a few years back and had some issues. Seems to work great now :)
Bitwarden is really great imo.
Selfhosting it is even better
deleted by creator
I use 1Password atm, but want to switch either to Proton or something selfhosted.
What are my thoughts on a password manager?
I think it’s both a good thing, and a crutch. I feel the fact that most services are rendered unusable without an account is sad, and with the 100’s of accounts one is expected to have a password manager is sadly needed if you can’t memorize a password or can make passwords with a consistent pass phrase.
Do I use one?
Nope, I have a password system which is good enough for most accounts that’s always more than 7 character long and unique for each account without being lost to me. The only time it has failed as when my work decided to have us change our passwords every quarter, and I ran out of password ideas.
In general, password managers are a must-have in today’s world. The question is not if you should have one, but which one and why.
As a Software Engineer very conscious about security and privacy, but also with a high practicality sense, I’d say you should opt for whatever you feel more comfortable.
If you don’t want to manage anything, then 1password, BitWarden, LastPass or any of those might be right for you. If you are more of the kind to tinker with everything, then you can have your own OwnCloud/NextCloud and use KeePassXC.
I particularly used the later setup, but NextCloud was too much to handle for me, and settled with KeePassXC + Dropbox.
You do you, but use a password manager.
KeePass is the perfect tool for me ! The cybersecurity practice at work also use it,
Yes, they should be used. KeepassXC FTW
I’m probably going to get grilled for this but I’ve Been using Firefox’s Saved passwords, I really don’t need anything better.
One another Bitwarden user chiming in!
I started with LastPass but they started making things difficult enough on the mobile side that I decided to jump ships. Bitwarden also is a smoother app to use - LastPass felt clunkier (I’ve used only the free side on both).
Been using 1password family subscription for years. Absolutely swear by it.
I’m in the Bitwarden camp. There is no other way for me to have complex/secure passwords and remember them for my gazillion accounts.