But now realizing that they're handling URLs in this way... I just can't use it anymore or recommend it in good faith.
So what do I do?
- KeePass looks nice, has multiplatform support and browser extensions but the crpytography in it is sketchy, custom KDF and stuff going on... mobile support might also not be so great though I'm not positive.
- PasswordSafe has better looking cryptography, though still not up to where I'd like it to be as well as a worse UI, worse browser support, etc. And last I checked I think Linux support was sketchy.
- There are an infinite number of questionable proprietary solutions that have similar problems to LastPass, usually far worse actually...
- and a few open source solutions that look good but completely lack in the UI and integration departments.
So I'm about to take KeePass, gut the crypto, replace it with simple scrypt and AES-OCB or chacha20-poly1305 and hope I can wind up with something I'm comfortable using - anyone have a better suggestion?