Personally, to me that sort of integration has always seemed like a bad idea. I'm glad that my password database can't talk to my browser programmatically. One less thing to go wrong.
Personally, to me that sort of integration has always seemed like a bad idea. I'm glad that my password database can't talk to my browser programmatically. One less thing to go wrong.
It takes passwords and makes them "unphishable", because the manager knows what domain you're on.
Of course it's also the largest attack surface. Personally, I think that tradeoff is worth it - assuming competent development.
...of every other extension that you use. That is a very bad assumption to make.
That said, I do use Lastpass myself and in fact have a premium membership.
Anyway, it doesn't necessarily protect from keyloggers for a couple of reasons:
1 - The password to the password database will be recorded by the keylogger. The password database can then be copied by the intruder and then opened using the logged password.
2 - Any password you type in to the password management app can be logged by the keylogger, so browser integration does not help.
2. You usually don't type passwords into the password management app, you generate them.
But yes, generally it's best if you don't get your computer infected with malware in the first place. Obviously if your computer is compromised there'll always be some way for sufficiently advanced malware to steal your password database.
2. Generating passwords would help protect them from keyloggers and is a reason to do so. But as far as I know no password manager prevents people from typing in passwords, and I'm sure a lot of people do for a variety of reasons (from importing old passwords or passwords generated on another device to creating memorable passwords or because the password generation mechanism of the password manager is inadequate in some way, etc).
> From the text it looks like one of the selling points is integration with apps like browsers so you don't have to copy/paste passwords, as with KeePassX.
Can you provide source please? thank you.
This [1] says the opposite: (quoting from the github issue):
"I removed the milestone for now since we are not sure if we actually want our users to expose their passwords over a network protocol with questionable security record. The security of both KeePassHTTP and KeePassRPC is doubtable and in their current state we would prefer not to have them as part of the main KeePassXC product.
This doesn't mean KeePassXC will never support it, it only means that at the moment we don't have immediate plans and an implementation needs further discussion."
[1] https://github.com/keepassxreboot/keepassxc/issues/88#issuec...
What's ugly about it, besides (I guess) .NET part?
Occasionally, text goes some unreadable colour. And it crashes when I click while holding down Super. And it only follows the GTK colour scheme sometimes; enabling night mode ended up with a beautiful mix of black-on-black-with-white-stripes.
Oh, and widgets like buttons look like a poor man's copy of Windows 95.
Though, to be fair, I now seem to be unable to trigger the above bugs in the latest build, so I guess it's no longer quite as much of an issue.
Yes, all of the above. Plus having several hundreds of mono libs installed for just one app. That app runs 100% of time, but still...
Personally the best feature I'm using KeePassXC for is the auto-reload feature. I sync my kdbx file with Tresorit across couple computers, and the auto-reload feature ensures that I'm always modifying the latest version.
This is something lacking in the original KeePassX.
$ decrypt psswd.txt | grep "mywebservice.com"
Though now the password is displayed on the terminal... Not great, but better than exposing the whole database.Not on Wayland.