Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass.
Don't suppose there's anything out there that can import the lastpass db?
Is there anything automatic out there? I'm not going to use program+dropbox/cloud-provider. I need something like lastpass.
Don't suppose there's anything out there that can import the lastpass db?
So I don't consider that a realistic approach for most people, especially for something as mission critical as password management.
I've read a lot of reviews but many predate 1Password's cloud option.
Has android/ios/blackberry/windows mobile clients, desktop clients for mac/win/linux/chromebook (including portable versions), and browser addons. It's not a subscription service---the desktop versions are free, and the mobile versions cost a 1-time purchase to unlock all the features. I'm very happy with it.
Usage: It's a git repo with passwords stored in encrypted text files. Syncing is done by push/pull the git repo. Since it is git, you have a record of every password you ever generated. Unlocking a password with a Yubikey requires a pin entry and a physical touch. Once entered, the key is available for further passwords without pin, but a Yubikey 4 can be configured to require a touch every time if you're worried about compromised hardware stealing your entire password database.
There's no import from other managers that I'm aware of, but it might exist. Googling stuff about 'pass' is tedious. Google for 'zx2c4 pass' and you'll have better results.
It can import from a lastpass file.
Even though it's open source, there is a hosted instance (so the experience is much like lastpass). There was a kickstarter a while back that failed though, so I'm unsure how it's funded.
The lead developer answered that here:
Autofills my logins and fully integrates with Firefoxes password manager so that you don't get conflicts between the browser and your password manager trying to save the same password. Also doesn't add the stupid CSS hacking that LastPass does to add their logo into the password fields breaking various site's styles.
[0]: http://keepass.info/help/base/importexport.html- No https on site
- Update file hosted via http (not https)
- Downloads via sourceforge which has injected adware in downloads before
- FAQ downplays lack of constant time comparison instead of using constant time comparisons and being extra safe
- You have to cobble together multiple apps from multiple developers to get a full working solution; means you have to trust lots of individual entities
That being said I can hardly defend staying on Lastpass anymore.
I just wish 1Pass was crossplatform so there was a clear universal winner!
The https thing is unfortunate and should be fixed, but I've always got my KeepassX from a signed repo.
The cobbling together is also an important part of its strengths. In particular I want the sync of the encrypted DB to be decoupled from the app that decrypts and manages the password entry into forms (the latter being yet another entity, btw).
I'm really curious to see that FAQ entry! Because I can't imagine a scenario where timing sidechannel attacks would be relevant to a password manager app (provided the sync is decoupled, which is one reason why that's so important). If you're gonna bruteforce the master key, you'll use an external program any way, so constant time comparisons in Keepass's routines shouldn't matter? Also it's not like you could remotely trigger Keepass to decrypt 1000s of times in order to glean info from timing data, because it's not a browser plugin. Which is one of the reasons why we don't want our password manager to be a browser plugin. Again, decoupling is a strength.
- Sourceforge, again not ideal but again it has very old beginnings from when Sourceforge was as respected as Github is. You can't blame the developer for the environment changing. Perhaps they're just a stickler for loyalty. I've never had any crapware with Keepass
- FAQ - I could't find your reference in the FAQ page [1]
- You have one app + plugin with a browser extension from two developers, hardly a mishmash. You know directly who those two developers are. You've no idea who was working on LastPass. I'd say it was more in the bazaar philosophy vs the LastPass cathedral.
[0]: http://keepass.info/integrity.html
[1]: http://keepass.info/help/base/faq_tech.html [0]: https://sourceforge.net/projects/keepass/files/KeePass%202.x/2.35/KeePass-2.35-Setup.exe
[1]: https://chocolatey.org/packages/keepassSounds like a huge pain compared to LastPass, as well as increasing attack surface.
So the extra layer is the plugin that is written by the same developer as the browser plugin. Which is a drop in plugin.
It's all open source so it's much easier for people to check the vulnerabilities. It's also easier to raise issues and other people to help fix them.
Separately Keepass is an offline database, so you have total control over access to it. The overhead of course is using something like Dropbox, plus probably Boxcryptor to ensure it's encrypted before it gets to Dropbox.
I've commented elsewhere here - it's similar to the Keepass bazaar vs the LastPass cathedral. Keepass might look uglier, but I trust it more.
https://csdashlane.zendesk.com/hc/en-us/articles/202699141-H...
There's an unfixed bug in the OSX client where it crashes rarely (every couple months for me) and I have to kill the process manually and restart, but it has very minor impact.
Is there any security analysis or consensus on Dashlane security vs. other password managers?
I feel like with lastpass the attack vector is bigger with all the fancy features.
Padlock does: https://padlock.io/howto/lastpass/
Disclaimer: I'm the developer