It was a total pain in the ass to set up, but now that it's working it's almost totally pain free. On iOS I use MiniKeepass. I would love to use KeepassTouch, but they won't release their source code (GPL fork of MiniKeepass) to check, so I'm stuck with MiniKeepass.
It's awesome and I can highly recommend it.
Unfortunately I'm not sure the iOS story is as great as Android?
I try to balance convenience with security, without being too zealous about either.
You don't have to maintain anything beyond setting it up and reconfiguring the clients allowed after reinstalling the OS on a client, and occasionally checking on it and updating the software. It's pretty low maintenance.
We tried passpack at work for a while to be able to share passwords across a small group of people and it wasn't a great experience, mostly because we always had to manually share everything to everyone in the group.
We moved to Lastpass recently because we can have group passwords. Turns out that you cannot even copy the password without displaying it, which I'm very surprised of.
In comparison, the KeePass would be worst if it comes to sharing between a group, but for a single individual, KeePass + Syncthing is amazing. I don't use any plugin, I just open up KeePass, ctrl + f to find the entry, ctrl + b to copy the username, ctrl + c to copy the password. With those shortcuts, it's quick enough for me.
If you want to keep it simple, just use the command-line `pass` utility. You can verify the workings of that fairly simple script yourself.
If you want to share your database across multiple machines, you can use git, or a non-cloud synchronisation tool such as Synthing². You can even encrypt (parts of) your password tree for multiple recipients (all using OpenPGP key-pairs).
Personally, I really like the setup I have with Syncthing and `pass`.
I use key file and Master password to access my password storage, which is hosted at Dropbox which is behind 2FA. Key file is hosted locally. So I believe this is more secure than just using Master password.
For iOS , I use minikeepass, you can export the password database from Dropbox if you install the app. The need of exporting password database to Minikeepass each time you make update on other devices is kind of annoying tho.
There is a plugin for connecting KeePass to Dropbox and Firefox has plugin for autocompleting and saving passwords to Keepass, so for me it works perfectly fine on desktop.
But in the end, I don't pay for password manager, and I can control my own data.
I migrated to https://www.passwordstore.org and am perfectly happy. I always used the keyboard driven password search to retrieve passwords in 1Password. On Linux I just use dmenu. It is as good as any other password manager and I don't have to worry about problems like the ones in this article.
I still like 1Password, but I won't be going back.
I still recommend 1Password if you need cloud sync. KeePassX is a good local storage GUI alternative. Or just use Keychain on a Mac.
1Password has so many useful features, but the push towards the subscription model feels like Agilebits might phase out all other storage engines eventually, regardless of what the official line is right now. At least maybe they'll branch into Linux support if the subscription model brings in more revenue.
pass generate accounts/news.ycombinator.com 32
> keyboard shortcut driven UI`pass` is a CLI application. It has tab-autocompletion and everything. It doesn't get more efficient than that (tip: use `pass find` to search for entries).
> different storage engines
It's just OpenPGP encrypted plain text on disk, not sure what more you could want, but there is support for Tomb (https://www.dyne.org/software/tomb/) as well. Anything you expose to the filesystem works of course, including services like SFTP.
> shared vaults
Syncthing or git, and the use of multiple OpenPGP recipients. (See `.gpg-id` in the `pass` man-file.)
> categories for secure non-password stuff like credit cards,
It's plain multi-line text. The only convention is that the first line is intended for the password or secret data that clients would copy to the clipboard. You can store whatever text you want.
> OTP support
The shell interface is good. Especially `pass search`. Simple but effective.
It has gotten quite popular as well (amongst technical folks anyway). It is basically just a giant shell script. You can almost sense the authors frustrating. FINE I will just write a password manager myself. This started a simple 30 line shell script. Then you get into hacking on it. The you figure FINE I will polish it and release it. :)
It's just a file system with gpg encrypted files at the end of the day. I keep it organized. Store credit cards, etc.
Browser and fingerprint.... No.
[1] https://jacob.hoffman-andrews.com/README/2017/01/15/how-not-...
It's also not open source so I don't recommend it to anyone but me. :-)
> KeePass 2.x features a powerful, built-in synchronization mechanism. Changes made in multiple copies of a database file can be merged safely.
> After synchronizing two files A and B, both A and B are up-to-date (i.e. KeePass saves the merged data to both locations when performing a synchronization).