KeePass is the best at what it does and stays local as any password manager should do. If you need more security & portability encrypt the DB with VeraCrypt, sync with whatever service you trust.
Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.
The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button.
Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.
You are right that this is a good approach for many it will certainly break for many as well.
Re a) https://keeweb.info/ toss this onto any ol' free tier web host you want. No app install necessary. It's not as nice as the apps, but it works.
Re b) Is there an environment that both has a web browser that you want password management with and doesn't let you access any consumer cloud sync service?
Yes, which is why I posted the alternative to installing an app. You can use Keepass + drive/dropbox sync without installing anything using keeweb.
You do not need to install apps to access drive, dropbox, etc...
I mean, installing browser extensions to deliberately get around their security measures seems a little bit counterproductive. They aren't more secure than local apps. Do you take this company's security measures seriously or is it just some hurdle to get around for you?
https://hardware.slashdot.org/story/19/07/22/1534200/dropbox...
What are you on about? Synchronization is easy, you can use just about any service you like.
The fact that it's not kept on a server by the same commercial party that also sold you the security product, is a feature. And obviously necessary, since KeePass is free and open source.
I see leaking credentials bugs with browser-extension operated online storage commercial password software all the time on HN. Obviously you're paying for shiny, not security.
I'd prefer people are using any password manager than go for perfection and then quit completely because it was a terrible UX. KeePass may be more secure against certain specific attacks, but it is largely irrelevant if people are going to contrast it against using no password manager at all because it was too cumbersome.
Sorry, not doomed to fail.
I'm not gonna use a password manager that is "context aware" and has the capability to auto-fill for sensitive sites - that's just my threat model. I'm okay with context aware storing of less critical passwords.
Can you give an example?
I seem to remember reading about similar stuff done elsewhere, but don't remember the details (or apparently a useful search term :P).
There is an option to autofill, but it's buried in advanced settings and Bitwarden will display a warning if you try to enable it. (This message ought to be worded more explicitly—it currently says "this feature is in beta" rather than "this feature will decrease you're security"—but, still, not a default.)
This is literally one of the last major attack vectors since password managers became somewhat more popular.
They all do encryption well, even the ones that keep the database on a server you don't control it's most probably actually encrypted, etc. They do the basic password manager thing. They keep your passwords.
Every time there's something wrong/vulnerable with a password manager, it is because it's a browser extension and the attack surface between the password manager and the browser is being attacked.
> I share your wariness of the browser extensions, but you're betting that a software bug is more likely than human error.
Well, it literally has been.
(this is why I'm using Keepass and no browser extension for my passwords)
You might think you'd notice if the site you're on had a different URL than the one you're expecting, but that level of constant vigilance might turn out to be more difficult to maintain than you expect. Especially when you take into account some of the more exotic phishing techniques like IDN homograph attacks.
why should I as someone who is securing my own passwords care about your preferences or what will and won't work for someone else too lazy to be concerned?
KeePass is barely decent for personal use only, and only for the desktop.
The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically unmaintained, barely usable and does no sync so you'd better watch out for conflicts.
There are multiple .kdbx apps, like MiniKeePass on iOS, which is decent, but it's lacking active development at the moment.
[1] https://play.google.com/store/apps/details?id=keepass2androi...
There is Strongbox on iOS and it's by far the best mobile KeePass-experience i've ever had.
And just like I think a password manager shouldn't be a browser extension, I also don't think it should encourage behaviour like sharing passwords among people ... I mean, really? That's literally password reuse, don't feel good about it. Of course a password manager shouldn't encourage it.
"Our son Jim made this password using his password manager thingy so it's probably really secure and now we use it for all our banking and government stuff"
I mean it's sincerely better to keep a "family password" on a post-it, so you don't confuse it with passwords you're actually trying to keep secure.
I don't know if the iOS client is that bad, but the Android one is just fine.
Both are based on the same underlying principles (AES encrypted database, encrypted using a slow hash of the master password). Both have been audited professionally. Both have browser extensions whose source code you can read (it is JavaScript, just open the extensions directory). Both support a full array of 2F options.
People are moving from LastPass to BitWarden because it is a better product. Plus many dislike LastPass's owners due to the LogMeIn pricing/business practices (like difficulty cancelling/early cancellation to avoid additional billing/aggressive sales people/etc).
The only advantage BitWarden may have is its backend is open source software and you can run a copy yourself (although most choose not to). If you're running it yourself BitWarden is likely your primary contender. If you aren't the difference is largely academic.
>How We Use the Information We Collect and Receive
>LogMeIn may access (which may include, with your consent, limited viewing or listening) and use the data we collect as necessary (a) to provide and maintain the Services; (b) to address and respond to service, security, and customer support issues; (c) to detect, prevent, or otherwise address fraud, security, unlawful, or technical issues; (d) as required by law; (e) to fulfill our contracts; (f) to improve and enhance the Services; (g) to provide analysis or valuable information back to our Customers and users. [1]
(e) is a very broad and loosely defined category. A contract can include Anything and this ambigious statement enables LogMeIn to inturn do anything with data they collect from all their services (including Lastpass).
In the new firefox updates, Lastpass won't let you open/run the extension until you provide it the abiltiy to monitor all browsing behavior (whereas on chrome I have it restricted to monitor sites when the extension is clicked/activated)... I will not be renewing my premium service and am looking to migrate away to another service.
I tried KeePass XC on the side and I’ve gotta say, very formidable option if you want one that is FOSS and with no central server. My only real issue is the mobile app story.
Considered doing the self-hosted approach, but wound up paying to support the project.
How does BitWarden compare to 1Password?
Maintaining a single node just for a Bitwarden service isn't a "set and forget" endeavour. It is easy to misconfigure Linux to be insecure, most distro's ship with too much software, and auto-update is often inadequate to maintain a secure environment.
There's far too many compromised Linux servers out in the world that people set up "to do one thing" turned on auto-update and then forgot about for years. Botters and spammers love them.
This has little to do with Bitwarden itself and everything to do with how much knowledge and time is required to correctly run any internet accessible server. People are inherently lazy and it is very easy to get apathetic when it just continues to work, until something bad happens.
Some people, organizations, or groups can, absolutely.
While this is definitely a valuable question to ask, self-hosting is still valuable for many. Also, as we have seen repeatedly, assuming a random company will devote resources towards security can be a very silly assumption.
Yes it is. It's a docker image, you're not setting up anything about the host that's exposed to the internet. Toss on watchtower to auto-update it and why would you ever need to touch it again?
The system hosting docker isn't getting updates, no, but it's not publicly reachable, so that's low risk. The system that is publicly reachable is entirely contained & auto-updated, so that's covered. What else is there to worry about?
Sorry, but nope. The Docker container itself is a fully functional machine. It also holds your most prized data (password database/password host). Turning on auto-updates and watchtower then leaving it unmaintained indefinitely was exactly the problem I was posting about above.
Scary that people think Docker is a security solution. It isn't. The Docker container is a full machine. The Docker host is a full machine. You've now doubled your points of failure and are zero percent more secure.
What? It's not unmaintained at all. It's continuously maintained by the updates to the container. That's the whole point. Just because the user that did the deployment isn't the one doing the maintenance doesn't mean it's unmaintained.
The end-user isn't the one building the docker container, maybe that's where you're getting confused. Bitwarden themselves are maintaining it. That's how they are shipping the software for self-hosted deployments. Professionally maintained and self-hosted. That's why docker enters the picture, not for some imagined security reason as you incorrectly claim.