I'd prefer people are using any password manager than go for perfection and then quit completely because it was a terrible UX. KeePass may be more secure against certain specific attacks, but it is largely irrelevant if people are going to contrast it against using no password manager at all because it was too cumbersome.
You might think you'd notice if the site you're on had a different URL than the one you're expecting, but that level of constant vigilance might turn out to be more difficult to maintain than you expect. Especially when you take into account some of the more exotic phishing techniques like IDN homograph attacks.
Sorry, not doomed to fail.
I'm not gonna use a password manager that is "context aware" and has the capability to auto-fill for sensitive sites - that's just my threat model. I'm okay with context aware storing of less critical passwords.
This is literally one of the last major attack vectors since password managers became somewhat more popular.
They all do encryption well, even the ones that keep the database on a server you don't control it's most probably actually encrypted, etc. They do the basic password manager thing. They keep your passwords.
Every time there's something wrong/vulnerable with a password manager, it is because it's a browser extension and the attack surface between the password manager and the browser is being attacked.
> I share your wariness of the browser extensions, but you're betting that a software bug is more likely than human error.
Well, it literally has been.
(this is why I'm using Keepass and no browser extension for my passwords)
Can you give an example?
I seem to remember reading about similar stuff done elsewhere, but don't remember the details (or apparently a useful search term :P).
There is an option to autofill, but it's buried in advanced settings and Bitwarden will display a warning if you try to enable it. (This message ought to be worded more explicitly—it currently says "this feature is in beta" rather than "this feature will decrease you're security"—but, still, not a default.)
why should I as someone who is securing my own passwords care about your preferences or what will and won't work for someone else too lazy to be concerned?
KeePass is barely decent for personal use only, and only for the desktop.
The quality of the available apps differs from platform to platform. For example Bitwarden has a decent iOS app, 1Password has a superb iOS app and in contrast the available KeePass app for iOS is a piece of shit – no offense intended but it's basically unmaintained, barely usable and does no sync so you'd better watch out for conflicts.
And just like I think a password manager shouldn't be a browser extension, I also don't think it should encourage behaviour like sharing passwords among people ... I mean, really? That's literally password reuse, don't feel good about it. Of course a password manager shouldn't encourage it.
"Our son Jim made this password using his password manager thingy so it's probably really secure and now we use it for all our banking and government stuff"
I mean it's sincerely better to keep a "family password" on a post-it, so you don't confuse it with passwords you're actually trying to keep secure.
There are multiple .kdbx apps, like MiniKeePass on iOS, which is decent, but it's lacking active development at the moment.
[1] https://play.google.com/store/apps/details?id=keepass2androi...
There is Strongbox on iOS and it's by far the best mobile KeePass-experience i've ever had.
Slightly? Just thinking about the synchronization between machines makes this an understatement in my opinion.
The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button.
Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.
You are right that this is a good approach for many it will certainly break for many as well.
Re a) https://keeweb.info/ toss this onto any ol' free tier web host you want. No app install necessary. It's not as nice as the apps, but it works.
Re b) Is there an environment that both has a web browser that you want password management with and doesn't let you access any consumer cloud sync service?
I mean, installing browser extensions to deliberately get around their security measures seems a little bit counterproductive. They aren't more secure than local apps. Do you take this company's security measures seriously or is it just some hurdle to get around for you?
Yes, which is why I posted the alternative to installing an app. You can use Keepass + drive/dropbox sync without installing anything using keeweb.
You do not need to install apps to access drive, dropbox, etc...
What are you on about? Synchronization is easy, you can use just about any service you like.
The fact that it's not kept on a server by the same commercial party that also sold you the security product, is a feature. And obviously necessary, since KeePass is free and open source.
I see leaking credentials bugs with browser-extension operated online storage commercial password software all the time on HN. Obviously you're paying for shiny, not security.
https://hardware.slashdot.org/story/19/07/22/1534200/dropbox...
KeePass is the best at what it does and stays local as any password manager should do. If you need more security & portability encrypt the DB with VeraCrypt, sync with whatever service you trust.
I don't know if the iOS client is that bad, but the Android one is just fine.