KeePassXC 2.7.0
keepassxc.org
keepassxc.org
* Runs on Linux/Mac/Windows and there are compatible clients for Android. Make your own cloud with a RaspberryPi referred by a DDNS and you'll have super powers.
* Auto-type. Is tricky to get it working but once you get it you'll become addicted.
* The UI makes it much easier to copy and paste fields and the notes are clearly visible. I often use the notes to store things like github tokens (for git), etc. However, I keep 2FA TOTP codes on my Pebble watch only. If you keep 2FA codes on the same file as your password then it isn't 2 Factor anymore, right?
Little things that bothered me:
* It took me a while to understand how does the Touch ID/fingertip reader works (you need to turn on the checkbox, press Ok on the authentication modal and then touch the reader). Touch ID is one of those things that suddenly you discover you can't live without.
* The browser add-ins are not always smooth and friction-less. Sometimes you need to reload the page, reopen the db. Chrome's add-in is the hardest to get working. Firefox's is better.
* Edit: forget this. As varjolintu explains bellow, this is wrong. ~~You can't have multiple addresses per entry. Some sites will login with different URL's and KeepassXC will not recognize all.~~
But I am still a fan. I'd give it a 8/10.
Thank you. That's very cool.
You can use global Auto-type which brings up Keepass window where you can pick from relevant entries.
You can a Global keyboard shortcut and it will work mostly anywhere.
https://addons.mozilla.org/en-US/firefox/addon/add-url-to-wi...
I can also make it auto-type into remote sessions, non-browser applications, and """""extremely secure""""" fields that don't allow you to paste into them.
I do use the 'url in title bar' browser extension (there are a lot of these) to help it lock on properly.
Technically no, but whether or not that is a problem depends on the threats you're worried about.
I'm personally most worried about 1. credential stuffing, 2. keyloggers/client exploits, and 3. Phishing/MITM attacks.
Using a password database allows me to use different passwords for every site, which defeats #1.
TOTP even if it's in the same database solves for #2 since simply scraping the password isn't enough to gain access.
And #3 isn't addressed at all, even if you use a separate device for TOTP.
What I'm not especially worried about is specific targeted attacks where the attacker is attempting to acquire my database and crack it.
Now, if you store your password database on someone else's cloud, that could become more of a concern, as a mass breach and bulk collection of databases becomes a possible attack vector. But I use syncthing to directly share my DB between devices, so I'm not particularly worried about that.
If you're worried about either of those threats, then a separate TOTP device is absolutely vital. But, for me personally, the inconvenience of it is not worth the additional security.
I know there are decent options for both mobile devices but it is harder to pitch a piece of software with multiple vendors than a single, unified vendor when security is a top concern.
Create 2 entries for the same site and install the Keepass helper (url in title) addon
I combine it with KeePassium on iOS and Resilio Sync for synchronising across my main and mobile devices. (Syncthing doesn't offer an iOS client, sadly, hence the choice of using Resilio)
This is true, but pricing is currently $3/mo, $15/year, $60 lifetime. So the one time payment is larger than most.
I host nextcloud and use strongbox. Nextcloud supports WebDAV and strongbox works well with syncing through that.
Of all the Keepass implementations in Android it seems to be the most actively maintained and featureful, but it's great to have a few different options. In addition to KeePassDroid (which I used to use, and have no major issues with) there's another (Authpass) on F-Droid which I haven't yet tried but looks promising.
1. I need a tool that can save not just password, but something more general. For example, a desktop software credential (with BitWarden, I need to open a browser or electron app to do that). Another example would be a PIN required each time I use the voice mail. Or certain PIN for my bank accounts (not the one used to login the online banking). I am aware you can save them in the note section, but it feels better when you can customize these fields. These non-password secrets used to be saved in plain text scattered around in various files on my PC. Now I have a centralized and organized access.
2. I know that with some configuration you can have self-hosted BitWarden vault. But I think KPXC + whatever_file_sync_app is simpler.
3. I actually started using KeePassXC because IT forced me so. I hated it initially, but later discovered it's actually a great tool for managing secrets in general.
4. HN Syndrome: preferring "native" app than web/electron.
I'm sure Bitwarden is more than adequate as well though.
With Bitwarden, I cannot create a new password or change existing one without being online, but I consider that a small price for not having to deal with conflicts anymore.
I assumed people would switch from Keepass + database synced on a private server to something else when they started working in teams and need better/easier permission models. :)
As you have mentioned it, I have written the tool keepass-diff (<https://github.com/Narigo/keepass-diff/>) to help me for exactly these conflicts and I could quickly resolve the issues with it. It was still useful enough to let me keep using Keepass. Was it not working for you or was it too hard to use because of how it needs to be set up first? Would you have stayed with Keepass + sync if something similar to this was integrated into UI clients?
Yet, the sync conflicts happened anyways. The first time it was quite shock, why my password doesn't work, but then I found the conflict password file and the password from there worked.
Your tool made it much easier, big thanks for creating it.
Maybe, if the keepassxc had in the UI, that it detected a sync conflict (that would involve a knowledge how the misc sync tools work) and offered merging them, I would probably stayed.
Ultimately, I switched to vaultwarden, on the same above-mentioned NAS. It does not have all the features of the keepassxc, but it is good enough for me, the sync problems disappeared, and the browser integration works a little bit better (doesn't complain that the main app isn't running, while it is).
Not sure if NextCloud could be causing some issues? As I mentioned, I believe Seafile automatically overwrites (to newest version) and it's been fine (there's history if you lose something, which shouldn't happen anyway).
I do think this merge functionality would be very nice in KPXC, but for other reasons: I sometimes use the browser databases to save passwords (when I forget to open KP) and I need to merge the new entires.
I recently tried it, as I don’t need 90% of the features NextCloud offers anyway. Sadly, the installation process seems far more complicated, and I ended up just abandoning it and going back to NC after getting unclear error messages.
I like the idea of self-hosting a lot, but I also think it's fine to have hosted services of OSS (I think you need to be technically oriented to make it work easily and reliably, which isn't everyone).
It's a small change but it does reduce the attack surface as well as force me to manage my data myself which I want to do more of.
Also with BitWarden, their UI annoyed me when I needed a password outside the browser. L
Are you using a wlroots compositor like sway or GNOME/KDE?
https://github.com/keepassxreboot/keepassxc/issues/2281
I'm considering adding support for keepassxc in tessen but autotype works only on wlroots based compositors like sway right now.
However, auto typing on Wayland works pretty well if you use wlroots compositors/window managers like sway.
What is the best "backend" for setting up sync between KeePassXC/Strongbox/etc, between multiple clients active simultaneously?
Is there a good reason why we haven't seen something like a REST API enabled backend using KeePassXC as a client? Syncing files using off-the-shelf services is great that it exists, but it's obviously far from an optimal solution.
Having said that, I am in the same camp as some of the other comments in using KPXC for it's AutoType (and ssh agent), so if that's also your requirements then Vaultwarden won't get it done because the Bitwarden clients are aggressively stupid
I like the idea of this sync but I don't know how the internal implementation would handle this. Dropbox and Nextcloud both sync the files themselves, and in case of a conflict, they preserve both versions, and let you pick which one you'd like to use as the "canonical". It's a pain but at least the data is preserved.
I had to use the old/creaky/unmaintained KeePassBrowser addon for Firefox back when I was still on regular KeyPass. The KeePassXC-Browser addon is still supported, and much cleaner.
p.s. - Oh, and the reason for considering even moving to bitwarden is ease of mobile access by several people at once...since schlepping a keepass database via file sync stuff works sort of ok until you have to access the same file via mobile (possible but not great), plus my family and i kept stepping on each other's toes when updating said file, etc. Not hating on keepass, as it has served my family really weell...and i'm very thankful to the keepass devs! It is simply that we might be outgrowing it a tad...maybe.
https://keepass.info/help/kb/sec_desk.html
I wish KeePassXC would implement this functionality on Windows. Seems there is an open issue, but KeePassXC author says this is just Windows security theater:
eg: account.domain.com changes to signon.domain.com at some point and it stops matching.
I've gone in and saved some accounts as just domain.com to prevent this, but when creating new passwords/etc, it always adds the current URL and the problem happens again after some time.
Thanks!
I see. You've chosen not to use remote sync?
I feel like this is an oxymoron. At least security updates should be something to look forward to, no?
The difficulty is telling the difference between projects that rarely update because there aren’t any vulns, and projects that rarely update because they don’t care.
I don't see how switching to a different extension will improve anything.... I have global auto-type binded to CTRL-SHIFT-C and it just works
If you need external functionality that is not available in KeePassXC, you can try to bolt it on via the KeePassXC-Browser API or open a feature request (or even better: pull request) to get it into the core application.
KeePassXC is a great program and combined with synthing, excellent solution to managing your passwords.
So is this another KeePass fork, and is different from this one: https://formulae.brew.sh/cask/keepassx ?
There are some small differences between the projects in technical aspects but I don't fully recall the details.
The C in KeePassXC stands for community IRC.
Subjectively I 'd say that if you are wondering which of the 3 to use, go with KeePassXC. That's what I am using.
KeePassXC had no such issue.
That was CVE-2022-0275 https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=keepass
BTW KeepassXC did not have the same issue.
Also, how would people compare this to something such as 1Password?
Read my comment on the top of the comments. The top features are browser integration, auto-type and integration with Touch ID/fingerprint reader.
> how would people compare this to something such as 1Password?
KeePassXC auto-type is a lot more powerful. It can be configured in several ways and works with a lot more windows: SSH sessions in terminals, os windows in programs, etc.
OTOH, 1Password is automatically "clouded". With KeePassXC you need to place the encrypted database in a cloud (OneDrive, Google Drive, Apple Drive).
Syncthing looks a lot like a "make your own cloud" solution.
I use OwnCloud in a RaspberryPi, instead. But as Moxie Marlinspike famously said: "People don’t want to run their own servers, and never will". (https://moxie.org/2022/01/07/web3-first-impressions.html)
Of course it's not magical : for them to be in sync, you'll then have to have both turned on with Syncthing running at the same time.
But if you have something lying around, like an old laptop, it's trivial to have it running, and maintenance is super low, just keep update it from time to time : I have Syncthing running on a low cost server for multiple years, syncing pictures + documents, and the only issue I ever had was disk space running out once.
The lack of built-in replication is considered by many (me included) as more secure as the db is only on a single system and never in the cloud or on the wire.
I switched to Bitwarden in order to deal with this.
I'm the author of keepass-diff and built it for my own needs. Looking through the comments here about why people switched from Keepass to Bitwarden, it feels like the compare feature is something that should be integrated to UI clients as many people seem to face this problem. I always assumed it was more because of permissions and better ability to work with it as a team...
Right now I just copy past them in the notes, but there should be an easier way.
https://keepassxc.org/docs/KeePassXC_UserGuide.html#_history
it took me like 2015-2017 to teach my siblings to use it. now we have copies of each others kbdx files and passwords in our respective files so if there is an emergency to access the others data (which contains btw, all important data besides login credentials, passport numbers, tax information, expiry of policies) and other than the occasional password change which barely happens now because we don't go and willy nilly create accounts or changes.
this is a very low cost/maintenance option because the files exist on our phones, in our backups, on our devices, the whole shebang.
i don't need an online password manager, it simply will not work for me because i am relying on someone else and because the data is on my device, its as secure as the xkcd plumbing password
this works almost like a safekeep in case a person dies and their heirs get to access important stuff which otherwise get lost. i mean my family has a copy of my file with the password