KeePass is the free, open source, light-weight and easy-to-use password manager
keepass.info
keepass.info
Their importer is powerful... but I had to manually configure it to import from lastpass. Just bake that in ffs.
There is no "generate password" button on the main application screen despite that being the #2 use for a password manager behind autofilling. Instead the main screen has "find", "find entries" and "search" buttons which are all slightly different despite sounding completely redundant.
To get a browser plugin, you have to pick from a disturbingly long list, each with pros and cons, each requiring a few config steps, and none of which work as well as the cloud competition. I had random disconnections from keepass and many autofill failures.
Finally, you get to syncing, and the friction is bigger than you expect. It is not enough to set up a LAN folder; your solution needs to be able to resolve conflicts if you ever use more than one device simultaneously, otherwise you run the risk of losing changes. The most common sync solution is dropbox because that is the only mainstream cloud offering with first party support for linux, which is fine, but can still cause conflicts. The recommended way to handle this is quite convoluted[1]. Just bake that in, FFS!
[1] https://keepass.info/help/kb/trigger_examples.html#dbsync
Some plugins on the list require other plugins to also be installed.
Would you explain what kind of a problem you see here (I mean: KeePass related)? AFAIK syncing two KeePass database instances is based on timestamps, so losing changes made on any two copies kept/used on different devices is simply impossible if you properly use KeePass (ie. do merge them with KeePass). Of course, if you want to have a real cloud-based password manager then KeePass (without any extension) isn't appropriate at all. But what's the purpose of comparing apples to oranges?
Now that is a whole different level of confusing then keepass. I mean I generally know what I'm looking for, but wouldn't know if I should click on the families or Linux button for example. So I think this refutes your point that market share is due to the download page.
Edit: Ah, I guess you might be talking about the small Downloads section in the footer. Even that's much more clear than a page with a 2.x download, 2.x portable download, 1.x download, 1.x portable download, and then 30+ unofficial ports.
But I have to say, arguing that the downloads buttons on keepass are more friction than "get started" (I don't see a app store link) which takes me to the business offer and then the family offer where I have to register an account and provide payment details, is a bit of a stretch. And bitwarden is very similar.
Sure I can search on the playstore, but then I also find keepass quite easily there.
KeePassXC is probably the closest to ideal. It could just use more info about what it does on the homepage, and change its name for better marketing. But the project states itself that their audience is "for people with extremely high demands of secure personal data management" so I doubt that would ever be addressed.
Well, "the closest", but not ideal, unfortunately, what I realized when they decided to abandon support for windows7 forcing me to maintain the KeePass database in VMs by hand... :-(
Idk. I very intentionally decided to not have 98% of my passwords on my phone. (The remaining few rarely change and I put them in my phone by hand without sync.)
This decision was less because of security consider but more because I don't want to be able to access the services through my phone.
If then anyone (especially I myself) wants to pressure me into doing work or anything like that when I'm away it won't work because I simply can't. Makes it easier to switch off after work or on holidays.
But work gets its own separate password manager that only lives on the work computer and nowhere else. I’ll get fired before I even think about work outside of work hours let alone on vacation.
the company I'm now working for uses 1password, it's on my work laptop and only there, not on my phone, neither my private PC. Same for slack. Only office mail is also on my phone, so that I can call sick from my phone if necessary (but normal work communication doesn't go through mail at all, so it's fine).
My stack is KeePassXC on computers, Keepass2android on mobile and Dropbox for syncing. A few months ago I realized that both of my clients showed a TOTP option. Went digging a little and realized that there was enough support that I felt completely comfortable jumping ship away from Google Authenticator.
Google Authenticator had been worryingly opaque to me until then - you scan a QR code and then somehow you get TOTP codes? - and having gone through a phone number change recently, I felt especially aware and uncomfortable about having 2FA for many important accounts tied to one fairly fragile, fairly mis-placeable electronic device (not to mention in an app controlled by Google).
Figuring out how to use TOTP on KeePass was the nudge I needed to read up on how TOTP works, and of course it was quite simple. And keeping TOTP secrets in a password manager seems like a not-terrible idea (with the one caveat - and it's not a small one, I know - of busting the "second factor"ness of 2FA by making it possible to generate a TOTP code from the same device that you're using to log in with).
I was especially impressed that KeePass knows about Steam's non-standard TOTP implementation and is able to generate Steam Authenticator codes. I will say that doing this requires some hairy steps! This was what put me on the right path: https://old.reddit.com/r/Bitwarden/comments/a67c1n/steam_aut... And I put a good ~200 words of notes stored in that particular KeePass entry to remind me how I did it in the future.
You can also have multiple files to handle different contexts, if you want some separation ie. 2FA-ness.
(you might also try keepassdx on android if you want a bit more polish)
Thank you very much for your remark! I always am in trouble when I have to dig through terrible KeePass "documentation" and never found a remark about it.
[edit: Syncthing's Discovery Server probably counts as data, actually; you can work around that but then it's less "straightforward"]
I ended up uploading the file to Google Drive and using it's client. It works pretty flawlessly.
This should be fixed: https://github.com/syncthing/syncthing-android/pull/1724
Besides my general distrust of Google, the real source of my headache is the ransomware attack. Thus such a simple schema is unsatisfactory. And the proper automatic backup procedure needs noninteractive testing whether the cloud copy is not garbled. Until now I don't know how to do it so I make backups of my Dropbox copy by hand.
It’s closed source though.
I would like to see a comparison with Syncthing.
From my view, Resilio is still easier to use with better apps than Syncthing, and in theory their corporate business model seems sustainable (more so than the previous parent company) and can provide useful corporate support when such needs occur. But there's still lingering doubts after all this time that they will continue to do the right things, support the software well, and it is closed source so there's not a lot of community support options if the company's business model pivots in any accidentally similar way to the events that lead to Resilio existing in the first place.
If you can self-host a password manager, then in the case of GitHub [0] going down every month you can self-host your Git repositories yourself, especially if you have projects like wireguard [1] for example.
This is the conundrum I am in. I have been looking for a pocket-sized password manager, which can sync from something like a spreadsheet I keep in cold storage. This seemed to fit the bill:
So I purchased one. It's pretty cool, although the controls are a bit clunky. Overall, pretty cool bit of tech.
However, to import your passwords into the device, there is no way to do so with the stock software which does not involve uploading all of your passwords to their servers. That is asinine, if I am being generous.
I feel more comfortable with that than syncing a KeePass file over dropbox or google drive, mostly because I got myself into a nasty situation that way with a corrupted KeePass database a while back.
I'm pretty much Syncthing + Synology these days. The bulk of my files are on Synology and the little files like the keepass databases are passed around with Syncthing.
I also have used keepassxc for years now on mac/windows/linux/iphones
what are the advantages of that?
Mono even had AOT compiler with capabilities that are only now landing on Native AOT, and are the underlying architecture for what made Blazor possible in first place.
The real reason to use KeepassXC over Keepass is because it's much better! The UI is better in almost every way.
You may sync it with your tool of choice, eg, Dropbox.
The desktop application is excellent, reliable, and with state of the art protections (Yubikey, Argon2 KDF, memory protections, etc).
I love KeePass for many reasons but one of the killer features for me is notes and encrypted attachments. It's also one of the reasons why I won't switch to applications like Bitwarden.
Bitwarden has both ;)
I set up pass (on Linux and Mac, using brew) with two GPG keypairs, a soft keypair and a YubiKey. The YubiKey goes in a physical safe along with instructions for next of kin (and as an ultimate backup for me). YubiKey is protected with PIN.
For daily use, use the soft GPG key and gpg-agent to cache it. PassFF on Firefox (or see github passforios for iOS) or command-line tools (easily can build hooks with dmenu/rofi as well).
pass stores the gpg-encrypted passwords in a Git repository. Set up a private remote repository and push to it for offsite backup. There is some leakage of info as the names of the sites become the filename, e.g., ycombinator.gpg. This can be mitigated with some plugins like tomb, but then PassFF and passforios won't work.
Or pass if your only on unix'es ;)
It's not just great FOSS software, it's just straight up great software.
There were a ton of usability headaches in the core application too. The UI was quite unintuitive.
It may be technically great, but that's just one dimension of greatness.
IMHO The UI of the Linux app is ok, not grate but very usable. The Android app I think is worse though.
Failing to fill auto-fill is in my experience 100% to blame on the website in question. It happens more often then with some commercial alternatives. They just don't have the same amount of resources to work around websites doing stupid quirky things with password input fields. Which websites would stop doing quirky password input field stuff.
True, and also recommend by the EFF:
I switched to KeePassXC on one of my laptops and it seems OK but requires more clicking to access and autotype a username and password. I haven't switched on any other devices. Still undecided.
By itself, Passwordstore will not encrypt file names or directory names (which by convention represent the names of the service/site you have an account with).
That might not pose a problem if no one else has access to the machine that hosts your git repo, but if that's not the case (even if it's a private repo on whatever platform), you might want to use either Tomb or git-crypt-remote to have full end-to-end encryption. There are even some tools that glue tomb and pass together (https://github.com/roddhjav/pass-tomb for one), though I'm not sure what's the situation is like when it comes to mobile integration with tomb/git-crypt-remote.
It’s like suggesting to encrypt public keys.
Wouldn't that same argument suggest that that encrypted DNS queries should not be something one would want to use?
My point is - it's nothing like that, I'm sure that most people could think of at least one website at some point in their life where they'd want to keep the knowledge of them having an account with that website private.
I've compiled a huge list of issues to convince them. Like no audit logs. No password complexity enforcement. No single password sharing with third parties (you have to give them the entire thing and password or create a new one which they can open forever). No central overview. We have no idea how many passwords are stored, how well they are secured (the master password) and who they are shared with and when.
Has anyone found a good argument to convince your leadership? And what did you move to?
But most of my concerns are centered around the fact that it's just files not centrally managed.
I wonder, aren't the majority of HNers working at a for-profit company funded by VCs?
The hypocrisy is just intolerable at this point.
Doesn't mean they agreed with their employers decision.
Doesn't mean they don't complain about it when their company does it.
Doesn't mean they don't raise complains internally with their employer.
But what do you expect?
They quitting their job about this, many can't afford it.
They mentioning how bad their employer is too every time they complain about a different company? That would be just annoying (close to) no one wants that.
Sure some people which also work for much worse companies wrt. such properties and are not currently looking for a different employer are hypocrites.
But so what? Better voice your complains even if you don't act on them then to not even voice your complains and just accept bad things. (Sure acting on them would be even better, way better.)
I don't agree with that. At best, they should resist bad ideas, and at the very least, they shouldn't b!tch about them on HN when someone else does it.
Since you're also using a keyfile to encrypt it, it doesn't matter if another party gets the db file and even your passphrase, since only a device that also has the physical keyfile can decrypt it.
The only thing it suffers from is that it looks too complicated for casual users.
This is where 1Password or BitWarden really shine.
At my current work, we have a lot of credentials to test environments shared on one single keepass file and I am wondering if I could securely use it as a network accessible (VPN only) vault and ideally something I could programmatically fetch those credentials for CI.
years later, its wonderful. they have EVERYTHING there and on their phones. they they dont need to keep the data synced at two places since they only use their phone so they keep a live copy on it and occasionally keep one with me just in case something happens to the phone.
it is a bulletproof setup that works. recently someone mistyped a password and i was like "dont you have keepass" and i was told "obvio"... that was nice.
the secondary improvement is by making it convenient to use and in turn discourage people from putting their passwords on sticky notes
I sync two databases across Mac, linux, ipads, and android phones. One for work, one for personal.
you can improve fool proving by watching the db file for change and then uploading it
you can further improve it by checking if the uploaded file is the one which was there when you did download it last and only then upload your changed version
but yes, for many people that simple approach would be good enough by far I mean how often do you add new passwords?
I mean you can only run into a problems when you change it in two devices without sync in between. But that is super unlikely (in general; if you have reliable internet; you can improve reliably of this setup by syncing to a kind of server/file storage as "source of truth" as it won't be e.g. out of battery or disconnected from the internet ;-) ).
And as long as what you use for syncing doesn't blindly overrides when conflicting syncs happen you can resolve the problem by hand, not that I would expect it to happen. (At least with KeePassXC this works well, I haven't use keepass as most places strongly recommend XC over keepass without XC.)
Now using KeePassium Pro. Very happy. Does everything I need, uses the file API for opening files and integrates well.