While I fully agree with you, how do you sync passwords across my 3 laptops and 3 phones without a SaaS offering?
While I don't use this feature, but it is common for ppl to share an account. How can I securely share credentials with family members?
While I fully agree with you, how do you sync passwords across my 3 laptops and 3 phones without a SaaS offering?
While I don't use this feature, but it is common for ppl to share an account. How can I securely share credentials with family members?
Syncthing. Set up once, runs reliably forever.
> How can I securely share credentials with family members?
I don't do this either (and don't know anyone who does) but I imagine it'd be easy to just create a different shared database for the family for that? With password store, it's also possible to set multiple different gpg keys for a specific directory. I don't think the last option is doable for most people though.
> it's also possible to set multiple different gpg keys for a specific directory. I don't think the last option is doable for most people though.
this seems really complex...
keepassxc + syncthing this is the way
android: keepassdx off f-droid + syncthing
> this seems really complex...
Like I said, it's probably not a solution for many. A second database with shared secret is very straightforward and transparent way that anyone can grasp I think. It would definitely pass the family test for me.
Anything more important than a Netflix account you don't share at all. If they need access, just call them.
Small startups use password sharing tools to share passwords with new employees (think db passwords or other saas accounts). This happens at least a once per month in a 10 person organization.
Maybe the answer is, you can't. Write them down, text each other, call each other and read it over the phone.
Making a spare key for my parents to get in my house isn't "click a button easy," I have to go to the hardware store -- and maybe THAT'S the appropriate level of difficulty.
Again, what many of us are saying is third party password managers are always a bad idea for fundamental reasons. Before, it was just the account owners and the site. Now there's a third party that has some kind of access, and that third party is a juicy target.
Under what guarantee then? Why believe they are safe, especially since time has shown that many are not.
It's dumb, and I will continue to maintain that it's dumb right up until one of these companies offers indemnifcation or some other serious grown-up guarantee.
I will pay for your service if and only if you pay me if/when you mess up.
if you are tech savvy, like to keep up to date on security and are ok with the hassle of setting up a NAS, sync stuff and know how to keep it secure, perhaps. If you had to pay me to do it for you, a few dollars service fee might be much cheaper...
With 1Password 7 I did this with their built-in local syncing feature. I don’t want my passwords in the cloud. I’m happy to manually sync them once a month (or probably less these days). But they removed it in version 8 and forced users into a subscription so I’m not upgrading. Eventually I’ll move to something else, but it’s still working for now.