On Linux and Windows, KeepassXC is my software of choice. On Android, I like (and have donated multiple times to) https://play.google.com/store/apps/details?id=keepass2androi...
With the cloud storage setup (which, in my case, happens to be Google Drive), I always have the most recent version of my password safe(s) where I need them to be.
With this, my major threat exposure comprises of * the cloud provider losing my data, letting an aggressor get hold of my (encrypted) password store(s) - and then the aggressor brute-forcing * I myself losing my password store data to an aggressor * I myself losing my password store credentials to an aggressor
I am explicitly not using any of the online password providers simply because they are by themselves a much too valuable target. I myself, hopefully, am not valuable (or visible) enough, and therefore am not subject to "at-scale" attack patterns.
I find this one nice, there's no need for a password manager to have Internet access when the database is synced with a separate client (in my case Nextcloud).
I mean this in all seriousness: how have you stayed on Lastpass after the innumerable breaches? There's "my weekends are not best spent exporting and importing csvs" and then there's borderline criminal negligence of credentials one pays a company to keep safe
I mean, it's your life, I'm just genuinely curious how that calculus plays out
And none of the breaches have resulted in password loss if you used a strong pass phrase.
All the talk about PBKFD2 iterations has been about preventing loss when you used a weak password.
The same brute forcing for the most part also applies to keepass if you host your vault in ways that someone could access.
I don’t love Lastpass in anyway, but let’s not pretend that there was outright catastrophe.
It was bad that servers of a popular password manager with millions of users were compromised. The security controls were bad: a lastpass engineer had access to critical credentials in the same machine that he watches Plex open to internet (and possibly more).
It was bad because a lot of users don’t have strong master passwords, and their vaults are at risk. Also, insufficient pbkdf2 iterations did not protect well against brute forcing the vault. Sure users should use strong master passwords as much as possible. But a weak password would not have been a problem if the servers had not been compromised.
It was bad because a lot metadata has been leaked, that can be useful in further attacks.
A compromised server could also push a malicious update to the users and steals master passwords.
When you use cryptography you go through all the hassle exactly so you don't have to have a panic attack when a company behaves stupidly.
- It turns out a lot of the vault isn’t actually encrypted
- Some vaults used weak, breakable encryption
- The browser extension could be tricked into decrypting data for malicious parties
Encryption isn’t an on/off thing, it’s only as good as its implementation.
Also, this isn’t “zero knowledge” encryption, it’s end to end encryption.
On a few devices that never connect to the same wifi i use tailscale to connect Syncthing.
Using an additional shared secret on a folder allows you to sync a folder to an untrusted device, which then itself only sees encrypted files.
The learning curve to understand all the moving pieces and the initial setup can be more hassle than many are willing to put up with, but after the initial legwork is done, adding new devices is not that much more complicated than what it is on paid services, and using it is as simple as any of the popular services, IMHO.
Pass is a short bash bash script (very little code). It passes the encryption to a dedicated utility GnuPG (out of which only the AES and cv25519 routines are used).
You should use smart card to store the GPG key. Every touch of the security key gives out only one password. So if you copy the HN password, other passwords such as your bank password is not at risk.
The missing part is integration with browsers, which increases the attack surface (although it’s minimal here, since only one password is at stake), but protects against phishing.
Pass probably doesn’t need an audit, since you can just read the script.
Only if you disregard that pass doesn't encrypt file names.
Gopass does encrypt file names too.
Also, I don't know if other people do this, but I don't actually use the pass scripts, and instead have my own scripts for managing things that just happens to be very similar to pass. I extend it in whatever ways I want to.
If I cared about this issue I would probably consider putting the passwords in a file system on a loopback mounted luks volume backed by a regular file, or maybe just store them in a different format altogether.
I do realize that the average user doesn't want to bother with all of this and wants something that "just works".
Not manually, and not only for this file: this is a system I have to sync the files I want in different machines, by running a little program I wrote (https://gitlab.com/jordibc/csync just in case). I would use syncthing otherwise, but this system has several advantages for me.
If I hadn't access to an online server, I'd use some cloud storage for the same thing.
i've been running this scheme where i keep the "live" DB on my phone so any change i need to do, i do it on the phone and every often i sync or copy it to the laptop.
this has served me well for like the past 6-9 years so i guess it works. You definitely do not need an online service.
its not like passwords change like crazy. i've had entries that i only change because of stupid password reset policies (every 4 months for example), other than that, i only update the DB if i add a new entry.
You can then choose at some later date to migrate to self-hosting or not.
The kbdx file is encrypted, so given a strong password it should not matter how secure the app for syncing the file is. Most people seem to use it with syncthing.
For people without need for sharing, use cloud storage. Make sure to use an app that protects from writes from different clients though.
For people with need for sharing, you are doomed. (e. g. Family sharing)
Device B -> git pull from remote repo
¯\_(ツ)_/¯
The Android pass app is developed and distributed by the same person who maintains the Android wireguard app iirc, otherwise I probably wouldn't have trusted it!