Setting up KeePassXC is trivial.
Setting up KeePassXC is trivial.
It is a tool that does one thing really well.
It is trivial to sync the password db. You can use whatever you prefer.
> "I have a working, synced password manager across my devices with good security practices."
Well, using Lastpass or any other third party to store your passwords was never good security practice.
Is that actually something the average person needs? Do they create new accounts ever day or week that they need to have on all device immediately? Merging DBs is like a 2 minute exercise at best.
I would argue the friction is a good thing. "Do I actually need to give yet another website information about myself for an account?" The answer is no more often than not.
Yes I know people don't care but those who don't are not using a password manager.
1. It has lots of features and complexity, but doesn't always convey affordances for common use cases to the user.
2. Some of the UI design feels very incrementally developed (naturally), and the implementation a bit quirky in parts.
(For one of many examples, when I had to do something involving adding TOTP secrets, once I found where to add them, I had to be careful in which sequence I clicked things, or it would just discard the secret I already put in the right place. If I hadn't been watching carefully, I might not have noticed immediately that it did this, and not been able to restore the secret before it was lost.)
Of course, in an ideal world, one would like to do a great holistic rethinking of the UI design (while preserving the data model), but that's a ton of work.
When advocating it to a "technical" person (who is not scared of, say, a legacy IDE), I would say it might do everything they need. When advocating to an ordinary user, I would look at their use cases, and see what they are going to see, and how confusing or quirky that might be for them.
If I keep a KeepassXC database on a set of devices, sync'd using syncthing, then for a large range of threats I'd need to be a target of interest.
This is in contrast to LastPass which is going to attract a ton of blackhat attention.
Yes, supply chain attacks are possible but they're equally possible for lastpass.
Switching to a self-hosted solution isn't perfect. Nothing is, and pointing that out isn't particularly useful.
What it does do is eliminate whole class of threats: large scale, broad based attacks against a single, high value target.
In fact I'd argue writing passwords down in a notebook or putting them in a naked text file on your computer is better than trusting a centralized service like LP.
Of course, if you are a target of interest, the calculus changes entirely.