KeePass: OpenSource Password Manager
keepass.info
keepass.info
Until I came across this: http://www.zx2c4.com/projects/password-store/
It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to come into existence. I am not associated with the project, but these are just a few things I love about "pass"
1. Command-line based: which means I can script it, I can run it remotely, etc.
2. Uses Git to store the passwords: full revision history, changelog, and remote push/sync features that git is SO good at. Other password managers have to reinvent that whole wheel and none seems to do a good job. This also eliminates the need for "hosted" solutions - which I just simply refuse to use.
3. GPG for password encryption: once again, such a natural, awesome way to do things. GPG is already the safest way practical way to secure data-at-rest. I can rest easy that no silly homegrown encryption system was invented. Also, as long as I have the keys, in the worst case I can do the decryption myself, if I do not have access to "pass".
The only thing I believe it might lack is the fact that the names of the entries are in the clear. Which means I cannot setup a github(private) repository as remote for my pass store: the passwords themselves would still be gpg encrypted, thus safe, but the repository will leak names of all websites and userIDs.
In anycase, kudos and thanks to the devs!
And on the web, all the other password managers have browser extensions to autofill data from their own database, but every common browser already does password storage and autofill natively. So once I grab a password from pass the browser remembers it anyway, making extensions unnecessary.
Oh, and the other thing I LOVE about pass is that because it uses GPG, the key encrypting all the data can be held in a nice portable smartcard, since GPG supports them directly, and it all just works when my smartcard is plugged in. I use a yubikey neo with openpgpcard applet for this and it's been great.
I did start writing an OS X dropdown menu for accessing my passwords from pass, but I haven't been in such a hurry to get it done because it doesn't seem all that necessary in practice :)
Consider encrypting the filenames with Fuse+EncFS. This flaw is pretty huge elsewise; it's why I changed to using gnupg.vim+SublimeGPG.
I would also be surprised if someone somewhere hasn't already written an "autotype" layer over pass, but thats not something I am personally interested in.
I do agree that for end users this may not be the case. For non-technical people (my parents, for example), I mostly recommend writing their passwords down on paper. They have very few passwords as-it-is, and almost none of them are critical.
My own use case, where I have literally hundreds of pieces of info I need to secure (passwords, key-files, gpg keys, ssh keys, etc), is very different from that of such users. Hence different tools.
Oh, also, "pass" can copy the password to the clipboard, making the copy-paste scenario trivial. In fact, it goes even further by clearing the pass from the clipboard after a preset time.
Never used roboform - its not available for linux, so can't comment there.
Does anyone know if there is a lib to read and write into keepass archives programmatically, e.g. from a C# app? that would be quite useful to manage in an automated way some credentials for production systems, sharing tha archive via versioning repos in a team.
Although since I am studying C#, VB and Java I would be interested to find out the answer to that.
The source[1] is also on GitHub too. As a non-c++ programmer, I found it pretty easy to follow along.
In fact, I usually just copy the password with Ctrl-C and the username with Ctrl-B. You can configure a secure clipboard erase after n seconds.
One thing I really wish had better support is ssh-based entry-level sync of databases[1]. Keepass has a plugin for it but I don't know the status for KeepassX 2 (currently in a non-stable release state). If I could point KeepassX at an SSH remote path and have it transparently sync at the entry level it'd be almost perfect.
This is mostly because I don't want to have to deal with copy-pasting my password between the KeePass app and the browser (where most of my passwords are needed). Luckily, there are autofill plugins that exist for Chrome [1], Firefox [2], and Android [3].
However:
- said plugins work with KeePass2 which on Linux the GUI theme to the point of being almost unusable (as a C# app using WinForms, it doesn't respect GTK/Qt themeing well).
- getting the KeePass2 plugin needed for the browser plugins requires jumping through hoops on Linux and I haven't gotten it to work (yet?).
- I'm sharing my KeePass database on DropBox (with its own security considerations...) to synchronise between the different systems and...
- The Android app just won't open the shared database.
So it feels like I'm 60% of the way there, but I still don't have a usable system. Hints appreciated.
[1] https://chrome.google.com/webstore/detail/chromeipass/ompiai... [2] https://addons.mozilla.org/EN-us/firefox/addon/passifox/ [3] https://play.google.com/store/apps/details?id=com.hanhuy.and...
For android, I recommend Keypass2Android: it comes with a custom keyboard you can enable temporarily, which inputs your password without going through the android clipboard. I use it with the dropbox app as well, I'm not sure why it's not working for you.
I need to give KeePass2Android a try.
Personally, I don't like the idea of browser plugins and I'm perfectly happy using copy and paste.
[1]https://play.google.com/store/apps/details?id=com.android.ke...
KeePassX has similar "auto-fill" functionality as well. It's not as perfect or as seamless as LastPass but it is definitely usable (after a bit of one-time per-site tweaking in some cases). Having recently decided that using LastPass presents a non-zero risk, the extra effort I have to spend w/ KeePassX is certainly worth it, IMO.
Although I don't do it now, I have in the past kept my password databases in Dropbox. With Dropbox also installed on my iPhone, I am able to access my password databases use "MiniKeePass" on iOS without any issues.
In addition, there are Windows, Linux, and OS X versions of KeePassX and all of them can open up my .kdb files without any issues.
Another opinion: It's weird loading a browser+environment for non-browser passwords (SSH, HTTP/WebDAV, etc), and it's equally weird managing the passwords separately.
Why the switch? Recent revelations WRT NSA & the iPhone, recent reports of other plugin developers selling their plugins to shady actors, and my general belief that the most sensitive credentials I have are safer on machines under my control instead of "in the cloud".
I work for an ISP and also manage systems and networks for schools, government organizations, health care facilities, investment firms, law offices, you name it. If someone were to gain access to all of my stored credentials, they could do a LOT of damage -- to myself as well as many, many others.
While I have no reason to believe that there's anything wrong with LastPass (from a security point of view), I am certain that the level of risk is lower with, i.e., KeePassX.
LastPass user here, wondering why?
I have the LastPass plugin installed in Firefox, which I use 95% of the time. I also have the mobile app installed on my iPhone.
Why the switch? Recent revelations WRT NSA & the iPhone, recent reports of other plugin developers selling their plugins to shady actors, and my general belief that the most sensitive credentials I have are safer on machines under my control instead of "in the cloud".
I work for an ISP and also manage systems and networks for schools, government organizations, health care facilities, investment firms, law offices, you name it. If someone were to gain access to all of my stored credentials, they could do a LOT of damage -- to myself as well as many, many others.
While I have no reason to believe that there's anything wrong with LastPass (from a security point of view), I am certain that the level of risk is lower with, i.e., KeePassX.
Plus I wouldn't trust any browser plugin with passwords
The algorithm is very roughly base64encode(hash(password + domain)), and then truncated to match your original password length.
The form on the site is just a demo (and backup if you need to use it outside of your own browser). What you really want is the extension (for most major browsers). You can type in the same strong password to every site and the extension will always hash it to the site specific password so you don't have to worry about them storing it poorly. You can also use unique master passwords for certain sites, if you so choose.
* A site may be able to compromise the browser extension.
* You have to memorize several passwords because sites require different length passwords.
* The code has been reviewed less.
* A key-store like KeePass can store many original passwords, not just one hashed password.
* It doesn't have a non-browser app, so I had to copy paste passwords from the browser, while KeePass has Alt-Ctrl-A.
From looking around it seems like the reason is that they wanted the visual representation of typing the password to reflect the number of characters you actually typed as you type them. I'm not sure if this comes out true, though, as I can't actually get it to work in chrome.
>Sure, but as long as the site actually sets the password length limit on the field it shouldn't matter.
Yes, but in my experience sites rarely implement this. If they do, it's probably inconsistent (i.e. different limits on the login field, create account, and reset password fields).
Re password lengths, my experience is that they usually truncate on the server side at that point, rendering it pretty moot. But yes, I do see this problem. I'm just not sure you're not going to run into it either way if you're practicing good password hygiene. I'd still prefer it make an attempt at adding as much difficulty to the password as possible, though.
1) It doesn't have to be compiled or installed, since it's just a monolithic HTML page with all JS/CSS inline.
2) It has a free, optional hosted service that stores encrypted passwords with pure client-side decryption, so you can get your passwords from any web-enabled device without having to trust the host.
This is an unbelievably audacious security shell game; I can't really believe this nonsense idea has somehow managed to gain traction.
The server is ephemerally delivering the code that supposedly encrypts your content securely.
How do you not have to trust the host?
By saving the HTML file and opening your local copy. You can audit the code and verify yourself that nothing will go over the wire unencrypted to their servers, so you get the benefit of them hosting the encrypted passes without having to trust them with your data. If you want it available anywhere, you don't want to save the file locally, and you don't trust the host, just host it yourself or grab it from Github.
You would have to audit it to ensure it never includes everything else, or posts anything externally with every release.
Not my cup of tea, personally.
What Java? It's a self-contained, monolithic HTML file with JS and CSS inline. What dependency are you imagining you're not going to have?
> You would have to audit it to ensure it never includes everything else, or posts anything externally with every release.
Exactly as you would with KeePass, or any other conceivable solution. If you don't want to audit future releases, save the last one you audited and use that.
Really, auditing this is impossible.
If you can't get a copy of Firefox that you trust hasn't been altered as part of a conspiracy to make you believe OneShallPass is a legit password manager, you've got bigger problems.
Additional features: - It works offline. - You can import or export your passwords in CSV form. - If you choose to delete your account, it is immediately and irrevocably destroyed.
The obvious and huge difference then would be that KeePass requires a password or key file to open but an HTML page requires only a browser or text editor. Major, major difference to me.
Did you spend even two seconds looking at OneShallPass? Literally the second thing on the page is a field asking for a passphrase, and yet you came here to complain that it doesn't require a passphrase.
The passwords are encrypted. The fact you can read the decryption algorithm in your text editor doesn't let anyone know your passwords, any more than you being able to download and read the source of KeePass lets you read other people's KeePass passwords.
It makes me wish there was an open standard for sites to negotiate a new entry with a password manager, something automatic in the background for new registrations.
Site could send password restrictions, like allowed and required character types, minimum length, even maximum length, though that last one would be frowned upon. The locker would reply with a preferred username and random password and add same to the database upon acceptance.
http://www.techdirt.com/articles/20130620/15390323549/nsa-ha...
At times, it contributes to what I call "log in anxiety" in that it necessitates opening the program, and inputting a password to get my other password. But no one ever said the extra security was synonymous with convenience.
And I dont leave it open, nor do I allow it to store any information in browser plugins as this seems counter productive to the sensitive passwords I use in this program.
* Spend some time learning the Keyboard shortcuts and you're all set.
* Keep the Keepass File on Dropbox, so it's sync across your machines and is backed up.
* Sharing common credentials with a team - server login details, team site details etc - have a common Keepass File on Dropbox and share it with your team. Suggestion is to open it as "read-only" unless you're adding new entries.
* You can also have an additional layer of security by using an additional (optional) Key Locker File (besides the main password) to lock Keepass. You can have that on a thumb-drive or some place you know.
* One thing I really wish 1Password has what Keepass has is the auto-generation a password when you enter a new entry. One can set parameters of what password is generated. I have click to get that in 1Password.
P.S. If I remember correctly, Keepass even has a portable version.
Does anyone see any security issues with supporting on a website allowing the user name and password to be entered together in one field? The normal way of entering the user name into one field and the password into another would continue to work. The site would simply check and if the user name field content is blank, and the password field content has a space in it, the password field content will be assumed to actually be the user name and password together, separated by a space.
The idea here is that you'd then be able to enter both the user name and the password with a single copy/paste operation. This would be convenient when using a password manager on an iPad. I sometimes get tired of having to do this:
1. unlock password manager
2. copy user name
3. switch to browser
4. paste user name
5. switch back to password manager
(If using most paranoid security settings, insert another step of "unlock password manager")
6. copy password
7. switch to browser
8. paste password
If the website supported my single-field option, I could just set the password manager to stop the computer user name and password is the password field, and then it is only unlock/copy/switch/paste.
Great software, everyone should be using password vaults.
It's a sort of wishful, hopeful approach to password security, really.
I wouldn't recommend using it yet, but any feedback would be super helpful.
I'm syncing it via ownCloud for as a testrun (https, non-US site) and it works fine. Not sure I ultimately want to do that via the cloud though. Might just switch to using a USB stick especially since merging DBs works pretty well.
edit: I wasn't sure if KeePassX had a Windows port -- it does and I downloaded it to replace KeePass at work with.
1. Clients available on web and/or all platforms, must be able to add/copy to clipboard passwords on all platforms. 2. Synced or Shared database between all clients. 3. No subscription cost (upfront cost OK).
Nice-to-have things would be browser plugins, command line interface etc., but that isn't essential.
Overall keepass is far from perfect and lacks polish, but it's good enough for most purposes, and doesn't require an internet connection, which opens more use cases (keeping banking info or wifi passwords for instance)
For example say on PC-A I make a change and save it. On PC-B I have the old database still opened and loaded in KeePass. What happens if I then save in PC-B without opening the database up? That means I just lost the one password?
I've been comfortable storing my database in Dropbox, with a decent length master password (15char+) on the assumption that it uses a high quality hash that would make bruteforcing the encryption impractical, without having to add another layer of encryption above it. Curious if others feel this is a reasonable assumption?
Now I just have to trust the security of btsync
I realize KeePass has they key advantage of being open source, but we have good UX :)
Very interested in your thoughts...
UX isn't a big win. KeyPassX is good enough i.e. works with keyboards entirely, is open source, is reviewed, goes to extra lengths not to leave stuff floating around in RAM as well. Oh and works across all platforms I use.
https://www.schneier.com/passsafe.html
It is convenient enough - and when it comes to such sensitive digital areas, then I defenitely prefer to take a conservative position over cloud based and client side encrypted solutions.
I like how it [the .kdb file, really] can be accessed//written_to in both Linux and Windows, and that it has a usb-portable version.
Very happy with the combination.
Edit: my above comment is just to prove a point. We put trust in a lot of the software we run. Software being open source does provide some safety, but very very few people will go through the effort to make that verification.
I use 1.x mostly as a backup.