floss.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
For people who care about, support, and build Free, Libre, and Open Source Software (FLOSS).

Administered by:

Server stats:

685
active users

Ade Malsasa Akbar

Which free software password manager do you use?

Please share your recommendation. Boost is very appreciated.

I use . What about you?

KeePassXC - Cross-Platform Password Manager

KeePassXC is a modern, secure, and open-source password manager that stores and manages your most sensitive information.

keepassxc.org

@ademalsasa In fact, I use 2 password managers :

- KeepassXC for personal use
- Vaultwarden linked to Bitwarden client for in our association

@angedestenebres @ademalsasa

Let me take s moment to ask you...

I use .kdbx too - #KeepassDX and #KeepassXC to sync between #Android, desktop, with cloud, using #Syncthing.

How do you find compatibility between #VaultWarden and #kdbx in regards to the "notes" section in those #Keepass clients?

I thought about doing a migraine, or at least a parallel management of them, but I rely heavily on my "notes" section for many particulars and reminders for my various accounts.

Thanks!

#tallship

⛵

@tallship I didn't migrate any data, there is no link between my KeepassXC & Vaultwarden.

Anyway, there is also a possibility to add notes in Vaultwarden / Bitwarden, see screen.

@ademalsasa

@ademalsasa enpass, sync to my iphone and mac

@ademalsasa KeePassXC in combination with #Syncthing is a dream. You do not need a cloud but all your devices are still synchronized.

@ademalsasa Also using KeypassXC in combination with an own, private Nextcloud Instance.
Sharing Passwords via different Files.

@ademalsasa if you use KeepassXC and want to support the team, they have listed a few methods on their website, including a Patreon account.

@brthur thank you very much for mentioning this. Boosted.

@ademalsasa currently, I'm on Dashlane.

Since they removed the desktop app for a browser only solution, thought, I am thinking to move away. I admit, I've never took enough time to find a different solution that suits my needs though.

@ademalsasa Enpass, with a background sync between devices

@ademalsasa I use Brave, can sync my password across devices.

@ademalsasa I've been using Bitwarden for quite some time now and recommend it. The UI works great for me, not only in the laptop browser but also on my phone.
As soon as it will work with PostgreSQL I will start running my own installation of Bitwarden 😎

@ademalsasa KeePass 2.x Portable with an automatic DB backup plugin.

@ademalsasa I use Keychain on my Mac - very effective.

@ademalsasa I use Apple/iCloud’s built-in password manager. In addition to that I use 1Password, which has been pretty good.

@ademalsasa
I primarily use Chrome's password manager for unimportant website passwords, and Bitwarden for important passwords and things that Chrome doesn't do, like remembering 2fa recovery codes and random account recovery answers

@ademalsasa password manager and generator on microsoft edge 🥲

@ademalsasa@floss.social Personally I use self-hosted Bitwarden. In my work, I use and recommend Keepass to everyone 😉

@szkodnix @ademalsasa what do you use so sync with all your devices? I read the some people use #Syncthing.

@edmonde@home.social @ademalsasa@floss.social I personally did not have any problems with sync thing passwords so I am not aware of the problem oO

@szkodnix @ademalsasa no problems, it works fine after a little set up. 😊

@ademalsasa i use pass with passf firefox extention but the extention is kinda mid since it doesn’t have a function to automatically add passwords to the password store when creating new account/signing in for the first time and i have to add every passwords manually
but besides that its alright

@deblan @ademalsasa I used to use Passman in Nextcloud, but switched to KeePassXC (but still use Nextcloud to sync it between my devices).

@ademalsasa I want something completely offline so keepass

@ademalsasa honestly, I don't use a password manager. I have tiers of passwords I use for different levels of importance on accounts, such as accounts for banking, accounts that have my credit card attached, my main email. That all have their own tiers of passwords based on their importance. And if one site gets compromised and my password for a tier gets leaked, I just reset password on that tier, and login to my email with the password I made just for it, and change em all.

@ademalsasa
Passman, its an add-on for nextcloud. Didn't intend to use that one passfically, but honestly worked well and been pretty convinient

@dd0ul hello, I'm an avid KDE user and it's very nice to find a KDE Kwallet user here. Greetings and thanks for your recommendation.

@ademalsasa I use KeePassXC for my personal passwords, because it's easy to sync with my phone. I use pass (the standard Unix password manager) for my work passwords, because it's easy to back up and rewind changes thanks to its Git integration.

@ademalsasa @df4or gibts auch zusätzlich als App für iOS und droid. Opensource, selber zu hosten, crypto transparent per gpg. Was will man mehr?

@ademalsasa I use firefox password manager. It’s nice, it let me sync between my desktop, iphone and ipad easily.

@avolkov @ademalsasa I used lockwise, which was their password manager until last year, when they discontinued it with a rather quiet memo. I had to switch to #lastpass (damn) and stopped using Firefox altogether. Now I'm setting #keepassxc up and it works just fine after a few adjustments.

@ademalsasa firefox pass, it's already on all my devices and it works without issues

@carlschwan thank you for your recommendation, Carl. I also use it.

@newsorpigal @ademalsasa Also GPG encrypted text files.

I recently learned that that is precisely pass's file format -- so maybe I'll swich between vim and pass as tools.

@chrysn @newsorpigal @ademalsasa
Using vim+gpg sounds interesting. Are you concerned about temporary files, copypaste buffers, history files, ... accidentally leaking passwords somewhere into storage?

Not meant as criticism. I'm simply curious about your setup and how you've solved those potential leaks (if you did).

@toe @newsorpigal @ademalsasa These are valid concerns; in rough order:
* Really important stuff uses certificates anyway
* I somewhat trust the gpg vim plugin not to litter tempfiles, and to a lesser extent not to leak data through other channels.
* Buffers ... well, the "+ buffer (system clipboard) is how I get my data out, and that's readable by any X11 application. One more reason not to use passwords, really :-)

@toe @chrysn @ademalsasa

You have to disable automatic backups, otherwise there will be unencrypted copies of the passwords.

@newsorpigal I don't think so -- AIU, the vim GPG plugin doesn't create temporary files on disk during decryption, and it turns off viminfo, swap and undo files before loading a GPG file.