155 points

I guess now is as good a time as any for them to start using a proper password manager.

Personally, I recommend Keepass - it has multiple clients for all platforms, and you can keep the file in sync with a program of your own choosing, like Dropbox, syncthing or whatever you like.

permalink
report
reply
62 points

Bitwarden is probably a more pragmatic choice for most users, given that it’s free and without having to manage the syncing yourself.

Any password manager is better than the alternative, though.

permalink
report
parent
reply
-3 points
*

I’m not sure what you’re comparing it to. Keepass is free too, in fact it’s open source. In my opinion, local software and database that is under your control is always superior to cloud.

Keepass over Bitwarden offers a lot of plugins and integrations, again, if you want more customization or automation.

But, I would say you can use any online password manager as long as it’s end to end encrypted, so Bitwarden is a good choice.

permalink
report
parent
reply
28 points

I think your bias may be showing. The average computer user doesn’t even think about using a password manager. It just exists and works in their browser.

permalink
report
parent
reply
18 points

Also, local software and database is always superior to cloud.

Now there’s an unfounded blanket statement if I ever saw one.

permalink
report
parent
reply
3 points

No dislike for Keepass here, but I prefer Bitwarden. It’s also super easy to self host with Vaultwarden.

permalink
report
parent
reply
57 points

Keepass XC on PC, Keepass DX on Android, Syncthing to sync database

Works flawlessly!

permalink
report
parent
reply
21 points

Most amazingly, this setup is also unexpectedly resilient against merge conflicts and can sync even when two copies have changed. You wouldn’t expect that from tools relying on 3rd party file syncing.

I still try to avoid it, but every time it accidentally happened, I could just merge the changes automatically without losing data.

permalink
report
parent
reply
11 points

How did you enable merge conflict resolution for KeePassXC databases?

permalink
report
parent
reply
1 point

I store my DB in Dropbox and use KeePass2Android on phone which has built in Dropbox sync.

permalink
report
parent
reply
1 point

Yeah but then you have to trust Dropbox

permalink
report
parent
reply
34 points

Vaultwarden ftw

permalink
report
parent
reply
17 points

Exactly! Self hosted FTW. Chances of a data breach… Typically pretty minor if you are smart.

permalink
report
parent
reply
20 points

Chances of losing the data is higher with selfhosting too. Unless you’re doing some sort of multizone replication, or course.

permalink
report
parent
reply
2 points

Keep vaultwarden behind wireguard for local only access then also use https certs and good master password. Very secure like this

permalink
report
parent
reply
7 points

+1 for a self-hosted Vaultwarden instance. If you’re technically capable and have extra hardware laying around this is the best way to go.

permalink
report
parent
reply

Although a backup is still required or you are gambling on hardware outliving your need for your data.

permalink
report
parent
reply
5 points

Shoutouts to paper and pen.

Keep the booklet in a safe place.

permalink
report
parent
reply
21 points

If you never, ever need your passwords outside of your home, that’s great advice - it’s as secure as can be against digital theft. Less so against fire though, and backups are out of the question.

permalink
report
parent
reply
13 points

I just store all my passwords in robots.txt on my web server, makes it easy for me to access them anywhere I go…

/s

permalink
report
parent
reply
4 points

Backups are easy? Just copy to another piece of paper and store somewhere else.

I’m just being facetious though.

permalink
report
parent
reply
3 points

I have a firesafe at home for important papers, passports and some emergency cash. I keep my passwords there.

permalink
report
parent
reply
2 points

You can have backups of physical books. Just copy the text from one to the other. Yeah it is manual work but so is writing the first one in the first place. You can then store the second copy in a fire resistant safe or at a friends or family members house (maybe inside a safe as well).

permalink
report
parent
reply
1 point

Well you can write a copy and keep it in a shed if it’s unlikely to also catch fire.

permalink
report
parent
reply
5 points

Typically, the drawer just below the keyboard (in my experience)

permalink
report
parent
reply
2 points

If it’s my mother, post it notes stuck to the laptop…

permalink
report
parent
reply
0 points

Hopefully someone in the house is supposed to be there, or they just take the TV.

permalink
report
parent
reply
3 points

This is the first suggestion here that’s actually within the technical abilities of most people, even most Lemmy users.

The level of technical knowledge some of people here seem to think the general public has is absurd.

permalink
report
parent
reply
2 points

I’m usually the one promoting technical literacy to all but in this case I honestly don’t use a password manager.

permalink
report
parent
reply
0 points
*

If getting a Dropbox account is too difficult for them, I seriously wonder why they’d be subscribed here, or reading articles about password management in browsers.

permalink
report
parent
reply
0 points

Never trust your credentials to a private company, they could be bought out by state actors.

permalink
report
parent
reply
1 point

Never trust your credentials to yourself, you can be bought out by beer, poor decisions, and tripping over the cables connected to your home server you cobbled together.

permalink
report
parent
reply
0 points

The xz compromise having demonstrated that FOSS projects are totally immune to interference from state actors…

permalink
report
parent
reply
1 point

Right that’s why you shouldn’t trust those either

permalink
report
parent
reply

I put all my passwords in a text document, then print it on a little strip of paper and shove it up my ass. Whenever I take a crap, I dig it out from the turds and try to memorise some of them again. Then I shove it back up there where noone else can find my data and I won’t lose it.

permalink
report
reply
209 points

Ah yes, KeepAss

permalink
report
parent
reply
11 points

Spectacular

permalink
report
parent
reply
4 points

I’m scared of downloading after that Mexican party

permalink
report
parent
reply
75 points

sh.itjust.works

permalink
report
parent
reply

Forgot to mention I delete the text document and set fire to the computer’s hard drive. The passwords are only ever in my ass, with the rest of my personal shit.

permalink
report
parent
reply
22 points

Following up your own shit post with another shit post is shit post gold.

permalink
report
parent
reply
5 points

This tracks very close to my idea of the suppository flask stick.

permalink
report
parent
reply
3 points

Have you ever tried anal, my beautiful gentleman?

permalink
report
parent
reply
3 points

Sounds like a security risk.

permalink
report
parent
reply

Maybe, but it would have to be personal and in my ass if I had or ever did.

permalink
report
parent
reply
103 points

Bitwarden here. Works well.

permalink
report
reply
85 points

No $10 gift card?

Lame.

permalink
report
reply
77 points

“Chrome users” or “Chrome under windows users” would be closer to the truth. Still, quite a screw up.

permalink
report
reply
12 points

Something like 2/3rds of the world uses chrome for desktop. I’d bet that number is higher for windows specifically. If you’re the rare person who doesn’t use chrome then you’re savy enough to know this doesn’t apply to you

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 18K

    Monthly active users

  • 11K

    Posts

  • 506K

    Comments