Hy,

In your opinion do you prefer Bitwarden or Proton Pass and why?

It seems proton pass have better integration with Firefox.

Good and bad?

Thanks.

  • @jplate8
    link
    English
    431 year ago

    Am I a boomer for still using KeepassXC synced via Dropbox?

    • @Synchrome
      link
      English
      6
      edit-2
      11 months ago

      deleted by creator

    • Zeta
      link
      fedilink
      51 year ago

      KeepassXC + SyncThing in my case, to skip the middle man (Dropbox/Google drive)

    • @TORFdot0
      link
      English
      41 year ago

      No sir, I did this for years. I used Kypass on my iPhone so I could use my passwords on my phone as well. I ended up switching to Bitwarden for easier 2FA implementation and granular password sharing rather than having to share my whole vault or manage a separated shared vault

      • @jplate8
        link
        English
        21 year ago

        What kind of 2FA setup do you have?

        • @TORFdot0
          link
          English
          11 year ago

          I use Bitwarden with DUO as my Authenticator app. I know that you can set up keepass with 2FA via an extension but I didn’t find it as portable with my existing apps which is why I decided to make the switch

    • ShellSurf
      link
      fedilink
      41 year ago

      Nah, still a great solution if you like. That was my solution for years until just about a month ago I switched to bitwarden because it seemed easier to protect with a yubikey. I’ve liked it so far.

      I took the opportunity to export all my passwords from Firefox, chrome, and KeePass, then spent about a day cleaning the whole mess up and removing duplicates, THEN imported the csv into bitwarden. Still getting used to not using chrome/Firefox for auto filling and storing passwords, but I like that my passwords don’t feel so spread out across multiple browsers/dbs.

    • Atemu
      link
      fedilink
      English
      31 year ago

      It works but partitions can and will happen and a merge afterwards is non-trivial AFAIK.

      • @jplate8
        link
        English
        51 year ago

        I just trust the built-in encryption, which makes it easier to read via keepass2android (since I don’t have to do an extra decryption step).

      • @Synchrome
        link
        English
        2
        edit-2
        11 months ago

        deleted by creator

          • @Synchrome
            link
            English
            2
            edit-2
            11 months ago

            deleted by creator

            • @[email protected]
              link
              fedilink
              English
              31 year ago

              Interesting. I assumed it did, two layers of encryption, different passcodes and ideally keys - not sure how it wouldn’t, but now I need to research it

              • @[email protected]
                link
                fedilink
                English
                4
                edit-2
                1 year ago

                These are my opinions, not a security expert or anything but - if your system is compromised two layers won’t make a difference. If someone gets ahold of the KDBX, two layers might slow them down but if they have the compute to crack the KDBX in the first place a second layer won’t make a difference, even if you’re using a stronger algorithm.

                I can only think of two benefits.

                1. using two different algorithms adds a layer of protection in the event a flaw is discovered.

                2. If it’s wrapped it would likely have a different extension and signature, so if someone were to say, hack the cloud storage provider and grab all the KDBX files you might get missed.

                In any case, the encryption algorithms we use today will likely be irrelevant and useless at some point in the near future. If you suspect your KDBX has been stolen, you should change all your passwords - even if they can’t crack it today, you don’t want to get an unpleasant surprise in a decade because you didn’t.

                Although changing your passwords on interval is a good security practice anyway.

                I also wouldn’t sync them with a cloud storage system either, since you never know.

              • @Synchrome
                link
                English
                2
                edit-2
                11 months ago

                deleted by creator