• @Plagiatus
    link
    1231 year ago

    I second the recommendation for Bitwarden.

    I switched over from Dashlane and never looked back. They even have a browser extension for mobile Firefox (the browser you should be using anyways) so it’s easy and convenient on all my devices.

    • @[email protected]
      link
      fedilink
      English
      411 year ago

      +1 for Bitwarden. There were growing pains at the start to move off of iCloud Keychain. Once done and being more proactive with managing passwords it’s so good and trustworthy

      • @[email protected]
        link
        fedilink
        141 year ago

        Agreed. Bitwarden has been fantastic. I just wish it was easier to swap between accounts on the browser extension. You can do it on desktop and mobile pretty easily.

      • @swiffswaffplop
        link
        English
        31 year ago

        Is there another way than just going back and forth and manually putting them in?

        • Otter
          link
          fedilink
          English
          31 year ago

          Manually putting what in?

          You can import from another service if that’s what you mean

        • @[email protected]
          link
          fedilink
          English
          21 year ago

          First time using it you export your password data and move it into BW. Then browser extension can help auto fill and detect new ones. It also has a password generator built in so that’s handy

          Phone app can integrate and auto fill. On iPhone I’m not sure it if can detect and save. But the few times I’ve needed to sign up on phone I manually input.

          I still use Firefox password and iCloud saves when prompted. Doesn’t hurt to have a backup I suppose.

        • @SmoothLiquidation
          link
          11 year ago

          I spent some time when I migrated from just storing my passwords in Chrome. I went through and made sure all of them were strong, unique passwords. I set up categories for all of them. I set it up so I could share the right ones with the family and whatnot.

          Doing the raw import is easy, but it was a good time to make sure everything was in order.

    • Otter
      link
      fedilink
      English
      141 year ago

      Is there a reason to use the mobile extension over the app itself? The app can input into other apps as well

      • @Plagiatus
        link
        11 year ago

        Don’t know honestly - I’ve never tried the app so I don’t have a comparison. Didn’t even know they had one.

        • @[email protected]
          link
          fedilink
          English
          21 year ago

          The app is nice if you want to use bitwarden to login to other appa. You can allow it permission to run alongside other apps that can fill in login forms.

      • @[email protected]
        link
        fedilink
        11 year ago

        I have never even got the mobile extension to work. When I set it up and enter in my email and master password, the Captcha that is supposed go show up is missing entirely. There is just a blank space under the password field where the Captcha is supposed to have appeared.

        IMG_20230910_152738

        • @Asudox
          link
          11 year ago

          If you have a custom DNS or VPN, that might be blocking the CAPTCHA.

  • @thisisawayoflife
    link
    581 year ago

    Been using KeePassXC (and before that, KeePassX) since I abandoned LastPass about a decade ago. The apps integrate with Nextcloud perfectly and at least for me, it’s a breeze. I use it for TOTP too, and I second the recommendation of a hardware token for an additional layer of security. There are some USBc options that work on phones (I’m using a pixel 7 pro).

    • jelloeater - Ops MgrA
      link
      English
      51 year ago

      I never got YubiKey to work on desktop with it. Key files seem to work good enough and easy to manage.

      • Rootiest
        link
        fedilink
        English
        6
        edit-2
        1 year ago

        YubiKey works for me, both on desktop with KeePassXC and on Android with KeePassDX to the same DB

        • @chockblock
          link
          31 year ago

          I like the look of KeePassDX but I was bothered by the fact that I have to use the yubikey every single time to unlock the database, unlike keepass2android which allows me to store the yubikey credential with biometric lock until the phone restarts. Keepass2android is not as nice of an app but that feature was really required for me.

          • Rootiest
            link
            fedilink
            English
            31 year ago

            KeepPassXC can do this as well, but it does require the yubikey to be inserted every time you want to save a change to the database.

            Look under Settings -> Security -> Convenience -> Enable database quick unlock (Touch ID/Windows Hello)

            Using that I can quick-unlock my database using my laptop’s fingerprint scanner, just like how KeepPassDX works on Android.

            • @chockblock
              link
              31 year ago

              its not a huge issue on KeePassXC because I keep a yubikey nano plugged into my laptop, but for my phone, I haven’t been able to make this work reliably with KeePassDX. I’ll have to give it another go.

              • Rootiest
                link
                fedilink
                English
                21 year ago

                Ah yeah you are right, it makes me tap my key every time I open the app.

                The biometrics seem to only replace the master password.

                I do wish it worked more like KeePassXC where the key is only needed to save the database after unlocking and confirming with fingerprint

      • @chockblock
        link
        41 year ago

        It does require some configuration within yubikey manager. I did not find it straightforward but once set up its really reliable.

    • FlumPHP
      link
      fedilink
      21 year ago

      I’m curious about using the same store for passwords and TOTP. Technically if someone gets screwed to your database, they have both your factors, yes? But I guess it does thwart someone trying to brute force your password.

      • @thisisawayoflife
        link
        3
        edit-2
        1 year ago

        Adding a hardware key, like Nitrokey, would be an additional level of safety there. I would not use the database without some kind of additional key (something you know and something you physically have).

        If there’s something nefarious that has user access, you’ve already lost in that regard.

          • @[email protected]
            link
            fedilink
            21 year ago

            This is what I do: I have 3 KeepassXC databases (regular passwords, “security” questions, TOTP tokens) each with a different password.

      • Amju Wolf
        link
        fedilink
        English
        11 year ago

        Technically you do lose the second factor, but nowadays 2FA is often mandatory or they force some crap like SMS/email verification onto you. If you are aware of the risk then it isn’t a huge deal.

        Though you might want to consider not using it at least for the most important stuff like banking (here you don’t even have an option; banks have their own 2FA apps that you have to use) and primary/recovery email.

  • downpunxx
    link
    fedilink
    511 year ago

    when lastpass screwed around with it’s free tier offering, i switched to bitwarden and haven’t felt any reason to use or even try anything else, it’s rock solid

    • @Bye
      link
      English
      71 year ago

      Same. Been very happy. Great iOS integration.

    • @glorious_albus
      link
      English
      31 year ago

      Exact same boat. It was so easy to migrate from lastpass, I didn’t even feel any friction.

  • @SuddenlyBlowGreen
    link
    461 year ago

    +1 for BitWarden.

    Plus, it’s ridiculously easy to self-host with VaultWarden.

  • mub
    link
    fedilink
    371 year ago

    Bitwarden - does everything, and is free. You can even setup a shared vault so 2 people can have access to shared stuff like online shopping and streaming sites. Takes a bit of admin work but it is not hard.

    • @[email protected]
      link
      fedilink
      English
      81 year ago

      Sadly that second but requires the other person to care enough to make an account and not just text you when they need the password 😂

      • @[email protected]
        link
        fedilink
        English
        11 year ago

        Just send a photograph of your screen showing the requested password of 25 random characters so they have to type it out. Guaranteed their next question will be where they sign up for an account.

        • @[email protected]
          link
          fedilink
          English
          11 year ago

          lol that’s generally what I do. Sometimes I’m nice enough to copy and paste. We don’t share a lot of accounts so it’s not a huge issue.

  • Polar
    link
    fedilink
    28
    edit-2
    1 year ago

    Proton Pass pisses me off. Proton is such a money grubbing company that takes FOREVER to release stuff.

    I pay $120 per year for ProtonMail, and they want me to pay $180 to unlock the full Proton Pass. $60 per year, for something that BitWarden does for only $12 per year.

    Not to mention you’ll be waiting years for apps to come out. They’re such a fragmented company. The Android remake is already so far past the estimated release date it’s sad. Proton Drive Windows app finally came out, but fuck Mac and Linux users, I guess.

    BitWarden is available for Windows, Linux, Mac, 9 browsers, iOS, Android, and CLI. - Premium is $1/month.

    ProtonPass is available for iOS, Android, and 4 browsers. - Premium is $5/month.

    Can’t wait for Proton to release a few more half baked services with outdated apps and a promise to update them in a year, but then 3 years later there’s still radio silence. Perhaps use your paid services money for developing in a timely manner? Holy shit.

    • @Asudox
      link
      3
      edit-2
      1 year ago

      It’s actually 10$ a year.

        • @Asudox
          link
          1
          edit-2
          1 year ago

          I meant the Bitwarden premium sub.

          • Polar
            link
            fedilink
            11 year ago

            Well ya, but I’m not American, so it’s not $10 for me.

            • @Asudox
              link
              11 year ago

              It’s also 10€ per year if you live in the EU.

              • Polar
                link
                fedilink
                11 year ago

                That’s because Euro and USD are similar. That’s how currency works. It’s not $10 where I live lol.

      • lckdscl [they/them]
        link
        fedilink
        English
        41 year ago

        Also why would someone who want enhanced privacy put all their eggs in the basket by trapping themself in Proton’s ecosystem. Compartmentalize is important, and it ends up being cheaper too. Proton’s pricing is cutthroat.

    • @jaegernut
      link
      21 year ago

      I agree with the fragmented part. Even their apps have different unlock interfaces, like they’re each made by a different company

    • @workerONE
      link
      21 year ago

      I’m using proton mail for free, paying like $12 a year for proton pass.

        • @workerONE
          link
          11 year ago

          That’s interesting. Looks like I received an email to get 75% off and I signed up using that

      • Polar
        link
        fedilink
        21 year ago

        Not the point.

        Paying for something is great. Not allowing paying customers to add a simple service without having to upgrade to the next tier, forcing them to buy shit they don’t want, is scummy.

  • @[email protected]
    link
    fedilink
    English
    251 year ago

    Wow, so 1Password is not recommended anymore? How come? I’ve been using them for years.

    • @[email protected]
      link
      fedilink
      16
      edit-2
      1 year ago

      Possibly because it is not open source and doesn’t have anything to offer that the other recommendations do not.

      • @Sigma_
        link
        English
        191 year ago

        Ya I think so. These are always tech articles and Foss software is always a big feature.

        But 1password has on going audits and a sane ui and mobile apps that pass the boomer-parent test. Canadian company too which is nice given the US centric tech world.

        • @[email protected]
          link
          fedilink
          11 year ago

          I use it because I share an account with my parents, so I can manage their stuff. My fathers old local Pw-Manager was a mess.

      • @[email protected]
        link
        fedilink
        61 year ago

        Fastmail integration for masked emails! If you already have an email provider you like then yeah not much to offer. But if you’re like me a few years ago and was looking to get off of chromes password manager and gmail, then 1password and fastmail is a nice combo.

        • @[email protected]
          link
          fedilink
          4
          edit-2
          1 year ago

          Bitwarden has integration with Fastmail, as well as for many other alias services (anon addy, SimpleLogin, etc). They also just added support for selfhosted anon addy, and are working on adding support for self hosted SimpleLogin.

    • @[email protected]
      link
      fedilink
      71 year ago

      It’s in their honorable mentions.

      Have no source available clients is the author’s main nit pick.

      • @Belazor
        link
        English
        51 year ago

        Which personally I think does a disservice to their readers. If their article ends up high in search results for “best password manager 2023” for whatever reason, most people aren’t going to care if there’s a source available client or not.

        Dash lane and 1Password might not have source available clients but they likely have better UI/UX than these more open source alternatives that are made for people with technical expertise.

    • @[email protected]
      link
      fedilink
      71 year ago

      Former 1password user, current Bitwarden user. Jumped ship when 1password dicked local vaults. Never been happier.

      And it’s a FUCKLOAD cheaper. 1password is very overpriced.

      • @[email protected]
        link
        fedilink
        41 year ago

        Bitwarden is practically free. You can pay for some extra features but all the core features and unlimited passwords storage works. Nobody should pay for a password manager.

    • @haulyard
      link
      51 year ago

      Same. We’ve been using it for about a decade I think. One vault for my wife and I to share. Hosted on their end in case all our self hosted stuff takes a crap our passwords are still available. Been considering looking at bitwarden but haven’t had the time.

    • @[email protected]
      link
      fedilink
      2
      edit-2
      1 year ago

      I’ve been thinking about trying it… I like Windows Hello integration which seems to easily break in Bitwarden

      • @Belazor
        link
        English
        11 year ago

        I can personally recommend 1Password, the Windows Hello integration works really well. Asks for your PIN code to unlock (or your master password after a reboot). If you put your computer to sleep rather than turn it off overnight, you won’t need the full master password.

        Also, if you’re so inclined, 1P has an excellent CLI tool you can use for accessing vaults programmatically. I use this for auto filling TOTP codes for my Final Fantasy XIV login.

  • @[email protected]
    link
    fedilink
    231 year ago

    I use KeePass and keep it synced with self hosting Nextcloud. I get the appeal of bitwarden, but I’m really trying to get off other people’s computers.

    • @[email protected]
      link
      fedilink
      61 year ago

      Bitwarden with the self hosted vaultwarden server then, that way you get the nice bitwarden experience, apps, browser plugins, but all hosted on your own hardware. I run my vaultwarden server on my synology.

    • @dack
      link
      31 year ago

      Syncthing is another good cloud-free option.

    • Mac
      link
      fedilink
      English
      31 year ago

      Vaultwarden can be easily hosted for free

    • Orionza
      link
      English
      11 year ago

      KeePass for me for the same reason.

  • Landor Dragen
    link
    fedilink
    English
    211 year ago

    Bitwarden. Tried Proton Pass but ultimately stuck with Bitwarden.

    It has been my password manager of choice for quite some time and I didn’t see any reason to change.

  • @Linus_Torvalds
    link
    101 year ago

    While I find a discussion about password managers great, I found the article to be underwhelming.

  • Concetta
    link
    fedilink
    81 year ago

    15 years ago the common logic was the most likely way for a password to get stolen is by writing it down and leaving it in an accessible spot, and somebody stealing the password there.

    I don’t think that logic holds anymore, and with the LastPass breach I think that’s proof you want to step away from the cloud not towards it. Imo the most secure way to store passwords is to generate multiple random codes, use a portion of each and then just write those down.

    • Rouxibeau
      link
      81 year ago

      15 years ago you had to worry about the people around you. Now you have billions of bots trying to force shit all the time.

    • @[email protected]
      link
      fedilink
      3
      edit-2
      1 year ago

      You can also use a password manager that’s not connected to a cloud. Or an encrypted usb stick. The problem with writing it on paper is, that people tend to use too short passwords or repeated passphrases. Using a really long master key and a key file with an encrypted database is safer than a cloud.

      • @[email protected]
        link
        fedilink
        31 year ago

        Usb sticks corrupts damn easily. Even faster carrying them around. Learnt that the hard way.

        Or does anyone know about an usb stick that is practically immortal, that they can recommend?

        • Redeven
          link
          31 year ago

          NVME ssd in a carry usb adapter. It’s as reliable as a regular ssd, but it’s way more portable and durable than commercial external hdds. A little bigger than usb flash drives but worth the tradeoff. Wouldn’t use it as the only backup place for a password dB file but for carrying around its pretty good.