How do you manage your passwords?
Brain-based management is getting too exhausting, and isn't even fully possible with a larger quantity of online accounts.
Syndicated from the fediverse. Read and engage on the original instance.
View original on lemmy.sdf.orgBrain-based management is getting too exhausting, and isn't even fully possible with a larger quantity of online accounts.
76 replies
Bitwarden
keepassxc
Bitwarden
To further this, if you actually move over to any password manager please regenerate all of your duplicate passwords with something 20+ characters. It’s almost pointless to have a PW Manager if you’re using the same weak password everywhere.
Make a new strong password for your master password too; I’d recommend a phrase of four moderately long words like “BattleshipMonitorPaintingPrinter” and perhaps a little postit note doodle drawing to remember it until it’s hammered home.
Alternatively, writing down the master password somewhere secure, like in a safe, would also be good if you have to pass on important accounts to descendants.
Or a USB with a Gpg encrypted text file locked with a slightly easier password.
That's my reason for wanting to switch to a password manager. Everything gets some long random string that would be insane to type anyway. Or using passkeys, if supported, though I'll have to research how that works.
My biggest problem is backups. I like the method of Aegis authenticator. It just stores some number of past (encrypted) databases. Each change is a new file. This way rsync takes care of both backups and version control. If I accidentally rsync a corrupted file, it doesn't matter much. And I can verify them with Rhash, just like all files that don't change (like photos).
I'm fairly sure you can self host Bitwarden, so it might be possible to have backups in a similar way
I think Vaultwarden is the self-hosted version
I ask AI to make me a random password for "x" service. Whenever I need to remember it, I just ask again \s
Vaultwarden
I've already seen someone do that, a certain family member. At first I found it funny when they asked an LLM about their WiFi password, which was some gibberish. But it worked. There's no way something like that would be default across entire product line.
Indeed, when I asked, I got "I gave it screenshots of everything because I didn't know what to type where".
pass: the standard unix password manager for tech-savvy people. It's dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.
with that you need to type the unlock password for every single read and search, right?
No, you can configure the timeout in
gpg-agent.conf. I've set mine to a few hours.I use KeePass database for all my passwords and other database for recovery passwords (like from 2FA codes etc). I have it synced in my Nextcloud and ProtonDrive (In case my Nextcloud would fuck up).
KeePass database in cloud storage, synced to my phone.
I write down a password hint on a physical piece of paper.
Since the primary threat vector is remote access and not physical access, I'd argue that is fine.
Additionally the password hint has to pass through several thought chains in order to provide the actual password.
I do wish sites would up front tell you what the password requirements were when you logged in though.
Self host. Keepass, NAS with a sync app across devices. Occasional manual backup. Probably overkill.
Nice try
With gnupg, git, and a hardware security token. Also known as "pass".
A bit of a tangent but these are the right people to ask... What do you think when a site or app says that your password is too long?
I think the site stores my password in its original form, without hashing. its way too common, even at high profile services like banks, university or government systems.
I'm glad they told me and didn't just truncate it forcing me to reset everytime.
Keepassxc/keepassdx, synced with syncthings/basicsync.
Using a headscale/tailscale setup so things stay synced even when i am not home.
I use Password123$ everywhere.
Mostly i get by by not telling others how or where I keep my passwords
Do you add 1 and then ! or ! And then 1 to secure your passwords?
keepassxc
Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.
Vaultwarden - self hosted bitwarden server that any bitwarden clients can connect to.
Have you considered trying pass phrases? Weirdly, they can sometimes be easier to remember depending on where you take it from.
Proton Pass for me since I use their VPN.
Vaultwarden for selfhosting.
BitWarden and a self hosted VaultWarden
Fun part of that sollution is that you only need one app.
You also need a secondary service on your server if you want to keep them in sync.
Keepass2
Have this as my backup just in case bitwarden goes somewhere. I tried to run it as my daily but, it just doesn't feel nice for some reason.
Piece of paper.
A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.
The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.
One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.
What do you use on a phone?
Syncthing-fork from Fdroid.
There were some repository ownership questions a few months back that were ironed out. In addition, Fdroid vets apps far better than Google ever has so I'm comfortable with the app's security.
I agree but they aren't checking every version for malicious changes. they would likely only get to know if a user checks it and notices it, and the developer could just make the change for a single release version.
of course that applies to any app but this handover/takeover was very sketchy.
Oh, sorry, I meant the password manager. There's multiple KDBX compatible apps.
KeePass2Android. Recommended by KeypassXC.
My dumbass reading through these comments: "keep ass... ehehehehe"
1Password family account with spouse, kids, and my parents. Vault management, ease of sharing, and remote management for my parents is nice, along with multiplatform for everything important, and the price feels quite reasonable at $1/user/month. No major security incidents ever, and I was pleased by their core service design whitepaper that I read many years ago. But as they’ve become increasingly corporate over the past several years I’ve felt like they care less and less about individual users, and the CEO’s recent pledge to Omarchy really pissed me off. So it’s been a great service for me but I don’t recommend it for new users unless they like nazis. I pay for a year at a time so I haven’t scrambled to migrate my family to a new solution quickly, but it sounds like Vaultwarden is most likely the way to go next.
Remember the password to my email. Create account on site. Log in and remain logged in. When eventually logged out click forgot password. Log into email and click reset link.
That was what I did 20 years ago
Seconding Bitwarden, have been with it since my previous one (Lastpass? I forget, it was red) moved most of the good functionality behind a paywall many years ago. 11/10 I usually pay for the subscription, I like their product and want them to have a little walkin' around money. But currently on the free tier which is perfectly fine (2 devices when I used pro for 3, but I hardly use my laptop.
My journey as well. Paid for LastPass (bought 10 years for $20) and changed when they went too much shit.
I don't particularly trust any password manager. If it can be breached, possibly, has been or a chance to be breached, then I don't trust it. I have a document of passwords locked behind a VeraCrypt container hosted locally. I trust nothing in the cloud or some remote program.
That's fair, but you've lost the ability to log access attempts for individual services, timeout sessions etc.
There are completely selfhost options for this
zx2c4 pass
Idk if this is the right choice but I write them down on a piece of paper and store that paper in my locked fireproof safe.
Not very user friendly, but not wrong either
Definitely the most secure!
Bruteforcing a safe might be easier than a password manager.
Once physical access is achieved you have already lost. They can just brute force your brain. A safe is perfectly fine for the usual remote attacker.
It really does depend on your threat model, yeah?
Firefox remembers my passwords. For other things, text documents stored in a Veracrypt container
I'm an old man yelling at clouds but I don't trust any of the password storing technologies. I have a system of making/writing passwords and a save a short form of them on my pc. Without knowing a specific segment you'd never be able to guess what they were so the segment is the only thing I need to remember. Having to access accounts when not at home is a massive pain in the ass though lol
Basically the same. But not stored in a computer
1Password
nice try hax0r
1Password, but planning to move to VaultWarden.
I moved away from Bitwarden because they removing values from their motto and some other shady stuff. I chose to go with AliasVault, it has a pretty nice alias email feature.
Self hosted vaultwarden
Vaultwarden
I use online bitwarden for unimportant accounts and offline keepassxc for important ones.
I have a notebook and an app called Password Generator from f-droid
I stick to brain based. I have a system that makes it easy for me to remember which password is for where. Step one is to use passphrases instead of password. Obligatory reference: xkcd correct horse battery staple
Selfhosted Aliasvault
iOS password manager.
Post-its
I don't.
Mostly with a mooltipass. I also save them in a keepass db that is only written to a thumb drive, for redundancies sake.
I use several tools depending on context (keepass for work accounts, a custom hosted solution for everything else). But I also have a system for my passwords that allows me to figure out what it should be in case I forget. Most of my passwords follow a specific pattern that incorporates the platform and a series of characters.
This specific implementation is now out of date, as it's not really necessary (or at least it shouldn't be) to have all the special characters; length should be the critical property of a secure password, but unfortunately many, many sites still require a mix of upper/lower/numbers/special chars. Regardless, it should still be simple to come up with a way for you to know your passwords, without them all being the same.