top 50 comments

sorted by: hot top controversial new old
[–] 111 points 3 years ago (13 children)

I second the recommendation for Bitwarden.

I switched over from Dashlane and never looked back. They even have a browser extension for mobile Firefox (the browser you should be using anyways) so it's easy and convenient on all my devices.

  • source
  • hideshow 13 child comments
  • [–] 41 points 3 years ago (5 children)

    +1 for Bitwarden. There were growing pains at the start to move off of iCloud Keychain. Once done and being more proactive with managing passwords it’s so good and trustworthy

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (4 replies)
  • [–] 56 points 3 years ago (16 children)

    Been using KeePassXC (and before that, KeePassX) since I abandoned LastPass about a decade ago. The apps integrate with Nextcloud perfectly and at least for me, it's a breeze. I use it for TOTP too, and I second the recommendation of a hardware token for an additional layer of security. There are some USBc options that work on phones (I'm using a pixel 7 pro).

  • source
  • hideshow 16 child comments
  • [–] 5 points 3 years ago (9 children)

    I never got YubiKey to work on desktop with it. Key files seem to work good enough and easy to manage.

  • source
  • parent
  • hideshow 9 child comments
  • load more comments (3 replies)
  • load more comments (5 replies)
    [–] 54 points 3 years ago (3 children)

    when lastpass screwed around with it's free tier offering, i switched to bitwarden and haven't felt any reason to use or even try anything else, it's rock solid

  • source
  • hideshow 3 child comments
  • load more comments (2 replies)
    [–] 45 points 3 years ago

    +1 for BitWarden.

    Plus, it's ridiculously easy to self-host with VaultWarden.

  • source
  • [–] 43 points 3 years ago

    Bitwarden gang

  • source
  • [–] 43 points 3 years ago (3 children)

    Bitwarden - does everything, and is free. You can even setup a shared vault so 2 people can have access to shared stuff like online shopping and streaming sites. Takes a bit of admin work but it is not hard.

  • source
  • hideshow 3 child comments
  • [–] 37 points 3 years ago

    Bitwarden, Been using it since 2021

  • source
  • [–] 29 points 3 years ago (6 children)

    I’ve settled in with Keep Ass myself.

  • source
  • hideshow 6 child comments
  • [–] 28 points 3 years ago* (last edited 1 week ago) (25 children)
    load more comments (25 replies)
    [+] 27 points 3 years ago (4 children)
  • load more comments (2 replies)
    [–] 25 points 3 years ago (13 children)

    Wow, so 1Password is not recommended anymore? How come? I’ve been using them for years.

  • source
  • hideshow 13 child comments
  • [–] 16 points 3 years ago* (4 children)

    Possibly because it is not open source and doesn't have anything to offer that the other recommendations do not.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 5 points 3 years ago

    Same. We’ve been using it for about a decade I think. One vault for my wife and I to share. Hosted on their end in case all our self hosted stuff takes a crap our passwords are still available. Been considering looking at bitwarden but haven’t had the time.

  • source
  • parent
  • load more comments (3 replies)
    [–] 23 points 3 years ago (7 children)

    I use KeePass and keep it synced with self hosting Nextcloud. I get the appeal of bitwarden, but I'm really trying to get off other people's computers.

  • source
  • hideshow 7 child comments
  • [–] 6 points 3 years ago

    Bitwarden with the self hosted vaultwarden server then, that way you get the nice bitwarden experience, apps, browser plugins, but all hosted on your own hardware. I run my vaultwarden server on my synology.

  • source
  • parent
  • load more comments (3 replies)
    [–] 22 points 3 years ago
    [–] 22 points 3 years ago

    Bitwarden. Tried Proton Pass but ultimately stuck with Bitwarden.

    It has been my password manager of choice for quite some time and I didn't see any reason to change.

  • source
  • [–] 10 points 3 years ago (3 children)

    Self-hosted bit warden works like a charm plus you get to learn reverse proxies if you use docker on a Nas, it's pretty fun, would recommend

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 8 points 3 years ago (2 children)

    LastPass did not make the list, I am shocked, shocked, well ok not that shocked.

  • source
  • hideshow 2 child comments
  • [–] 8 points 3 years ago

    While I find a discussion about password managers great, I found the article to be underwhelming.

  • source
  • [–] 8 points 3 years ago* (last edited 3 years ago) (5 children)

    I made a hardware-based password manager that I keep on me with the 3-2-1 rule. (One on me, one at home, one in a remote location) It's barely-secure, but the data is not accessible except when I'm updating it. It's similar to the mooltipass but all the passwords are stored on eeprom.

    Could the eeprom be hacked by someone and all my passwords probably read in cleartext? Yeah. How many fucking people actually know how to do that though? Virtually none.

    Honestly, I'd love to just simply be able to afford a mooltipass though. :(

    This is what I based my personal one on: https://www.instructables.com/PasswordPump-Passwords-Manager/

    And I usually generate the passwords with an online tool so that I'm never using the same password twice.

  • source
  • hideshow 5 child comments
  • [–] 21 points 3 years ago* (3 children)

    Why not keepass and its editors and just keep the vault file on a flash drive?

  • source
  • parent
  • hideshow 3 child comments
  • load more comments (1 reply)
    [–] 8 points 3 years ago (4 children)

    15 years ago the common logic was the most likely way for a password to get stolen is by writing it down and leaving it in an accessible spot, and somebody stealing the password there.

    I don't think that logic holds anymore, and with the LastPass breach I think that's proof you want to step away from the cloud not towards it. Imo the most secure way to store passwords is to generate multiple random codes, use a portion of each and then just write those down.

  • source
  • hideshow 4 child comments
  • load more comments (3 replies)
    [–] 8 points 3 years ago (3 children)

    GNU Pass, has been the best one so far. Set up your own git to sync it to all devices.

  • source
  • hideshow 3 child comments
  • load more comments (3 replies)
    [–] 7 points 3 years ago (2 children)

    have being using Enpass for a long time, it’s really good, you can choose any cloud provider or host your vault yourself, subscription based payment or one time only

  • source
  • hideshow 2 child comments
  • [–] 6 points 3 years ago* (1 child)

    I am also using Enpass since a decade or so and never had the urge to switch to another provider. Everything works, you got all the features (TOTP, pawned password auto-checks, native apps and autofill, storage of other things than passwords; …) and pricing is still very reasonable.

    It can be fully used offline too (with WiFi sync) or with any local storage or online cloud option.

    I bought it one time back then but still pay the small subscription fee since I don’t want Enpass to go away.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 7 points 3 years ago

    Your homegrown script opening a gpg encrypted file in runtimedir in a text editor.

  • source
  • load more comments
    view more: next ›