Keepassxc/keepassdx, synced with syncthings/basicsync.
Using a headscale/tailscale setup so things stay synced even when i am not home.
Keepassxc/keepassdx, synced with syncthings/basicsync.
Using a headscale/tailscale setup so things stay synced even when i am not home.
nice try hax0r
Bitwarden
BitWarden and a self hosted VaultWarden
Remember the password to my email. Create account on site. Log in and remain logged in. When eventually logged out click forgot password. Log into email and click reset link.
A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.
The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.
One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.
What do you use on a phone?
Syncthing-fork from Fdroid.
There were some repository ownership questions a few months back that were ironed out. In addition, Fdroid vets apps far better than Google ever has so I'm comfortable with the app's security.
I moved away from Bitwarden because they removing values from their motto and some other shady stuff. I chose to go with AliasVault, it has a pretty nice alias email feature.
Keepass2
Vaultwarden - self hosted bitwarden server that any bitwarden clients can connect to.
Firefox remembers my passwords. For other things, text documents stored in a Veracrypt container
Idk if this is the right choice but I write them down on a piece of paper and store that paper in my locked fireproof safe.
1Password family account with spouse, kids, and my parents. Vault management, ease of sharing, and remote management for my parents is nice, along with multiplatform for everything important, and the price feels quite reasonable at $1/user/month. No major security incidents ever, and I was pleased by their core service design whitepaper that I read many years ago. But as they’ve become increasingly corporate over the past several years I’ve felt like they care less and less about individual users, and the CEO’s recent pledge to Omarchy really pissed me off. So it’s been a great service for me but I don’t recommend it for new users unless they like nazis. I pay for a year at a time so I haven’t scrambled to migrate my family to a new solution quickly, but it sounds like Vaultwarden is most likely the way to go next.
Seconding Bitwarden, have been with it since my previous one (Lastpass? I forget, it was red) moved most of the good functionality behind a paywall many years ago. 11/10 I usually pay for the subscription, I like their product and want them to have a little walkin' around money. But currently on the free tier which is perfectly fine (2 devices when I used pro for 3, but I hardly use my laptop.
I use online bitwarden for unimportant accounts and offline keepassxc for important ones.
I'm an old man yelling at clouds but I don't trust any of the password storing technologies. I have a system of making/writing passwords and a save a short form of them on my pc. Without knowing a specific segment you'd never be able to guess what they were so the segment is the only thing I need to remember. Having to access accounts when not at home is a massive pain in the ass though lol
Selfhosted Aliasvault
Mostly with a mooltipass. I also save them in a keepass db that is only written to a thumb drive, for redundancies sake.
I stick to brain based. I have a system that makes it easy for me to remember which password is for where. Step one is to use passphrases instead of password. Obligatory reference: xkcd correct horse battery staple
I use several tools depending on context (keepass for work accounts, a custom hosted solution for everything else). But I also have a system for my passwords that allows me to figure out what it should be in case I forget. Most of my passwords follow a specific pattern that incorporates the platform and a series of characters.
This specific implementation is now out of date, as it's not really necessary (or at least it shouldn't be) to have all the special characters; length should be the critical property of a secure password, but unfortunately many, many sites still require a mix of upper/lower/numbers/special chars. Regardless, it should still be simple to come up with a way for you to know your passwords, without them all being the same.
all 41 comments