2023 was a record-breaking year for cybersecurity in a bad way. Ransomware payments hit a record high of $1.1 billion, which is likely to…
BitWarden
and/or Vaultwarden as a selfhosted alternative.
Vaultwarden is a great piece of self hosted server software, which meshes with Bitwarden software perfectly. And for people who can’t self host, IMO Bitwarden gives you more than enough bang for your buck with their own hosting plans.
It’s one of the few examples of software being open source and ethically making money regardless. (For comparison, Standard Notes has tried pretty hard to make sure non-paying users have an inferior experience even if they self-host literally everything.)
<$1/mo for bitwarden hosted premium is a no brainer for me
I was really disappointed about standard notes’ plans. Took me forever to get everything set up to self host, only to find I couldn’t even use markdown unless I bought a license? Silly.
Yeah, the value of buying a hosted service should be the fact you don’t have to worry about hosting it yourself. Not a tiny piece of Javascript that was grabbed from a third party developer anyway.
I can see what they’re trying to do, but the experience leaves a really bad taste in my mouth.
I’m excited that the bitwarden phone apps are getting a brand new native version for ios and Android soon.
Tried, and not a fan of. The organizing features are kind of not what I expected. Sticking to KeepassXC for now.
I actually thought the organization stuff is pretty good, coming from keepassxc myself. The way we have it set up is that each of the members of our family all have VW accounts, and we have a common organization shared among us for stuff we all use (e.g. home devices). It’s all in one installation, so it’s pretty convenient. I don’t think I can do the same as easily with keepass.
That being said, keepass is a really solid piece of software. I’d recommend it myself.
I’m curious, what features is it lacking that you want to see?
First is the organizing feature. It doesn’t let me to have sub folders which I need to categorize items.
Second is the TAN management to store my MFA backup codes. A feature the original Keepass have but KeepassXC doesn’t. You can use notes to mimic but it doesn’t auto expire after use, i.e. more manual work.
Bitwarden + aegis for everything possible.
Authelia or authentik for self hosted stuff.
pass.
Is Keepass there? Good. Upvote.
Prefer KeepassXC but let’s be honest, the best password manager is the only you actually use and keep using.
And that doesn’t get hacked!
Everything gets hacked given enough time. Just not everyone says they were hacked or realised they were.
Prefer KeepassXC
Why? Keepass has lots of plugins and XC doesn’t, right?
KeepassXC looks better IMO. Also I like that hardware keys work without plugins. Personally I still use KeePass for one feature that XC doesn’t offer.
I would only use KeepassXC
+1 For KeepassXC, I use it in combination with syncthing to have my passwords available on all devices.
Nextcloud syncs my KeepassXC safe.
Syncthing for me, but Nextcloud has its advantages too.
Same for me
Been using that same setup and very happy with it.
I use Bitwarden for passwords. Just works so well.
KeepassXC and KeePassium for TOTP codes. I keep the database in the cloud but sync a key with Syncthing that’s needed to unlock the database on the devices themselves.
Locally hosted bitwarden (vault warden) that is only accessible on your local network is the way to go. When a new sync is needed away from home, wireguard VPN to connect back in makes everything nice and secure. Otherwise most of the time the vault is cached to the device locally so you don’t need to phone home to access passwords.
I do it exactly like that, except that im connected via vpn most of the time, since my pihole is also located in my lan
Exactly my setup
My setup
Still using KeepassXC on desktop and laptop and KeePassDX on mobile.
This is exactly my setup. How did you know? LOL.
File synchronized with Syncthing? :)
I’ve thought about it, but for now at least I just use a USB flash drive to keep the file synchronized.
I could say I know because i’m an elite haxxor but it would be a lie. I’m not even at script kiddie level.
I like ProtonPass. It’s nice.
And they are really moving quickly with development. I feel like we’re getting new features monthly
Same. The UI is pretty good and modern, they support TOPT and cards as well and the development is being done at a good pace.
KeepassXC & Syncthing
And I do keepassdx on Android, with a (phone-specific) database synced with syncthing
P.S. syncthing is fantastic: I hope more people consider hosting discovery servers and especially relays
Syncthing is so good!
Keepass + Syncthing is a great combination.
And with Syncthing’s Untrusted Device Encryption feature I can use my VPS as an extra node for synchronization without worrying touch if it becomes compromised without me knowing.
the file is already encrypted so you aren’t getting much more security
I also sync other stuff, so it’s useful anyway.
And it hides file names and sizes by splitting things up, which puts one extra layer of difficulty for someone trying to find my passwords file to target. I have a much stronger password on the syncthing directory than my normal type-each-time password to open keepassxc.
If you are into the command line, pass is also neat. You can even have your keys in a git repo and access it with a FOSS Android app (requires some dedication to set it up). It’s very useful to feed passwords to scripts without hardcoding them in the source.
KeepassXC, Passbolt
I use keepass with my database on onedrive.
Then i connect every device to said onedrive account, copy the private key manually on each device that i need to use.
I secure my databse with said private key + a passphrase.
Might not be the best setup, but i feel like with passphrase+key i am secure enough to have the db file in the cloud.
you could encrypt onedrive with cryptomator
KeePassXC my beloved
I love Dashlane, someone tell me why it’s bad.
I know they recently published the code for their clients, so that’s a plus. But I can’t find any independent audits for their architecture or clients.
While all mentioned options does have independent audits done.
Aslo more expensive than Bitwarden for example, should u want to pay for premium.
Dashlane’s app experience across platforms was hit and miss for me. 1Password has been much better.
KeePass for me. I keep my encrypted vault in my 2 factor encrypted gdrive. Get the best of both worlds. No traditional cloud that’s a target for hackers and I have passes I can share across devices.