Live data from Hacker News

On Password Managers

tbray.org

301–310 of 347 posts

Re: On Password Managers

#301
post #293

Earlier quoted context omitted.

I've used KeePassXC, and I think it's the best KeePass variant. I don't like stock KeePass because it's horribly slow under Mono (Linux/OS X). And I like but am not as satisfied with KeePassX because it lacks some features I like. From what I recall, the maintainers of KeePassXC got frustrated with the feature set and development pace of KeePassX, so they made their own fork. And they added nice things like TOTP code…

With KeePassXC you would do this by adding new entries for each alias and then reference the username and password values of the "base" entry. I believe the feature still isn't in a release, and the UX isn't there at the moment. The problem is that they can't deviate from the official KeePass database format, so adding something like aliases requires hacks like the above.

KeePass is moving to a new file format, KDBX 4 [1]. It includes Custom Headers feature that might enable plugins to implement URL Aliasing.

KeePassXC doesn't support KDBX yet, but they'r working on it[2].

[1] http://keepass.info/help/kb/kdbx_4.html

[2] https://github.com/keepassxreboot/keepassxc/issues/148

Re: On Password Managers

#302
post #298

I'm glad to see this getting more attention because it has been brewing for months and 1Password is essentially doing what they promised they wouldn't - forcing users to the subscription/online model my phasing out support for local vaults. I'm not mad at the subscription. I'd pay them the few bucks a month happily for what is an excellent application cross-platform. I AM mad at the forced cloud sync. My current plan…

Polished as in having a more "modern"/user friendly UI? I'd say the UI is the least important part of a password manager. Especially if you use an extension for autofilling/autosaving, you barely ever see it. Anyways, there is a more stylish web UI for Keepass: https://keeweb.info/

No, polished as in a functional browser integration and mobile app. For example, 1Password can fill in specific apps on iOS whereas I haven't found a KeePass app that can.

Small things, but "polish" nonetheless.

Have used KeeWeb and it's great.

Re: On Password Managers

#303
In 1Password's case, I understand their desire to switch over to subscription pricing, and also have some sympathy with the notion that moving people to a cloud-based model reduces confusion and complexity (including their support costs). I also have no doubt that they now intend to take security as seriously in the future as they have in the past.

Beyond the not-insignificant risks of them screwing up, despite the best of intentions, there's nothing that prevents a change of company direction/priorities that could greatly increase the risk of a significant security breach. New senior people get brought in, crises happen that lead to poor decisions for financial or other reasons, and companies get sold to people who may well have completely different priorities.

Re: On Password Managers

#304
The single point of failure is my own memory. I never commit passwords to anything else. Frequent user of password recovery for online sites. Will never use a password manager trojan for obvious reasons imho.

Re: On Password Managers

#305

With a couple UI/UX enhancements, Apple could take over the iOS/MacOS marketshare of these products with Keychain. It's already possible to use keychain in your workflow for password management, it's just not super convenient. I'd switch from Lastpass, if Apple made it easier to autofill and autogenerate passwords and added support for sharing / teams.

macOS/iCloud keychain does the job for me, but agreed that that user experience can be much better. If not a Safari password that's not setup for autofill, opening Keychain access, searching for the right credential, then authenticating to see the password gets tedious real fast. Same with being on iOS of opening Safari > Settings > Passwords, authenticating, and scrolling through a list of passwords to choose from with a final Copy/Paste action in the end. At the very least Apple should make credential management a lot more easier.

Re: On Password Managers

#306
post #235
post #202

Earlier quoted context omitted.

I've used it but there are two major issues they still haven't fixed. On windows there's some bug with a qt library they're using that, of all things, messes up network connectivity. It does polling of the network interfaces every 30 seconds (I believe) which causes traffic to completely stop for a couple of seconds. On Android at least, it is EXTREMELY slow. Search works about 10% of the time, and the other 90% of t…

Set the QT_BEARER_POLL_TIMEOUT environment variable to -1 I work on a Qt powered project and we had the same bug

Tried that, it did nothing. The only thing that worked for me was to delete the library entirely. At which point I'd ask why they bother including it in the first place if it's unnecessary and causes issues.

Re: On Password Managers

#307
post #5

The 1Password situation is complicated, and is a lot less sketchy than Bray's summary would lead you to believe. 1Password has not in fact phased out their native applications or required people to use 1Password.com to store passwords (it would be insane for them to do so). There are four issues that I'm currently aware of with 1Password: 1. They've converted from flat to subscription pricing. 2. They're pushing peop…

I just keep copies of a heavily encrypted txt file with all of my passwords, and while it's a bit less convenient in theory, in practice I've never had to worry about it or change my system. It's as secure as I choose to make it, and while I've been actually laughed at for this, I'm not in a position to have to trust a company that's monetizing my security as they "evolve" as a business.

Re: On Password Managers

#308
post #243
post #41

Earlier quoted context omitted.

Right! Sorry. I don't use Windows. Honestly? My recommendation about password managers probably shouldn't extend to Windows; there might be no password manager I confidently recommend on that platform. That's not a statement about 1Password; it's about the fact that the security models are different on the two platforms, and I'm very familiar with how 1Password works on macOS and less so on Windows.

It would appear making a password store on Windows would be rather simple, wrapping DPAPI: https://msdn.microsoft.com/en-us/library/ms995355.aspx At that point you should probably be about as (in)secure as access to the platform is. I don't know how you could improve much on that (assuming secureboot and bitlocker encrypted disk). Is there some magic going on the MacOS side that somehow improves on this?

Yes! The actual encryption of passwords is not the hard part of a password manager (though, of course, commercial password managers seem plenty capable of screwing that up!)

The hard problem is getting the passwords out of the encrypted store and into form fields in your browser.

Re: On Password Managers

#309
post #221

Earlier quoted context omitted.

The Chrome people, who I respect, recommend it. But Steve Thomas, who I also respect, has a lot of specific bad things to say about it. I don't think it will destroy you. But it is not my first choice.

Are these remarks of Steve (not a person I know, but I wouldn't expect to...) public somewhere?

Yes, they're on Twitter.

Re: On Password Managers

#310
post #33

Earlier quoted context omitted.

> I recommend 1Password, and there's currently no other commercial password manager that I recommend. Are there any open source password manager products that you would recommend?

As a 1Password customer who's been pretty unhappy with how the company took my money for a full version and has, since, been pushing me towards a subscription (making the non-subscription version/features harder to find, no Windows version, etc), I'm seriously considering switching over to Enpass [1]. The UI is pretty similar to 1Password and most of the features are there. It can sync with Dropbox and a few other cl…

I don't understand this mentality of getting angry that a company wants to migrate to a subscription fee so they can have sustainable income. You have a full version, so continue using it, but it's not fair to expect updates for free in perpetuity across platforms and browsers in today's churning software ecosystem.

1Password is an incredibly complex, solid and polished suite of software products that provides an essential security function. It absolutely boggles the mind that people get up in arms over the idea that they would be forced to pay $36 each year to use it.

Post reply on HN