Live data from Hacker News

KeePass: OpenSource Password Manager

keepass.info

101–110 of 138 posts

Re: KeePass: OpenSource Password Manager

#101

I've been a long time user of Password Safe. Any compelling reason to switch to KeePass?

Password Safe is the real deal because the master wrote it:

https://www.schneier.com/passsafe.html

It is convenient enough - and when it comes to such sensitive digital areas, then I defenitely prefer to take a conservative position over cloud based and client side encrypted solutions.

Re: KeePass: OpenSource Password Manager

#102
post #91

If I may, I have a question that was inspired by using password managers. Does anyone see any security issues with supporting on a website allowing the user name and password to be entered together in one field? The normal way of entering the user name into one field and the password into another would continue to work. The site would simply check and if the user name field content is blank, and the password field co…

In Windows, KeePass has Ctrl+Alt+A to auto-type usernamepassword.

Re: KeePass: OpenSource Password Manager

#103
post #94

I have tried pretty much every one of the well known password managers (that are open source and work on linux), but never found any of them very convenient to use. Until I came across this: http://www.zx2c4.com/projects/password-store/ It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to…

I think just pressing a hotkey to auto-type the correct password and username based on the currently active web page, program, window, etc. is easier still than opening a terminal and running a command. To me at least.

Re: KeePass: OpenSource Password Manager

#105
post #94

I have tried pretty much every one of the well known password managers (that are open source and work on linux), but never found any of them very convenient to use. Until I came across this: http://www.zx2c4.com/projects/password-store/ It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to…

Indeed, I love pass. I found that the majority of the time, typing 'pass ' is faster than clicking through a GUI anyway, and far more convenient if I'm already in the terminal. And on the web, all the other password managers have browser extensions to autofill data from their own database, but every common browser already does password storage and autofill natively. So once I grab a password from pass the browser rem…

As someone who does not have my browser remember my passwords I find the auto fill feature of KeePass a necessity.

Re: KeePass: OpenSource Password Manager

#106
post #103
post #94

I have tried pretty much every one of the well known password managers (that are open source and work on linux), but never found any of them very convenient to use. Until I came across this: http://www.zx2c4.com/projects/password-store/ It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to…

I think just pressing a hotkey to auto-type the correct password and username based on the currently active web page, program, window, etc. is easier still than opening a terminal and running a command. To me at least.

Unfortunately, that's useless if you need to store passwords for anything other than web use, if you need to automate the entering of passwords and so on.

Re: KeePass: OpenSource Password Manager

#107

I've been having it on my various systems (Windows, Linux, Android) in the sidelines for a couple months, and after initial fiddling, still haven't actually started using it. This is mostly because I don't want to have to deal with copy-pasting my password between the KeePass app and the browser (where most of my passwords are needed). Luckily, there are autofill plugins that exist for Chrome [1], Firefox [2], and An…

Keepass proper has a global Ctrl+Alt+A shortcut that automatically types in your username and password into the form: I've found it works fine on the majority of sites (almost everyone uses username-tab-password-enter, but for the few that don't, you can specify a custom auto type format in keepass. It even has an option to obfuscate the typing to trick keyloggers). For android, I recommend Keypass2Android: it comes…

KeePassDroid is another good one for Android. It does use the clipboard though by giving you two notifications to click on. One for the username, and one for the password of the chosen credentials.

I need to give KeePass2Android a try.

Re: KeePass: OpenSource Password Manager

#108

I use a password locker. It makes me wish there was an open standard for sites to negotiate a new entry with a password manager, something automatic in the background for new registrations. Site could send password restrictions, like allowed and required character types, minimum length, even maximum length, though that last one would be frowned upon. The locker would reply with a preferred username and random passwor…

God damn what you mentioned is a brilliant idea. I wish there was some standard for it. These are problems that I'm often inclined to work on solving, but unfortunately they are also the kind that need lots of time and adoption and formal procedures and acceptance from a large group of people to go anywhere so I tend to just day dream about them for a little while then give up, hoping some standard body or an organization like Mozilla do something about it.

Re: KeePass: OpenSource Password Manager

#109
post #103
post #94

I have tried pretty much every one of the well known password managers (that are open source and work on linux), but never found any of them very convenient to use. Until I came across this: http://www.zx2c4.com/projects/password-store/ It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to…

I think just pressing a hotkey to auto-type the correct password and username based on the currently active web page, program, window, etc. is easier still than opening a terminal and running a command. To me at least.

Well, I always have guake running, so for me doing it all on the command-line is WAY faster and more convenient. I forgot to mention that "pass" also has command line completion - which makes retrieval trivial.

I would also be surprised if someone somewhere hasn't already written an "autotype" layer over pass, but thats not something I am personally interested in.

I do agree that for end users this may not be the case. For non-technical people (my parents, for example), I mostly recommend writing their passwords down on paper. They have very few passwords as-it-is, and almost none of them are critical.

My own use case, where I have literally hundreds of pieces of info I need to secure (passwords, key-files, gpg keys, ssh keys, etc), is very different from that of such users. Hence different tools.

Oh, also, "pass" can copy the password to the clipboard, making the copy-paste scenario trivial. In fact, it goes even further by clearing the pass from the clipboard after a preset time.

Re: KeePass: OpenSource Password Manager

#110
post #94

I have tried pretty much every one of the well known password managers (that are open source and work on linux), but never found any of them very convenient to use. Until I came across this: http://www.zx2c4.com/projects/password-store/ It is simply the easiest, most intuitive password manager out there. One of those things that, once you come across them, you wonder why it took so long for something this logical to…

you make some really good points, as a programmer/scripter but for most end users and consumers they need something intuitive and keeppass is just that. personally I've used roboform now for over 5 years and have never been so happy to pay a yearly subscription fee. stores notes/passwords etc.

I agree. As a programmer/admin, my password storage needs are different than that of an average enduser. Security of my passwords, keys, etc is also significantly more critical and failure cause much more damage. So while KeePass/Lastpass etc might work for an average end user, they suck for my usage scenario.

Never used roboform - its not available for linux, so can't comment there.

Post reply on HN