Live data from Hacker News

Password Managers

lock.cmpxchg8b.com

21–30 of 342 posts

Re: Password Managers

#21
post #19

I worked on the design of adding passwordless 2fa to the Saas Pass password manager. In addition the saas pass password manager identifies websites that you can add 2FA to as well.

More details on adding 2fa to a password manager and figuring out websites and services you can add it to:

https://blog.saaspass.com/saaspass-password-manager-authenti...

Re: Password Managers

#22
Passwords are a lost cause. This doesn't mean that you need to give up on using good practices, just don't go overboard trying to plug all the theoretical holes. It's not all or nothing, sometimes it's OK to be good enough. For everything important you oughta use 2FA anyway.

Re: Password Managers

#23

After building my new rig, I also made a successful jump from Windows 7 to PopOS. It was mostly a very smooth transition, but I am having real problems with replacing Password Safe I used on Win. I eventually defaulted to using FF for passwords, but it still feels wrong. Password Safe had password generators, space for notes.. lil things that I keep missing.

I recently moved my passwords from an expired 1Password account to Bitwarden (right at the time they announced linux support actually, which was always the biggest thing I missed). Bitwarden has a FF extension and allows me to use it across mac/windows/linux.

Re: Password Managers

#24
post #6

This does not reallz discuss offline password managers like keepassx except for this one sentence > Conceptually, what could be simpler than a password manager? It’s just a trivial key-value store. In fact, the simplest implementations are usually great. Good examples of simple and safe password managers are keepass and keepassx, or even pass if you’re a nerd. I think keepass synched via nextcloud is a great solution…

What’s is the difference between keepass synced by X and another service which is completely online? Simplified with keepass I have a) the database and b) an online accessible Location for storage. If I use Bitwarden, I still have a) and b), right? So for keepass to be better it would need to be better (as in safer) for one of those. I’m not sure if that’s the case (you can even selfhost both Bitwarden and nextcloud…

Using keepass would decouple password management from your browser. Bitwarden, for example, usually runs as a browser addon.

Re: Password Managers

#25
I used to like Chrome password manager, but since moving back to Firefox, I like their password manager more.

I havent been comfortable with other 3rd party password managers and their integration feels forced

Re: Password Managers

#26
post #6

This does not reallz discuss offline password managers like keepassx except for this one sentence > Conceptually, what could be simpler than a password manager? It’s just a trivial key-value store. In fact, the simplest implementations are usually great. Good examples of simple and safe password managers are keepass and keepassx, or even pass if you’re a nerd. I think keepass synched via nextcloud is a great solution…

What’s is the difference between keepass synced by X and another service which is completely online? Simplified with keepass I have a) the database and b) an online accessible Location for storage. If I use Bitwarden, I still have a) and b), right? So for keepass to be better it would need to be better (as in safer) for one of those. I’m not sure if that’s the case (you can even selfhost both Bitwarden and nextcloud…

For one, it's completly free. I use a free nextcloud 1gig instance, you might use dropbox, onedrive, gdrive whatever. I don't think a trivial application like a password safe should require a personal server or a suscription, as the author rightly noted, it's not much more than a very, very small key value store

Re: Password Managers

#27
post #17

> This problem is pervasive among online password managers, you can never be sure if you’re interacting with a website or your password manager. Isn't this true for any scenario, password manager or not? If a site has been compromised without you knowing and you enter your password from memory, paste, or a password manager, that password is at risk. Is the author saying that he is able to access ALL passwords in the…

That's the vulnerability he's targeting, yes.

Re: Password Managers

#28
post #7
post #2

Malicious site

Sorry, to clarify Norton raised an alert on this domain. So proceed with caution.

yeah, funny how antivirus software would complain about the website of somebody known, among other things, for demonstrating a lot of security flaws in antivirus software.

Re: Password Managers

#29

tl;dr: browser extensions are bad therefore all password managers are bad Also find it odd the author uses Chrome, which doesn't even let you set a master password to E2E encrypt its password store.

It's usually encrypted with your Windows / Mac / Linux login password.

Re: Password Managers

#30
I have no complaints of keepass on my desktop. I tried using it on mobile but decided it wasn't worth the trouble to get it working as I wanted in terms of syncing and autofill. Instead I just use a select few logged in apps that I either memorize the password or use fingerprints. I don't really like the idea of syncing all my passwords with any online service.
Post reply on HN