Live data from Hacker News

KeePassXC 2.6.1

keepassxc.org

71–80 of 119 posts

Re: KeePassXC 2.6.1

#71
post #2

KeePassXC and Bitwarden are the best password managers in existence right now: KeePassXC if you want to be disconnected from the cloud and Bitwarden if you want both the convenience of cloud-based password management AND high security.

Nope, pass (Password Store) is way better IMO.

Re: KeePassXC 2.6.1

#72
post #2

KeePassXC and Bitwarden are the best password managers in existence right now: KeePassXC if you want to be disconnected from the cloud and Bitwarden if you want both the convenience of cloud-based password management AND high security.

Nope, pass (Password Store) is way better IMO.

I’m very happy with pass too.

Re: KeePassXC 2.6.1

#73

Earlier quoted context omitted.

> (from what I've heard 1Password only recently even added a Linux-compatible client). Just plugins for Firefox and Chrome, AFAIK, actually. And a command line client that's just a wrapper for the website. No full-featured client available. KeePassXC can be a better option for interop with 1pass than 1pass is, on Linux, depending on what you need.

No, they have a client now. https://discussions.agilebits.com/discussion/114964/1passwor... HN discussion: https://news.ycombinator.com/item?id=24054112

Guess that hasn't made it to their "download for linux" page on the main site yet. It still offers the plugins, with an alternate option for the command line tools.

Re: KeePassXC 2.6.1

#74
post #40

Earlier quoted context omitted.

>best password managers in existence right now I am using 1Password with a standalone licence (sunk cost, so 'free' doesn't matter much. Also, C$70 is essentially free when it comes to securing my digital life). I sync a vault with a few co-workers via Dropbox and this is sufficient for us, no need for 1Password.com 'cloud' yet. We like the UI, and to our knowledge 1Password has the best track record for security, wi…

Source code access, and being free of charge seems to be the main things you would get compared to 1Password. Also, great Linux support (from what I've heard 1Password only recently even added a Linux-compatible client). But to me it sounds like you have a solution you are very happy with, and you don't mind paying for that solution, so my recommendation would be to stick with it. Although, as a happy user of KeePass…

They are also very responsive on Github for logged issues and questions. They responded within the hour to an update to an existing issue that I logged.

Re: KeePassXC 2.6.1

#75
post #51

Any reason to switch over from KeePass to KeePassXC? I'm only using Windows so the cross platform argument doesn't hit me actually.

KeePassXC supports TOTP. This is the main reason why I switched.

Re: KeePassXC 2.6.1

#76
post #51

Any reason to switch over from KeePass to KeePassXC? I'm only using Windows so the cross platform argument doesn't hit me actually.

Arguments sound good but I didn't seem to find any biometric authentication for KeePassXC. In KeePass I could use some plug-ins to connect Windows Hello with KeePass so I could unlock the DB with my fingerprint or via looking into the camera.

Maybe I simply didn't search good enough, is there any possibility to have such functionality in KeePassXC?

Re: KeePassXC 2.6.1

#77
post #20

Earlier quoted context omitted.

Started using Keypass about a year ago, I really like it. Just wondering if Dropbox is considered a safe place to store the DB files? I did this for a while, but then I got paranoid and switched to something fully encrypted. For sharing between devices I found Firefox Send to be useful (before it went down, hope it comes back), also Keybase filesystem is one of my go-tos as well. Maybe I’m being overly cautious, but…

Your database is encrypted by default. Additional encryption won't hurt, of course, but you can absolutely use Dropbox.

Right, I guess my concern was a brute force attack on a DB file if it fell into the wrong hands. I looked at the main website again though, and apparently the official Windows app has some protection against this. It says however, KeypassX (and I assume therefore KeypassXC) does not have the same level of protection.

Another comment mentioned using a key-file, so maybe I will revisit that approach, since I used password only when I started.

Re: KeePassXC 2.6.1

#78
post #2

KeePassXC and Bitwarden are the best password managers in existence right now: KeePassXC if you want to be disconnected from the cloud and Bitwarden if you want both the convenience of cloud-based password management AND high security.

Nope, pass (Password Store) is way better IMO.

I realize GP was unqualified too, but can you expand on this since it sounds like you've used both? I use (go)pass fairly happily and was recently recommended BitWarden and I'm curious about what separates them.

Re: KeePassXC 2.6.1

#79
post #46

Earlier quoted context omitted.

Syncthing is a nice alternative to Dropbox. If you use multiple computers at different locations, you could, say, use Syncthing to sync your KeepassXC database between your home computer and your phone, and between your phone and your work computer, without it ever touching a third party service.

It has worked for me perfectly for quite a long time. All my personal documents and photos are synced between an Android phone, my RPi 4 and my laptop. I haven't touched the settings for years. It just always works, 100% perfectly. I don't understand why it isn't more popular.

"First, you'll want to set up a server" and you're already down to well under 1% of the population that'll be interested in reading any further, let alone following through and actually doing it.

Re: KeePassXC 2.6.1

#80
post #15
post #9

Earlier quoted context omitted.

A habit I carried over from using KeePassXC is that I don't use a browser extension. Call it paranoia but I don't want the browser process to have the ability to reach into my password manager. What I do is pin the Bitwarden tab open and just copy & paste where needed. For the desktop app it would be awesome if it had an auto-type feature like KeePassXC (something that mystifies coworkers who see that in action for t…

You're losing out on certain types of phishing protections by doing this. You're also potentially opening yourself up to any apps/tools that are keeping an eye on your clipboard if you're copying and pasting. Auto-type might help with that, but I also wouldn't hold my breath for such a feature coming.

And you are gaining that many passwords are not shared with the browser. I rely on in browser password storage (which you can also encrypt e.g. in Chrome) for frequently accessed sites.

I think the separation of concerns outweighs the KeepassXCBrowser integration part.

If your computer is compromised (meaning occasional copy&paste is not secure) you have WAY more problems than only Keepass and phishing.

Post reply on HN