Live data from Hacker News

KeePassXC 2.6.1

keepassxc.org

91–100 of 119 posts

Re: KeePassXC 2.6.1

#91
post #82

Earlier quoted context omitted.

I store the KDBX file in Dropbox, store the key file elsewhere, and use a strong password. Without the key the database file is useless.

I currently only use a password/phrase, but I will consider using a key file as well. My concern was a brute force attack on a compromised DB file. But I guess as long as the key-file was never put in the cloud, this would alleviate that concern?

Yes, when you want to use a new device you sideload the key file onto it in a secure manner (i.e. USB).

On Android this presents some issues though, since the last I checked the keyfile had to be added to the "SD Card" class storage, which other apps can also access. If you are on android and go this route, be really careful about the types of apps you install that have Storage permissions (good advice in general, of course).

Re: KeePassXC 2.6.1

#93
post #50

Earlier quoted context omitted.

KeePassDX has a much more modern UI. Also open source https://www.keepassdx.com/

> KeePassDX has a much more modern UI. Is that supposed to be an endorsement or a warning?

I like the app and use it due to it being offline + a smooth UI. No clunky like the rest, even though they are great too.

Your choice. It was an endorsement.

Re: KeePassXC 2.6.1

#94
post #15

Earlier quoted context omitted.

You're losing out on certain types of phishing protections by doing this. You're also potentially opening yourself up to any apps/tools that are keeping an eye on your clipboard if you're copying and pasting. Auto-type might help with that, but I also wouldn't hold my breath for such a feature coming.

And at the same time you win by not falling victim of "oops, there is a bug in our browser add-on that accidentally leaks arbitrary login data to websites", as it has happened in the past. Leaking all my credentials certainly sounds more concerning to me than leaking the credentials to a single page.

KeePassXC asks for permission to share each credential with the browser, with a "Remember" checkbox. You can have convenience for your unimportant logins while keeping your sensitive credentials fully secure.

Re: KeePassXC 2.6.1

#95

Earlier quoted context omitted.

You can also run your own bitwarden server either with their official server or with bitwarden_rs, a reimplementation in rust that runs better on lower-end hardware

It runs better everywhere. I have set up both and see no difference between them feature wise. Why would you use the official one? It's so resource heavy, more difficult to set up, feels very enterprise-y.

exactly, it is suited for enterprises, where you have to stick with the official builds for compliance.

Re: KeePassXC 2.6.1

#96
post #86

Earlier quoted context omitted.

I did read the other comment about syncthing; but that requires setting up a server. Do not want to go that route.. :)

Syncthing does not require setting up a server. Your devices connect to each other directly, or through a relay if that's not possible.

Thanks.. Will give a try...

Re: KeePassXC 2.6.1

#98
post #84
post #45

Earlier quoted context omitted.

What vendor lock-in? They make it plainly clear how to export your data from BitWarden: https://bitwarden.com/help/article/export-your-data/ Personally I think it would be awesome if Bitwarden gave you the option to export your password vault as a KDBX4 file. What's the best way to fund a bounty program for adding this feature to Bitwarden?

KeePass has the ability to import Bitwarden JSON file so there's little need for the feature.

There might not be a need but I like the idea of being able to use the Bitwarden client on iOS/Android with a KDBX4 database file from KeePass(XC).

Re: KeePassXC 2.6.1

#99
post #15

Earlier quoted context omitted.

You're losing out on certain types of phishing protections by doing this. You're also potentially opening yourself up to any apps/tools that are keeping an eye on your clipboard if you're copying and pasting. Auto-type might help with that, but I also wouldn't hold my breath for such a feature coming.

If you are infected with a clipboard logger chances are it is also a keyboard logger. Frankly, at that point you're unlikely to be saved by a browser extension anyway.

That depends on how many horrible ideas make their way from phone to desktop.

Re: KeePassXC 2.6.1

#100
post #2

KeePassXC and Bitwarden are the best password managers in existence right now: KeePassXC if you want to be disconnected from the cloud and Bitwarden if you want both the convenience of cloud-based password management AND high security.

>best password managers in existence right now I am using 1Password with a standalone licence (sunk cost, so 'free' doesn't matter much. Also, C$70 is essentially free when it comes to securing my digital life). I sync a vault with a few co-workers via Dropbox and this is sufficient for us, no need for 1Password.com 'cloud' yet. We like the UI, and to our knowledge 1Password has the best track record for security, wi…

The advantage is higher security, zero cost and control over data.

1password is closed source and there is no way to verify that it actually encrypts the passwords.

I wouldn’t give someone my passwords to encrypt and store them for me. It’s a simple task and I can just encrypt and store my passwords. I don’t need a shinier UI.

Post reply on HN