Ask HN: What is your password management solution?

192 points by ericb ↗ HN
I'm a bit unhappy with 1Password. I don't want a subscription service, I want something that keeps an encrypted file that I can put in dropbox.

What is everyone else using these days?

319 comments

[ 2.9 ms ] story [ 466 ms ] thread
> I want something that keeps an encrypted file that I can put in dropbox.

KeePass.

My brain, and several easy to remember password generating rules.
> I want something that keeps an encrypted file that I can put in dropbox

FWIW You can do this with 1Password. Preferences > Sync > Sync with Dropbox

This, IIRC, requires an older version of 1Password. Version 4, from the "Who moved my cheese" discussion of 1Password's most recent subscription changes.
I can confirm this option still exists in 1Password 6 (I'm using the iCloud sync but I see the option for dropbox as well). I'm not sure how to get the license though. I only see the upgrade path that I took - not the outright purchase.
https://agilebits.com/store

You can still purchase a Mac license there. I don't see a Windows option, but I'm viewing this from a Mac, so not sure if they're just hiding it. (Some people in this thread have said that there's no longer a non-subscription version for Windows.)

MacOS 1P can still do it for current version and next version, as per their blog post. iOS 1P still does too.
Not on 1Password 6 on Windows. Subscription only.
write it down and put piece of paper in pocket
Congratulations for having the patience to write out long strings of characters on paper and type them out repeatedly, but that doesn't sound very safe.
You can make it safe by using a secret key in conjunction with the keys. For example; all passwords as written but the third character must be # instead of what's written. This renders the book useless if stolen or copied.

If you keep the book in a locked draw and use some tell tails to ensure that you will know if it's been opened you have a strong chance of being able to know if you have been physically compromised.

Any online key store is vulnerable in a number of ways, end to end security is hard. The biggest issue is that your provider might be placed under significant physical pressure relieved only when your account is compromised.

And you will be unaware.

Well "safe". Once your written down password is compromised (e.g. with a photo of a page), the entropy for cracking the password is tremendously minimized. In combination with dumped hashes of the site in question even more.

Maybe a password card is a better solution? [1]

[1]: https://www.passwordcard.org/en

It's about as safe as sms 2fa. Once you've used the password 10 or 20 times it becomes memorized.
Enpass is what you are looking for!
I too use enpass. Syncs your password vault to OneDrive, Dropbox. (It's just an encrypted file)
My favourite, and I'm happy to support financially.
Enpass all the way. Free and works with dropbox
I tried it and was mostly happy with it. But has it gone through anywhere near the third-party scrunity that 1p has?
I would be much more eager to use Enpass if they made the code available to people who pay.
They use SQLCipher which is OSS. I understand they don't release the UI code as it is what they use to make money. If you are afraid that they secretly copy your passwords you can easily check this. As you keep the file on your device or place it at a third party service it is more secure than a service like LastPass. Also don't use browser plugins but copy and paste the password
My favourite, and I'm happy to support financially.
I started using Enpass a few months ago and am mostly happy with it, but I'm not sure it'll work for me long term.

A few of the issues:

- It crashes periodically on Linux. Though it has never wedged the database.

- On ChromeOS, it is "supported" via the Android app, which does not integrate with the Browser plugin from what I can tell. I was really hoping for something that would work there.

- You can't have multiple password databases at all, from what I can tell. I'd really like something that could manage my personal passwords, work passwords that I share with 2 other people at work, and family passwords that are shared with my fiance'.

For the last decade I used a gpg encrypted file on my laptop, combined with passwords saved in the browser on my encrypted file-system. That worked fairly well, until I was in Mexico and my laptop decided to take a vacation too. I couldn't access ANY of my passwords until I got home and could get to my desktop or move my drive to another machine.

Enpass has some benefits:

- The syncing using Google Drive works well.

- Fingerprint unlocking of the vault on my phone works well.

- I've always had a pain point with apps on my phone that update and then need the password again (front door smart lock, car, bank), and I can't access them anymore until I get to my laptop and type in the 30 character random password.

- You can add fields to the records, the default "login" record has "security question" and answer, but for sites that have 3 security questions I can add them as custom fields. (My mothers maiden name? It's "mCxK7JszjJ5Mq29")

- It is available on Linux and Android and kinda on ChromeOS.

I do feel like a web-based one would work better with ChromeOS, but I'm still experimenting with whether ChromeOS can replace my laptop. I'm typing this on my laptop, so...

I'm a huge fan of Enpass, simple and does exactly what it says on the tin. I've convinced friends and coworkers to switch over to it and they're all very happy with it from what I've heard. What I don't like, and one of the reasons I'm looking at moving away from it, is that the code isn't open source. It also conveniently enables the sending of analytics/data usage by default and hides the option to turn it off at the very bottom of the Preferences / Advanced tab. The only reason I even noticed this was from Little Snitch popping up to tell me. Maybe not a massive problem, but I'd rather a password manager didn't phone home every time I open the damn thing up.
I'm a happy Enpass user too. The best thing I like about Enpass is it's built on Open Standard, you can decrypt the database file easily if Enpass dies
I use this. My only gripe is that I need to unlock each day for the browser integration to work, and I need to open the app to (not have a service in the background).
KeePass and KeeWeb are both great interfaces that can read KDBX format. I sync with Dropbox and encrypt with a private key that I carry with me or keep on my main machines.
1Password & gopass (https://www.justwatch.com/gopass/, it's "pass" compatible if you are using that already). I don't really mind the subscription service as it works fine across all platforms I use.
Do you sync 1password and gopass? or one for home and other for work?

I love 1Password but the lack of linux support is irritating. (I know about the web client)

1Password for all my private stuff and I also have a vault for work credentials (websites, external services, third party APIs etc where autofill in the browser comes in handy)

I use gopass for everything that's company internal.

`pass` is a nice command line tool that stores gpg2 encrypted password files. It's simple, super handy and doesn't require you to trust any third party with what you're storing. website: https://www.passwordstore.org/ man page: https://git.zx2c4.com/password-store/about/
+1 for `pass`. I wrote a handy Bash script [1] that lets me easily search my passwords without having an exact match (e.g., `fpass fin cap one` quickly finds my password info for "Financial/CapitalOne.gpg"). It makes pulling up passwords so much easier as I only need to remember fragments of how I stored it instead of trying to remember exact folders and names using auto-complete to find the password.

I also use iTerm2's system-wide hotkey [2] to quickly show/hide a dedicated terminal window that I use for retrieving passwords.

I've been using this setup for years now and I absolutely love it. The only downside is no access from my phone, but I always have my laptop with me and I memorize passwords that I frequently use.

1. https://github.com/raamdev/bin/blob/master/fpass

2. https://apple.stackexchange.com/a/48805

Oh my ZSH (http://ohmyz.sh/), if you use zsh of course, has autocomplete, so folders and GPG files are only a few tabs away.
Don't need omz for autocomplete, it's already there in zsh. I TBH don't really like omz. It feels bloated, and I don't really need anything else on top of the already-awesome zsh.
> The only downside is no access from my phone.

On Android, I use Password Store to sync my `pass` directory and use it from the phone. It a very high quality app, I had no issues after years of usage.

https://github.com/zeapo/Android-Password-Store

Keepass user here wanting to switch over to pass, this is exactly the missing piece of the puzzle I needed - thank you!
I'm looking into using pass / keepass, any particular reason you are switching over to pass?
I think I'm currently in a minimalist phase; the KeePassX UI is too feature rich and cluttered and makes me want to configure everything but I don't want to manage that.

If that's not a problem for you, KeePassX is definitely a solid password manager!

Instead of hiding the window, why don't you look into using terminal colors to hide the password? That way the passwords aren't visible until you highlight them.
Better to use the '-c' option to put the password in the clipboard and not display it in the terminal.
Does pass still stote metadata unencrypted (as file names) or did they fix that now?
If you're not going to use 1Password, which is still the only commercial password manager I'll recommend, "pass" is probably your best alternative.
As a LastPass user, any particular reasons why I should avoid them? Is it down to all the security issues they've faced lately?
1Password is the only commercial password manager I recommend, but I'll go further than that when it comes to LastPass and say: I really think you should avoid LastPass, and, if you're using it, migrate to something else.

I'm not going to go into details, sorry.

LastPass is the only commercial password manager I recommend. I really think you should avoid 1Password.

I'm not going to go into details, sorry.

You do much work in this field?
It doesn't matter whether he does or not. He's using your own argument against you. Stepping in here and saying, "don't worry guys I'm the expert, so don't ask any questions", is just pompous and doesn't actually convince anybody. Use logic to support your claims, not your resume.
No, sorry.
Are you able to say why you aren't willing to go in to details? I respect your CV and am going to switch to 1Password from LastPass based on your comment, but I'm curious whether I need to be concerned about my information being compromised.
It's funny. When I was the GP comment I thought "well that's not a very useful comment". Now that I've paid attention to who the author is... I'm getting concerned about LastPass :)
Well, shit, two conflicting comments. Which advice do I take? Quite the quandary.
Why do the trouble of replying but fail to explain your reasons? That's wasting your own time mostly.

I would recommend 1password over lastpass as well. First reason being the security issues of lastpass chrome extension. Though claimed it is fixed now they have claimed before on other issues only to be proven wrong after. I simply don't trust them anymore with my data.

But even more I would choose 1password over its usability. I used lastpass before but switched during the past few security issues reported. I have never looked back. 1Password is much better integrated in your mobile devices. The app feels more robust and is easier to operate. In addition the whole process of setting up your devices felt easier and more secure using 1password.

Second. My wife understands it which is a big plus. She doesn't complain anymore about the cumbersome lastpass. We keep a shared vault as well. That alone is worth every penny and maybe the only reason I keep with a commercial password manager. I don't think she will use the alternatives.

I would strongly advice you to at least try it. It claims to be able to import your lastpass though personally I didn't try as my lastpass was a bit of a mess.

I understand why it makes people uncomfortable to know that they're not getting all the information I could possibly convey in a comment.

I don't see how that would make it better for me to not comment at all.

If it's too much for a content, how about a link to a source that articulates your point? I'm sure many people would appreciate more complete information.
Because an advice without argument is ignored (in many cases). If it were me I would have rephrased my comment to include a summary. That would be sufficient to understand why you said things and in addition would be perceived less cocky. Now it came over as I'm saying this and you are not worth my time explaining the arguments.

Apparently you have knowledge on the subject so a sentence or five would have helped everybody reading this thread. In fact, it is what I would expect from an HN comment. I usually read the comments before the article as on HN there is often more information than the actual article. Most often different sides of the coin are in enlightened in the comments bringing insight in the otherwise one-sided monologue in the article.

I suspect the reluctance to offer more than a brief recommendation isn't a lack of confidence in the argument, but rather a sensible level of restraint for someone who is in the security industry.
Neither are deal breakers for me, but I get issues with their plugins sometimes.

The deal breaker for me before vs 1PW was that I would store quite a bit of info in 1PW for some logins. Filling out a whole sign up form might include birthday security question/answer, name, and more. For various reasons, I don't always use real info so having this info automatically saved or easily added as new fields is great. I know Lastpass has a few extra field options and a notes section within each login, but the fields aren't enough and I don't want to have to manually add all the info into the notes like some people I know do. I'd rather pay a few dollars more a month and get the convenience and time saved.

I'm sure it makes up for the extra ~$25 a year. And the family plan at $60 a year for up to 5 family members isn't a bad deal in my opinion either if that can work for you. I know it sucks compared to buying the apps one time, but I don't feel it is as bad the outcry was/still is.

I guess I'm looking at this strictly in terms of what is best for my day to day life. It's not worth it worrying about a few extra dollars a month when I only have a handful of subscriptions as it is.

Is your recommendation of 1Password contingent on any particular set up (like only using a "local vault" and not their cloud solution)?
My main reason to not use pass is that I can't allow multiple private keys to unlock the password store. I don't want to transfer my private key between all my machines.
You absolutely can do this.

In your .gpg-id file, simply list the keys you want to encrypt for on separate lines. Every file below that .gpg-id file in the directory hierarchy will be encrypted for any of those keys to unlock.

Also you can re-init any time you want, listing multiple keys. This will go through all your passwords and re-encrypt them for each of the keys listed. That's how I got my phone set up with access (with its own locally-generated private key).

If you want more granular key strategy, look at gopass [1], which is a pass-compatible binary that gives a little more granular control over key usage (IIRC), and is written in Go.

[1] https://github.com/justwatchcom/gopass

Why not transfer the private key? I encrypted it using a one-time pass and send it using email. I then decryped and installed to the other machine.

Since I don't have the one time pass anymore the encrypted file is not usable anymore and I have the same key to both machines.

Please explain any holes with that flow.

Switched from pass to gopass recently : (https://github.com/justwatchcom/gopass). It's open source and has a tad bit more features over pass. Some of the reasons for my choice to switch:

- compatible with pass

- support for multiple stores

- store binary data (e.g. QR codes for seeding 2FA) : upcoming

- report / track issues on github.com/justwatchcom/gopass/issues

- more details here : https://www.justwatch.com/gopass/docs/

fun fact: 2FA QR codes contain the secret as just part of a url. you don't need to save the binary image, just figure out what the (usually base32-encoded) secret value is, and store that. google authentcator lets you type in the base32-encoded secret (useful if your phone's camera is broken). see e.g. https://garbagecollected.org/2014/09/14/how-google-authentic...
The original pass seems to handle binary data fine:

    $ pass insert -m mybinarysecret <secret.png
    $ pass show mybinarysecret >secret.png
Admittedly, it's not very user-friendly, but some simple wrapper scripts could fix that.
(comment deleted)
Pass also has Android and (AFAIK) iOS clients, and many other frontends.
Password Safe + pwSafe ios and mac clients + Dropbox
https://www.lastpass.com

Free to use, auto password generation, has an iOS app with thumb print unlock (saves you from typing in a long master password).

I personally really enjoy it.

Android version also the first thing I set up on a fresh phone. Fingerprint unlock, can input passwords directly into most apps (it matches sites to apps automatically) as well as Chrome.
Keep in mind that enabling the LastPass Accessibility service in Android disables device protection features (like storage encryption).
>I don't want a subscription service, I want something that keeps an encrypted file that I can put in dropbox.
My company uses it and I really despise it.

Basically their web add-ons are extremely buggy. I was using Firefox and after many issues tried Chrome version, that one looks nicer but is similar POS and similarly had its own set of issues. Perhaps I would be happier if there was just a standalone app that I would only fire up when I need it.

I agree. The browser plugins used to be much cleaner and snappier when I first started using LastPass a few years ago, but it has progressively gotten worse to the point of making the whole thing nearly unusable. It feels like some 4th grader tried to reimplement drop-down menus using a crappy home-made JS framework.

I stayed with LastPass through the various security incidents they've suffered, but recent UI updates finally made me cancel my paid subscription and switch to 1Password -- a standalone app that integrates with the browser through a very lightweight plugin.

I don't understand the hate against Lastpass. Why would I trade it's awfully simple features (autofill on Android, automatically save/update passwords from website forms in browser, cheap etc.) for something like Keepass, even if the latter is purportedly a bit more secure? Some people also say that Lastpass's UI isn't great, but who cares about a password manager's UI as long as it does the job?
I use it but as others have mentioned it seems the browser extensions are getting slower and buggier
>purportedly a bit more secure?

The worst bugs in LastPass are:

1. Four months ago a bug was discovered by project zero[1] about how all of your passwords can be stolen just by making a user visit a webpage. Moreover, any code can be executed remotely, compromising your entire computer. Discussion[2]

2. Later on the day vulnerability (1) was published, another was found. Project zero bug report. [3]

3. Last year a software engineer who wasn't a security researcher found a bug[4], which again, gives all your passwords.

4. The bug in (3) wasn't fixed properly, which lead to this [5]

Other bugs, but not as terrible as the ones I listed above

Jul 27 2016 [6]

Mar 25 2017 [7]

Jun 17, 2015 [8]

Nov 17, 2015 [9]

You are also forgetting a whole another class of attacks - Phishing [10]

[1]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

[2]: https://news.ycombinator.com/item?id=13924737

[3]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

[4]: https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...

[5]: https://bugs.chromium.org/p/project-zero/issues/detail?id=11...

[6]: https://bugs.chromium.org/p/project-zero/issues/detail?id=88...

[7]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

[8]: http://www.businessinsider.com/security-expert-describes-las...

[9]: http://www.martinvigo.com/even-the-lastpass-will-be-stolen-d...

[10]: https://www.seancassidy.me/lostpass.html

Oh my. Thanks for taking the time to list these down. Will work right away to get off Lastpass. No, seriously!
What ever password manager you move to, chose something that will stay far away from your browser. And don't use anything that autofills your passwords. This includes KeePassHTTP.
I use Keepass 2. With a plugin, it's synced to Dropbox, where I can access it on my Android device with one of the compatible apps.
I use KeePassXC [1], which is open-source, and I sync it across my iPhone, Windows laptop, and Linux desktop via Tresorit [2] (like Dropbox but end-to-end encrypted). It's secured with a password that I know, and a keyfile that I have. I don't sync the keyfile and always manually transfer to new computers.

I also use Arq [3] to automatically backup to S3 every hour, and I also do manual backup to my external backup drives once in a while.

  [1]: https://keepassxc.org
  [2]: https://tresorit.com
  [3]: https://www.arqbackup.com
Agreed on use of keepassxc - fantastic utility.

I don't, and wouldn't, use dropbox or any other non-free non-self-hosted system to manage the storage or synchronisation of my secure data, so it's unison(rsync) and/or ssh'd between desktop and laptop.

If only there's a way to do that with my iPhone :(
There are file sync apps that work with iOS devices that work with self-hosted file sync solutions.
do you have a particular one you recommend?
I don't use one, but to give an example, Google for "nextcloud iphone".
(comment deleted)
I store my password file on my phone, and use KDEConnect to access it on my desktop when needed.
Why not use dropbox? It is only used for sync databases, not access them, I always though if someone found my keypass database encrypted it would be useless.
Paranoia

Yeah, the KeePass database is encrypted and I secure it with both password and keyfile, but I still want something that won't leave my database "out there" available for bruteforce attempts or other attempts at it.

It's hardly "out there" though. A hacker would still need to hack dropbox before they could access your keepass db and begin brute forcing. What makes your own private server more secure than dropbox's network?
What is the cause for your paranoia about keeping your keyfile in your Dropbox? I have used and advocated this model for years with no ill effects.

My Dropbox is secured by MFA, with the Dropbox password itself being a random password within the KeePass keyfile. I store the whole Keepass program for Windows inside the same Dropbox account, feel free to indicate that as a security gap. On mobile I use the KeePass2Android app.

You meant the kdbx file right? not the separate keyfile you can use to secure the kdbx file with.

I think the feeling is the same as the feeling of just leaving your SSH private key "out there". Sure, it's protected with a passphrase, but I still don't want to do that.

Can you trust Dropbox would never have security issues? See https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authent...

Didn't matter if you have MFA or use a secure password.

Some people will not be satisfied so long as the keyfile, KDBX, and password reside in the same version of our shared reality, as it's still mathematically possible to decode the numbers into something they personally value.
you can also encrypt the db file it self (before putting it on dropbox) with something like EncFS.
I used to do that when I used purely Linux. However, once you bring iPhone and Windows into the picture it doesn't work anymore.
What do you use to read the DB files on your phone? I'm new to iPhone and looking for an app I trust right now.
I use MiniKeepass [1]. It's open-source [2] and I build it myself to load onto my phone.

  [1]: https://itunes.apple.com/us/app/minikeepass-secure-password-manager/id451661808?mt=8
  [2]: https://github.com/MiniKeePass/MiniKeePass
Same, but using Keepassdroid + DropSync use it on, and sync it to, my Android phone.

Crashplan is my backup tool of choice and also backs up the Dropbox, just in case...

This is my solution as well. I back it up to a sftp server to keep it synced across my devices.
I recently did a bunch of research into password managers, and went with Keepassxc as well. I'm using Syncthing to sync the password archive across Linux, Mac, Android, and Windows devices. The whole setup is working very well and is all open source.
I use the standard keepass 2 client on my windoes machines, and keepass2android on my phone. Clients only access the file via ssh to my server at home so it doesn't require storing the database on other machines.
I use the standard keepass 2 client on my windoes machines, and keepass2android on my phone. Clients only access the file via ssh to my server at home so it doesn't require storing the database on other machines.
Roboform
Wow, haven't heard that name in a decade. Crazy that they are still around.
Ah. I used to love Roboform and bought it for $20 for life but then they changed their minds about honouring that so I went elsewhere. Lastpass currently.
Same happened to me. 1PW for me now.
It's crazy Roboform is still around. They didn't honor my old purchase so i moved on from them. Their product from a far also doesn't look that good in 2017. Did not expect to see a serious mention of Roboform in this thread though!
I use Vault from hashi corp for everything.
Subscription to 1Password is not mandatory. Or at least it was not in the past. Without a subscription, you can create local vaults which can be synced via Dropbox, iCloud or over WiFi within the same subnet (which means over VPN too).

Here is some documentation on the Dropbox sync for example: https://support.1password.com/sync-with-dropbox/

The subscription isn't really mandatory, but I've been quite disappointed at the transparency with which they've been pushing people towards that...even those of us that purchased the full version somewhat recently. For instance, the complete lack of a Windows version that isn't subscription based is a huge pain since I got a cheap Kodi box recently and my keyboard is a remote control that sucks for typing passwords.

I get that they want to transition people to that revenue model for their own benefit, but they haven't made a convincing argument that it's in our interests and they've definitely made those of us "offline" customers feel like second-class citizens. Normally, I'm all for subscription services, but password management is one area that I want complete control over and if they keep pushing me towards a model that requires their online presence, I'll end up switching.

I currently have 1password and 1password 6 installed. At some point I followed an "upgrade" suggestion, found out I don't get the upgrade for free and I had put new passwords into what is now an expired version.

Nothing about that made me happy.

https://1password.com/downloads/ still links to the 1Password v4 version for Windows, which supports local vaults.

And shameless plug for my own cross-platform powershell-based 1Password client, which can read both formats of local vaults: https://github.com/latkin/1poshword

I tried the v4, but it wouldn't accept my v6 license key :(

My workaround was to write a small utility that I run on both my Mac and Windows boxes that sits in the background and keeps the two clipboards synchronized. So I just copy from Mac 1p and paste in Windows. Not ideal, since it makes the browser extension useless, but it works well enough for the few times that I need to enter passwords on that box. But on the plus side, I can also use it for entering commands in cmd.exe and Powershell too.

I can't find how to purchase the single license for Windows. I found the download for Windows v4 and the single license purchase for Mac here: https://agilebits.com/store but not the Windows license.
1Password 6 for Windows is subscription only. You’d need 1Password 4 to work with local/Dropbox vaults.

Funny enough, 1P6 worked fine with my local/Dropbox vault during beta, then the app stopped letting me update my vault when it left beta. :\

(comment deleted)
I use this ruby script:

    print ((rand * 1_000_000_000).to_i.to_s + \
           ("a".."z").to_a.sample(10).join + \
           ("A".."Z").to_a.sample(10).join + "_")
It solves a number of annoyances. First, it's easy to type on mobile if you need to for some dumb website that clears your input field when you alt-tab, since it sticks to numbers, letters, then capitalised letters. It contains a non-alpha numeric character, but at the end for stupid forms that don't allow them.

As for keeping the passwords around, you can do one of a couple things, but I generally just forget the password after logging in with it everywhere. I'm signed into chrome, so what's the point in remember the password myself? Unless it's something sensitive I don't bother. It's easier to generate a new one than to dig it up.