Ask HN: What is your password management solution?
I'm a bit unhappy with 1Password. I don't want a subscription service, I want something that keeps an encrypted file that I can put in dropbox.
What is everyone else using these days?
What is everyone else using these days?
319 comments
[ 3.4 ms ] story [ 301 ms ] threadKeePass.
FWIW You can do this with 1Password. Preferences > Sync > Sync with Dropbox
You can still purchase a Mac license there. I don't see a Windows option, but I'm viewing this from a Mac, so not sure if they're just hiding it. (Some people in this thread have said that there's no longer a non-subscription version for Windows.)
If you keep the book in a locked draw and use some tell tails to ensure that you will know if it's been opened you have a strong chance of being able to know if you have been physically compromised.
Any online key store is vulnerable in a number of ways, end to end security is hard. The biggest issue is that your provider might be placed under significant physical pressure relieved only when your account is compromised.
And you will be unaware.
Maybe a password card is a better solution? [1]
[1]: https://www.passwordcard.org/en
A few of the issues:
- It crashes periodically on Linux. Though it has never wedged the database.
- On ChromeOS, it is "supported" via the Android app, which does not integrate with the Browser plugin from what I can tell. I was really hoping for something that would work there.
- You can't have multiple password databases at all, from what I can tell. I'd really like something that could manage my personal passwords, work passwords that I share with 2 other people at work, and family passwords that are shared with my fiance'.
For the last decade I used a gpg encrypted file on my laptop, combined with passwords saved in the browser on my encrypted file-system. That worked fairly well, until I was in Mexico and my laptop decided to take a vacation too. I couldn't access ANY of my passwords until I got home and could get to my desktop or move my drive to another machine.
Enpass has some benefits:
- The syncing using Google Drive works well.
- Fingerprint unlocking of the vault on my phone works well.
- I've always had a pain point with apps on my phone that update and then need the password again (front door smart lock, car, bank), and I can't access them anymore until I get to my laptop and type in the 30 character random password.
- You can add fields to the records, the default "login" record has "security question" and answer, but for sites that have 3 security questions I can add them as custom fields. (My mothers maiden name? It's "mCxK7JszjJ5Mq29")
- It is available on Linux and Android and kinda on ChromeOS.
I do feel like a web-based one would work better with ChromeOS, but I'm still experimenting with whether ChromeOS can replace my laptop. I'm typing this on my laptop, so...
You can self host the webapp, or run the desktop app. You can store your file on Dropbox
https://www.justwatch.com/blog/post/announcing-gopass/
I love 1Password but the lack of linux support is irritating. (I know about the web client)
I use gopass for everything that's company internal.
I also use iTerm2's system-wide hotkey [2] to quickly show/hide a dedicated terminal window that I use for retrieving passwords.
I've been using this setup for years now and I absolutely love it. The only downside is no access from my phone, but I always have my laptop with me and I memorize passwords that I frequently use.
1. https://github.com/raamdev/bin/blob/master/fpass
2. https://apple.stackexchange.com/a/48805
On Android, I use Password Store to sync my `pass` directory and use it from the phone. It a very high quality app, I had no issues after years of usage.
https://github.com/zeapo/Android-Password-Store
If that's not a problem for you, KeePassX is definitely a solid password manager!
For iOS: https://github.com/mssun/passforios works really well and it's open source.
I'm not going to go into details, sorry.
I'm not going to go into details, sorry.
I would recommend 1password over lastpass as well. First reason being the security issues of lastpass chrome extension. Though claimed it is fixed now they have claimed before on other issues only to be proven wrong after. I simply don't trust them anymore with my data.
But even more I would choose 1password over its usability. I used lastpass before but switched during the past few security issues reported. I have never looked back. 1Password is much better integrated in your mobile devices. The app feels more robust and is easier to operate. In addition the whole process of setting up your devices felt easier and more secure using 1password.
Second. My wife understands it which is a big plus. She doesn't complain anymore about the cumbersome lastpass. We keep a shared vault as well. That alone is worth every penny and maybe the only reason I keep with a commercial password manager. I don't think she will use the alternatives.
I would strongly advice you to at least try it. It claims to be able to import your lastpass though personally I didn't try as my lastpass was a bit of a mess.
I don't see how that would make it better for me to not comment at all.
https://www.google.com/amp/s/arstechnica.com/security/2017/0...
for a real link to the same article
Apparently you have knowledge on the subject so a sentence or five would have helped everybody reading this thread. In fact, it is what I would expect from an HN comment. I usually read the comments before the article as on HN there is often more information than the actual article. Most often different sides of the coin are in enlightened in the comments bringing insight in the otherwise one-sided monologue in the article.
The deal breaker for me before vs 1PW was that I would store quite a bit of info in 1PW for some logins. Filling out a whole sign up form might include birthday security question/answer, name, and more. For various reasons, I don't always use real info so having this info automatically saved or easily added as new fields is great. I know Lastpass has a few extra field options and a notes section within each login, but the fields aren't enough and I don't want to have to manually add all the info into the notes like some people I know do. I'd rather pay a few dollars more a month and get the convenience and time saved.
I'm sure it makes up for the extra ~$25 a year. And the family plan at $60 a year for up to 5 family members isn't a bad deal in my opinion either if that can work for you. I know it sucks compared to buying the apps one time, but I don't feel it is as bad the outcry was/still is.
I guess I'm looking at this strictly in terms of what is best for my day to day life. It's not worth it worrying about a few extra dollars a month when I only have a handful of subscriptions as it is.
In your .gpg-id file, simply list the keys you want to encrypt for on separate lines. Every file below that .gpg-id file in the directory hierarchy will be encrypted for any of those keys to unlock.
If you want more granular key strategy, look at gopass [1], which is a pass-compatible binary that gives a little more granular control over key usage (IIRC), and is written in Go.
[1] https://github.com/justwatchcom/gopass
Since I don't have the one time pass anymore the encrypted file is not usable anymore and I have the same key to both machines.
Please explain any holes with that flow.
- compatible with pass
- support for multiple stores
- store binary data (e.g. QR codes for seeding 2FA) : upcoming
- report / track issues on github.com/justwatchcom/gopass/issues
- more details here : https://www.justwatch.com/gopass/docs/
Free to use, auto password generation, has an iOS app with thumb print unlock (saves you from typing in a long master password).
I personally really enjoy it.
Basically their web add-ons are extremely buggy. I was using Firefox and after many issues tried Chrome version, that one looks nicer but is similar POS and similarly had its own set of issues. Perhaps I would be happier if there was just a standalone app that I would only fire up when I need it.
I stayed with LastPass through the various security incidents they've suffered, but recent UI updates finally made me cancel my paid subscription and switch to 1Password -- a standalone app that integrates with the browser through a very lightweight plugin.
The worst bugs in LastPass are:
1. Four months ago a bug was discovered by project zero[1] about how all of your passwords can be stolen just by making a user visit a webpage. Moreover, any code can be executed remotely, compromising your entire computer. Discussion[2]
2. Later on the day vulnerability (1) was published, another was found. Project zero bug report. [3]
3. Last year a software engineer who wasn't a security researcher found a bug[4], which again, gives all your passwords.
4. The bug in (3) wasn't fixed properly, which lead to this [5]
Other bugs, but not as terrible as the ones I listed above
Jul 27 2016 [6]
Mar 25 2017 [7]
Jun 17, 2015 [8]
Nov 17, 2015 [9]
You are also forgetting a whole another class of attacks - Phishing [10]
[1]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
[2]: https://news.ycombinator.com/item?id=13924737
[3]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
[4]: https://labs.detectify.com/2016/07/27/how-i-made-lastpass-gi...
[5]: https://bugs.chromium.org/p/project-zero/issues/detail?id=11...
[6]: https://bugs.chromium.org/p/project-zero/issues/detail?id=88...
[7]: https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
[8]: http://www.businessinsider.com/security-expert-describes-las...
[9]: http://www.martinvigo.com/even-the-lastpass-will-be-stolen-d...
[10]: https://www.seancassidy.me/lostpass.html
I also use Arq [3] to automatically backup to S3 every hour, and I also do manual backup to my external backup drives once in a while.
I don't, and wouldn't, use dropbox or any other non-free non-self-hosted system to manage the storage or synchronisation of my secure data, so it's unison(rsync) and/or ssh'd between desktop and laptop.
Yeah, the KeePass database is encrypted and I secure it with both password and keyfile, but I still want something that won't leave my database "out there" available for bruteforce attempts or other attempts at it.
I don't trust the servers (Dropbox or my), and thus I want it encrypted on my computer prior to sending it out on the Internet.
My Dropbox is secured by MFA, with the Dropbox password itself being a random password within the KeePass keyfile. I store the whole Keepass program for Windows inside the same Dropbox account, feel free to indicate that as a security gap. On mobile I use the KeePass2Android app.
I think the feeling is the same as the feeling of just leaving your SSH private key "out there". Sure, it's protected with a passphrase, but I still don't want to do that.
Can you trust Dropbox would never have security issues? See https://blogs.dropbox.com/dropbox/2011/06/yesterdays-authent...
Didn't matter if you have MFA or use a secure password.
Crashplan is my backup tool of choice and also backs up the Dropbox, just in case...
For everyone else KeePassXC is really nice.
I really like that there are so many "clones" and variants that can read/write the file format natively: https://en.wikipedia.org/wiki/KeePass#Unofficial_KeePass_rel...
As asked you can just use gpg https://www.gnupg.org
Here is some documentation on the Dropbox sync for example: https://support.1password.com/sync-with-dropbox/
I get that they want to transition people to that revenue model for their own benefit, but they haven't made a convincing argument that it's in our interests and they've definitely made those of us "offline" customers feel like second-class citizens. Normally, I'm all for subscription services, but password management is one area that I want complete control over and if they keep pushing me towards a model that requires their online presence, I'll end up switching.
Nothing about that made me happy.
And shameless plug for my own cross-platform powershell-based 1Password client, which can read both formats of local vaults: https://github.com/latkin/1poshword
My workaround was to write a small utility that I run on both my Mac and Windows boxes that sits in the background and keeps the two clipboards synchronized. So I just copy from Mac 1p and paste in Windows. Not ideal, since it makes the browser extension useless, but it works well enough for the few times that I need to enter passwords on that box. But on the plus side, I can also use it for entering commands in cmd.exe and Powershell too.
Funny enough, 1P6 worked fine with my local/Dropbox vault during beta, then the app stopped letting me update my vault when it left beta. :\
It uses Alfred to get fast, autocompleted access to passwords.
As for keeping the passwords around, you can do one of a couple things, but I generally just forget the password after logging in with it everywhere. I'm signed into chrome, so what's the point in remember the password myself? Unless it's something sensitive I don't bother. It's easier to generate a new one than to dig it up.