• mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    22
    ·
    edit-2
    12 hours ago

    lots of people recommend bitwarden, but i am more at peace with an offline password manager that i control like Keepass. You can also go the GNU route and use “pass” on Linux too

    Or use a physical key like Yubikey to login

    • peskypry@lemmy.ml
      link
      fedilink
      English
      arrow-up
      55
      ·
      edit-2
      12 hours ago

      No. Offline password managers are also suspectible to supply chain risk.

    • aeiou_ckr@lemmy.world
      link
      fedilink
      English
      arrow-up
      9
      ·
      12 hours ago

      Only if yubibkey worked for more than the handful of sites/services. I have one for my bitwarden as majority of places want to send a text or us totp.

      • neclimdul@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 hours ago

        Also they only half work in Linux I guess? Something about not being able to create something.

    • mlg@lemmy.world
      link
      fedilink
      English
      arrow-up
      7
      ·
      12 hours ago

      I’ve been trialing Vaultwarden for a while and while I do like the server sync setup and clean web access, the Bitwarden browser plugin is just okay despite being an “enterprise” solution. It misses probably about 20% of websites when creating a new account, forcing you to grab the password from the generator history and make a new entry manually.

      KeepassXC is much better in that regard, and it’s almost as good as the default credential handler of Firefox, and it lets you set up a bunch of custom stuff to extend the functionality if you want. Plus it has some neat kbdx options aside from AES256.

      Only downside is syncing, which I’m debating how I’ll deal with something better than syncthing on android (protocol is great, android makes it a PITA to have a background process if its not Google spyware).

      • KyuubiNoKitsune@lemmy.blahaj.zone
        link
        fedilink
        English
        arrow-up
        4
        ·
        7 hours ago

        It misses probably about 20% of websites when creating a new account, forcing you to grab the password from the generator history and make a new entry manually.

        This makes me so fucking angry. How can a password manager be so bad at storing passwords, it’s like it’s only job. It even is generating the password for you! Aaaaaaaaaaaaaah!