hazel,

Could anyone give me recommendations for a password manager? Google is basically useless now and I don't know anywhere else to ask. 😅

So far, I've never found one that I trust enough to use. I do understand the importance but I'm extremely, incredibly hesitant to hand over my passwords to a 3rd party program. I'm even more hesitant to use randomly-generated passwords that I can't memorize as a backup.

All that being said, here's what's important to me:

  • Transparency - public audits, published whitepaper, and/or open source.
  • Export to a printable format. I don't have reliable backups, so this is a must-have!
  • Works with desktop & mobile Firefox.
  • Works on Windows & Linux (I regularly use both).
  • Works on Android - not critical, but would be really helpful.
  • Can work offline (I don't trust any sync server to stay online).

For everything else, I'm more flexible. I don't mind paying a small amount for a better / more trustworthy option, either.

Any suggestions, recommendations, or just boosts are appreciated! Thanks so much in advance! 💙

blinkygal,
khamis_joe,

@hazel I love KeePassXC ( https://keepassxc.org/ )

jeff,

@hazel

I’ve seen a lot of recommendations for Bitwarden. That is what I use personally. Have for a few years now.

I have no complaints at this time.

breuxi,

@hazel Bitwarden! I can only speak for selfhosted vaultwarden on server side, but this alone works perfectly in daily life switching fast between windows, linux, macos and android!

compilation_error,

@hazel
@bitwarden is a great option. Open source and cross platform!

hazel,

@compilation_error @bitwarden thanks for the suggestion!

jwd630,
@jwd630@mastodon.social avatar

@hazel I switched the family to BitWarden a year ago (when the LastPass fiasco got going big time.) Research suggested the likely choices were that or 1password. My criteria included the hit by a bus scenario: if I wasn't around to be the helpdesk (and/or my vault was locked) would my family have some sort of resource and community they could look to for help. Its ease of use and their apparent willingness to listen to security concerns have not disappointed me yet.

hazel,

@jwd630 thanks for the recommendation! BitWarden and 1Password are currently my top choices. Family use isn't a top priority, but it would be a nice bonus. I appreciate the note about their security response. I didn't put it in my post, but I pay very close attention to how a company responds when (not if) they are compromised. Trying to cover up or downplay it is a huge red flag, whereas responding openly and swiftly is a huge plus.

gatesvp,

@hazel
I use (& pay for) 1password.

To the best of my knowledge, it does all of these things. It also supports family accounts, so you can give vaults to loved ones and also share passwords with others.

hazel,

@gatesvp that might be useful! I share some accounts with my wife and it would be very nice to keep those passwords in sync.

gatesvp,

@hazel

👍 to "wife access", I also have kids and have started putting this on their computers as well.

Also, the "printable backup" may not be obvious. They call it the "emergency kit".
https://support.1password.com/emergency-kit/

hazel,

@gatesvp thanks for the info about the "emergency kit", that would definitely have confused me!

yatil,
@yatil@yatil.social avatar

@hazel @redcrew 1Password is my recommendation. Syncing is through their servers but there is a secret key that only lives on your devices. Super reliable and also on the Fediverse: @1password

hazel,

@yatil @redcrew @1password thanks for the recommendation!

blake, (edited )
@blake@1password.social avatar

@yatil @hazel @redcrew Thanks for the shoutout, Eric! 💙

To hit some of the points Hazel was looking for:

• Security Audits: https://support.1password.com/security-assessments/

• Exportability/Printability: You can export in CSV or JSON, or you can print items directly from 1Password.com | https://support.1password.com/export/

• Whitepaper: https://1passwordstatic.com/files/security/1password-white-paper.pdf

• Available Everywhere (yes, that means Linux too): https://1password.com/downloads/

• Offline Access: https://support.1password.com/explore/membership/#unlimited-devicesbrunlimited-freedom

hazel,

@blake @yatil @redcrew Thank you for the information!

blake,
@blake@1password.social avatar

@hazel @yatil @redcrew Anytime! Always happy to help. Lemme’ know if there’s anything else you’re curious about! 🙌

cormac,

@hazel I recommend BitWarden.

It has audits and is published on thier site.

Supports exports to .csv .json and encrypted .json

Not sure about mobile Firefox but works with everything I own (Android, Linux, Windows, desktop firefox)

Works offline - it's local first, sync later.

hazel,

@cormac thanks for the recommendation!

amxmln,
@amxmln@mastodon.design avatar

@hazel have you heard of https://padloc.app — I'm not sure if it fulfills your requirement of printable exports, but it should tick all other boxes. 😊

hazel,

@amxmln I hadn't heard of that before, thanks for the suggestion!

russ,

@hazel I settled on Bitwarden after trying a few others.

abhijit,

@hazel I've been using Bitwarden for a while now and it has never let me down. It has extensions for almost all browsers I've had to use and apps across all devices. Plus you can host it yourself if needed to ensure maximum security.

tutwilly,
hazel,

@tutwilly thanks for the link!

darwinwoodka,
@darwinwoodka@mastodon.social avatar

@hazel

1password

tkk13909,
@tkk13909@fosstodon.org avatar

@hazel I use ( on my phone and on my laptop) and sync the file using but I've also heard good things about

hazel,

@tkk13909 thanks for the recommendations!

M4rkF,

@tkk13909 @hazel
bitwarden works great for me. You do not have to self-host if you dont want to.
2FAS for OTP allows off-line backups that you can carry around and backup as necessary.

hazel,

@M4rkF @tkk13909 thanks for the info and recommendation!

UP8,
@UP8@mastodon.social avatar

@hazel I have a python script based on an idea from CACM in 2005 or so which takes the domain name of the site you want to log into, asks for a secret phrase, concatenates them and puts them through a hash function to make 8 random characters.

some problems are: some sites want more characters, some sites don’t like the characters it uses (either it uses ones they don’t accept or they want something specific), also what to do if you have to change your password

hazel,

@UP8 that's a neat concept!

UP8,
@UP8@mastodon.social avatar
hazel,

@UP8 thanks!

drikanis,

@hazel
I use bitwarden. End to end encrypted, Firefox extension, open source.

hazel,

@drikanis nice, thanks for the recommendation

julian,

@hazel I personally am using the KeePass-Ecosystem for my password managing needs. KeePass databases are just files, which you open with a primary password, so they work offline just fine.

On my laptop and desktop I'm running KeePassXC, which is a great cross-platform KeePass password manager (supports Linux, macOS and Windows). It also allows for exports to a plain text file I'm certain and it comes with an accompanying browser extension, which then allows you to fill in your passwords on different websites.

For mobile - as an iOS user - I use Strongbox, which is also amazing as well, tho I also have friends using KeePass on Android, so I'm assuming you should find a good client there as well.

And then finally for making sure my passwords are synced, I simply store them in my Nextcloud (tho you could also use a cloud provider or maybe even something like Syncthing I would assume).

That's kinda like my personal setup, which would also fit your needs pretty well from what you've written.

hazel,

@julian Thanks for the recommendations!

highway2009,

@hazel I use keepass and the db is synced with syncthing. This is p2p so no single point of failure.

hazel,

@highway2009 Thanks for the suggestion! p2p is interesting, although I'd be nervous about exposing the db like that. If there's ever a vulnerability in the encryption, then all of my credentials would be exposed.

charles222a203,

@hazel 1password is excellent.

hazel,

@charles222a203 thanks for the recommendation!

charles222a203,

@hazel you're welcome!

epixoip,

@hazel my personal recommendations, as a noted password security expert and password cracking tool developer, are Bitwarden, 1Password, and Dashlane. hope that helps!

hazel,

@epixoip Thanks for the suggestions!

flimpie,

@hazel @alice depending on how unixbeard-level you’re willing to go: private GitHub/GitLab/sourcehut repo and https://www.passwordstore.org, it is not a app on itself but just a standard saying “store passwords in GPG-encrypted files and store those in git”

it has applications that run on most platforms and I believe they also have browser plugins - not sure how good they work, never used them

hazel,

@flimpie @alice Thanks for the suggestion, although I'd definitely prefer an out-of-the box solution rather than something custom.

rdfhrn,
@rdfhrn@hessen.social avatar

@hazel I'm using passmann app in nextcloud and for my private passwords etc enpass. The vaults (yup, multiple) are on nextcloud

natty,
@natty@astolfo.social avatar

@hazel Bitwarden ticks all of those boxes, can recommend ​:blobfoxfloofhappy:​

It only needs to be connected online for write access, but read access is always available

Exporting works as a CSV, JSON or encrypted JSON
Has a desktop (although Electron) client, Firefox extension for desktop, for Android it integrates via the autofill framework

hazel,

@natty thanks for the recommendation!

It only needs to be connected online for write access, but read access is always available

That's totally fine, I just don't want to lose my credentials.

Exporting works as a CSV, JSON or encrypted JSON

Perfect, I can work with that.

Jessica,
@Jessica@kitsunes.club avatar

@hazel I hear proton password manager is good and free, and I personally use Bitwarden because I’m lazy

hazel,

@Jessica I've never heard of proton password manager before. Is it related to proton VPN?

Jessica,
@Jessica@kitsunes.club avatar

@hazel yes

hazel,

@Jessica ah ok. I don't really trust that company, but that's just a personal bias.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • security
  • DreamBathrooms
  • InstantRegret
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • modclub
  • Youngstown
  • ngwrru68w68
  • slotface
  • osvaldo12
  • kavyap
  • mdbf
  • thenastyranch
  • JUstTest
  • everett
  • cubers
  • cisconetworking
  • normalnudes
  • Durango
  • anitta
  • khanakhh
  • tacticalgear
  • tester
  • provamag3
  • megavids
  • Leos
  • lostlight
  • All magazines