cross-posted from: https://infosec.pub/post/42164102

Researchers demo weaknesses affecting some of the most popular options Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.…

all 25 comments

sorted by: hot top controversial new old
[–] 53 points 5 months ago (1 child)

I appreciate the air of publicity this story brings.

You probably can't trust your password manager if it's compromised

In other headlines: water is surprisingly wet.

  • source
  • hideshow 2 child comments
  • [–] 26 points 5 months ago

    KeePassXC ftw

  • source
  • [–] 19 points 5 months ago (3 children)

    I always keep my keepass databases offline for good

  • source
  • hideshow 6 child comments
  • [–] [S] 2 points 5 months ago (2 children)

    I need to search this KeePass. I read it in other comments, but I have never heard of it before.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 7 points 5 months ago

    In other news. Water is wet

  • source
  • [–] 1 point 5 months ago

    I use Pass since a few years. It has a wonderful package for Emacs, and great iOS apps with face ID for ease of use, and the DB can sync to your own private git server behind tailscale. If you have a server, I definitely suggest looking into it. You can check it out at https://www.passwordstore.org/

  • source
  • [–] 0 points 5 months ago (3 children)

    Am I the only person here that never used one just because of this? They all sounded too sus to me.

  • source
  • hideshow 6 child comments
  • [–] 15 points 5 months ago (1 child)

    You can use local ones like KeePassXC.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 3 points 5 months ago (1 child)

    I have a degoogled phone with e/OS. I might try if they get a bit further into my use of their products and security. It sure would simplify methods.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 5 months ago (1 child)

    I have a similar setup with LineageOS. I use KeePassXC on PC (KeePassDX on Android). I can sync them via Nextcloud with peace in mind because the database is already encrypted. Syncthing-fork also works if you want completely local.

    I'm sure e/OS already has a password vault app in their list but if not KeePassXC is fully local out of the box and can be used with DX on Android.

    It's far secure than Firefox's built-in password manager.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 1 point 5 months ago

    I've only been using e/OS for a few months. Once I gain more confidence in the OS I can certainly try. I'm still super paranoid. It's a lineage fork so there is update lag and possible security limitations in the OS itself. I'm just not sure yet.

  • source
  • parent
  • [–] 7 points 5 months ago* (last edited 5 months ago) (2 children)

    Keeping them in your head? So, your passwords must be shit, lmao.

    Zero threat prioritisation.

  • source
  • parent
  • hideshow 4 child comments
  • [–] 4 points 5 months ago (1 child)
  • [–] 1 point 5 months ago

    I have a few that I just have off the wall for a few things and I memorize those. Some I just use ssh keys. Others go off a pattern and I put hints in a file to figure it out. The account itself is not even put in this file, so I have to just know what the hints mean for both the account and what password pattern hints go with them. Usually, the user IDs are something I store in this file, because those get too tough for the aforementioned methods of determinism.

  • source
  • parent