I like the simplicity of password-store. It's just a simple wrapper around a text editor, gpg, and git that allows you to make an encrypted, version controlled password repository that you can sync between devices using GitHub/Gitlab/etc. It also doesn't lock you in to any app since the passwords are just stored in gpg-encrypted files.
Android
DROID DOES
Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules
1. All posts must be relevant to Android devices/operating system.
2. Posts cannot be illegal or NSFW material.
3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.
4. Non-whitelisted bots will be banned.
5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.
6. Memes are not allowed to be posts, but are allowed in the comments.
7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.
8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.
Community Resources:
We are Android girls*,
In our Lemmy.world.
The back is plastic,
It's fantastic.
*Well, not just girls: people of all gender identities are welcomed here.
Our Partner Communities:
I also use Bitwarden. I would recommend it to anyone who can benefit from a cloud-based password manager because the basic functionality is free and the more advanced features (premium, family) are very affordable.
Using Bitwarden safely will make your digital life safer, but it will most likely be more complicated than it is now. You will need to:
- Use a randomly generated password for the master password, which is intuitive but increases your safety
- Enable two-factor authentication (2FA) for all of your accounts that offer it.
- Make an encrypted backup of your Bitwarden vault.
- Create an emergency sheet with your master password, 2FA recovery key, and other important information.
- Plan for what will happen to your passwords if you become sick or die.
You can think about increasing your safety/convenience step by step by keeping a book of password (which can be lost, so has to be kept secure and probably make backup) with
- Random password/passphrase generator
- Yubikey + recovery numbers
- Drop the book, use an offline password manager (which some consider safer)
- Switch to cloud-based cross-platform password manager, which maximizes convenience
What are my thoughts on a password manager?
I think it’s both a good thing, and a crutch. I feel the fact that most services are rendered unusable without an account is sad, and with the 100’s of accounts one is expected to have a password manager is sadly needed if you can’t memorize a password or can make passwords with a consistent pass phrase.
Do I use one?
Nope, I have a password system which is good enough for most accounts that’s always more than 7 character long and unique for each account without being lost to me. The only time it has failed as when my work decided to have us change our passwords every quarter, and I ran out of password ideas.
KeePass is the perfect tool for me ! The cybersecurity practice at work also use it,
I use KeePassXC and synchronise it with syncthing. This allows me to keep it off devices I have no control over (OneDrive servers) and also allows me to have per device version history.
Bitwarden, open-source, free, and awesome!!!!!
I used to use BitWarden but switched to 1Password about a year ago once I decided to buy a business account for my department at work (which gives every user a free family account)
1Password is fantastic. It stores more than passwords, it's fine tuned to do that, but really can be used to store anything securely. The dev team uses it to share secure .env variables and API keys for example.
One of the best features though is the ability to share secured links to VIEW passwords outside of your network. When a coworker asks me to share an account password I don't just copy and paste the username and password over email. I click share in 1Password and shoot them a link that only they can view (using email 2fa). I can also make more open links to shared credentials that expire (or until I expire those links myself).
The phone app works great and once you get it set up on one device it's easy to configure it on others.
Switched to bitwarden last October and couldn't be happier. Was previously just storing everything in chrome/my Google account. Reused the same password on pretty much every website. When I saw a few articless about chrome causing issues with ad blockers I decided to switch to Firefox which meant having to figure out my passwords. Decided that was a great time to figure out a separate password manager. I still occasionally run into websites I don't use often that still have my old password but for the most part everything is switched over and if 2FA is an option I have it set up. Going through my main sites was a drag but I felt so much better afterwards. I was really shocked at how many websites have really low limits on password length. And how some of the accounts I would really really prefer to have 2FA it's not even an option, looking at you banks.
My work actually just switched payroll companies and when creating my account I noticed the password field was 0/127 so of course I bumped up my password generator to 127 and maxed out the password field 😂
https://play.google.com/store/apps/details?id=keepass2android.keepass2android
Been using this for years. Hosted via ssh on my server in a ovh data center. Fingerprint access and every single account with a random password.
I use KeePass (more specifically KeePassXC). I manually copy my password files around like a caveman but I don't mind. At least my kdbx files are not accessible easily.
I've used LastPass in the past but now I use bitwarden, gets the job done
I've used 1Password for years. Works well on all my devices (MacBook and Samsung Galaxy phone). I'd absolutely recommend you use one.
Not only are they great for handling complex passwords, but a benefit I've not seen mentioned here is that they are a way of just keeping track of just how many sites and accounts you've registered with.
For example - You buy one product once from an online store, save a password so you can monitor the order status but never use that site again. Before I used 1Password I'd just have forgotten I'd even used that site. But now I can just look down my 1password account and see a whole list of all these passwords and accounts ive created. And there's loads. You forget just how many online accounts and passwords you have out there.
If you are not using a password manager you are doing it wrong.
Any security researcher worth there salt says to use one .Not sure what the question is. Bitwarden and 1pass are general good recommendations.
I've been a KeePass user for over a decade and it's always been good to me, especially when using Box and OneDrive to sync it between devices. The ecosystem is great with enough plugins and support to make it fit your use case on any modern OS.
Can't recommend it enough. Especially over other options that are offered by a commercial company (LastPass for example). Not only because you're intently placing your trust in them to not expose your data and keep it secure, but also because you're giving them a lot of leverage to turn around and hold your passwords for ransom at some point in the future (when they IPO for instance, as a popular example) or lock you out after they fold for whatever reason.
I couldn't live without one these days. I personally use Bitwarden. I have tried most of the other manager suggested in this thread. They each their own benefits. I would recommend one of the hosted services for most people (1password, Bitwarden, not LastPass). I came to prefer Bitwarden for their combination of features and openness. I have self hosted it in the past, but these days just use their hosted service.
There are a lot of side benefits to using one besides just remembering your usernames and passwords for you too.
- It lets you use catch-all emails if you have your own email domain
- allows you to give services their own address to track abuse
- makes you more resistant to someone taking your leaked credentials from one site and using it for another
- easier spam filtering
- Most password managers support random password generation
- Saving things that aren't logins
- Family member's SSNs and DL numbers
- Credit cards
- Wifi passwords
- Gate codes
- Sharing always up to date passwords and other secrets with people (for hosted options)
- 2FA is easier
I can't imagine not having a password manager. I even got my mom to switch to bitwarden. I'm not sure if I just don't know how to do it, but the only thing I wish I could do with bitwarden is share a password with another bitwarden user.
1Password for years, never had any issues.
Started with LastPass, used it for 10 years. Switched to Bitwarden a while ago, would never go back.
After using one for like 8 years I really don't know how people have the time/energy to make up and remember all their own passwords
I use Firefox's built in password manager because its crossplatform and I can use it on all my devices.
Yes, 100%... In fact, I often do recommend it to others. Personally I use Bitwarden (paid account even) but I've also recommended 1pass to apple only users because it fits well in that ecosystem.
You can use them to generate a different password for each and every login. And it's really just random letters, number and special characters. That one site gets compromised? They can't then use those credentials to login anywhere else.
You don't have to remember those passwords. Passwords that are easy to remember are probably found in dictionary attacks. You know what's not? Wt2Pwi#$a@Nzeq7*8UwSJ7sTsMKdC!HSGZZ7JnzCtxhfCfFCiXP&FD!yM!c^$DisSR@2
(which I just generated with bitwarden)
2-factor auth is also really easy with most password managers and makes logging in with 2-factor auth easy. I hit one hotkey to fill in the web form with my username/password, hit enter to login and then it auto-copies my TOTP code so I can just paste it and go. Super secure but super easy.
You go to a phishing site? Guess what, a good password manager will store the url and if it doesn't match, that should be your first red flag. If I end up at g00gle.com instead of google.com, it won't show as having a login available.
KeePass. Putting your passwords on someone else's webserver is just asking for trouble.
I haven't heard anyone mention Google password manager, which is the one I started using recently. I assume very few people trust it because... Google?
I’d say they’re pretty much necessary so you can have unique, complex passwords.
I’m currently test driving Proton’s new password manager, I’ve been using 1Password for ages.
It’s 1Password for me. Looks good, works good and is available for every platform that I use.
For work I use KeepasXC and Bitwarden+Vaultwarden as well.
I use Chrome password manager. Is there any difference to this vs. Bitwarden or other services? Chrome is super convenient since it suggests passwords in browser while signing up and auto-inputs them to apps/websites cross platform. And also integrates with GBoard to quickly search password to copy into a field.
Not sure if Bitwarden has any additional features other than the benefit of not keeping all my info with Google. Or if it's less convenient and I have to go into the Bitwarden app or something everytime to look up or generate passwords?
Butwarden. Always Bitwarden. Just like almost everyone else in here it seems like.
My nickname in HS was Buttwarden.
Started with LastPass many years ago - but has changed to 1Password just last week.
Bitwarden and Dashlane were close contenders, but I found that 1Password's sharing feature was better in my usage scenarios.