varx is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

Hello !

Currently looking for a password manager I had heard of Keepass, Lastpass and the sort, but found Password Safe and "made by Schneier" caught my attention, any feedbacks on it ? On password managers in general ?

@dustofgoat I'd stay the hell away from LastPass (their security posture is terrible). 1Password gets recommended a lot, but it's closed-source, which makes me leery.

Personally, I just use Firefox's built-in password manager. I like the idea of using one that *isn't* connected to the browser, though, at least for more sensitive passwords. But at that point I might as well just use Emacs' GPG integration and keep it in a file. :-P

@varx @dustofgoat 1Password (the non-cloud version) gets 👍👍 from me

@jerry @varx
I will try to stick to FOSS and Keepass(XC as @bugshiv suggested to me). I planned on avoiding LastPass too from the very beginning (cloud ...)

thanks for your advice :)

varx @varx

@dustofgoat @jerry @bugshiv And not just cloud, but buggy, vulnerable cloud: brainonfire.net/blog/2015/12/1

That was almost 2.5 years ago, and they still haven't fixed their -Security-Policy header to mitigate XSS -.-

· Web · 0 · 1

@varx @dustofgoat @jerry using a hosted solution for password storage is never a good idea - you can't audit it and their DB can always be found leaked/stolen.

with KeepassXC you can audit the code and you're the one in control of the DB file.

@varx @jerry @bugshiv
Yes I guess saying it to you is kinda pointless but adopting cloud solutions for this purpose just to avoid the inconvenience of having to carry the db file around sounds dumb

@dustofgoat @varx @jerry you can use syncthing to avoid having to carry the file around.

@bugshiv
@varx @jerry
Way overkill for me and my lone laptop but nice to know, thanks for sharing :)