• mazzilius_marsti@lemmy.world
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    4
    ·
    edit-2
    4 hours ago

    lots of people recommend bitwarden, but i am more at peace with an offline password manager that i control like Keepass. You can also go the GNU route and use “pass” on Linux too

    Or use a physical key like Yubikey to login

    • peskypry@lemmy.ml
      link
      fedilink
      English
      arrow-up
      36
      ·
      edit-2
      4 hours ago

      No. Offline password managers are also suspectible to supply chain risk.

    • aeiou_ckr@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      4 hours ago

      Only if yubibkey worked for more than the handful of sites/services. I have one for my bitwarden as majority of places want to send a text or us totp.

    • mlg@lemmy.world
      link
      fedilink
      English
      arrow-up
      5
      ·
      4 hours ago

      I’ve been trialing Vaultwarden for a while and while I do like the server sync setup and clean web access, the Bitwarden browser plugin is just okay despite being an “enterprise” solution. It misses probably about 20% of websites when creating a new account, forcing you to grab the password from the generator history and make a new entry manually.

      KeepassXC is much better in that regard, and it’s almost as good as the default credential handler of Firefox, and it lets you set up a bunch of custom stuff to extend the functionality if you want. Plus it has some neat kbdx options aside from AES256.

      Only downside is syncing, which I’m debating how I’ll deal with something better than syncthing on android (protocol is great, android makes it a PITA to have a background process if its not Google spyware).