Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.
Bitwarden
pass: the standard unix password manager for tech-savvy people. It’s dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.
with that you need to type the unlock password for every single read and search, right?
No, you can configure the timeout in
gpg-agent.conf. I’ve set mine to a few hours.
Keepassxc/keepassdx, synced with syncthings/basicsync.
Using a headscale/tailscale setup so things stay synced even when i am not home.
keepassxc
BitWarden and a self hosted VaultWarden
Fun part of that sollution is that you only need one app.
You also need a secondary service on your server if you want to keep them in sync.
Not really. Bitwarden is hosted by Bitwarden, why would you want to run the sync yourself? Vaultwarden is self hosted anyway.
I assumed that’s what you meant by saying bitwarden and Vaultwarden.
With gnupg, git, and a hardware security token. Also known as “pass”.
A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.
The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.
One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.
What do you use on a phone?
Syncthing-fork from Fdroid.
There were some repository ownership questions a few months back that were ironed out. In addition, Fdroid vets apps far better than Google ever has so I’m comfortable with the app’s security.
In addition, Fdroid vets apps far better than Google ever has so I’m comfortable with the app’s security.
I agree but they aren’t checking every version for malicious changes. they would likely only get to know if a user checks it and notices it, and the developer could just make the change for a single release version.
of course that applies to any app but this handover/takeover was very sketchy.
Oh, sorry, I meant the password manager. There’s multiple KDBX compatible apps.
KeePass2Android. Recommended by KeypassXC.
Mostly i get by by not telling others how or where I keep my passwords
Do you add 1 and then ! or ! And then 1 to secure your passwords?
I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again \s
Vaultwarden
I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again
I’ve already seen someone do that, a certain family member. At first I found it funny when they asked an LLM about their WiFi password, which was some gibberish. But it worked. There’s no way something like that would be default across entire product line.
Indeed, when I asked, I got “I gave it screenshots of everything because I didn’t know what to type where”.
I use KeePass database for all my passwords and other database for recovery passwords (like from 2FA codes etc). I have it synced in my Nextcloud and ProtonDrive (In case my Nextcloud would fuck up).
Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.
1Password family account with spouse, kids, and my parents. Vault management, ease of sharing, and remote management for my parents is nice, along with multiplatform for everything important, and the price feels quite reasonable at $1/user/month. No major security incidents ever, and I was pleased by their core service design whitepaper that I read many years ago. But as they’ve become increasingly corporate over the past several years I’ve felt like they care less and less about individual users, and the CEO’s recent pledge to Omarchy really pissed me off. So it’s been a great service for me but I don’t recommend it for new users unless they like nazis. I pay for a year at a time so I haven’t scrambled to migrate my family to a new solution quickly, but it sounds like Vaultwarden is most likely the way to go next.
KeePass database in cloud storage, synced to my phone.
I write down a password hint on a physical piece of paper.
Since the primary threat vector is remote access and not physical access, I’d argue that is fine.
Additionally the password hint has to pass through several thought chains in order to provide the actual password.
I do wish sites would up front tell you what the password requirements were when you logged in though.
Proton Pass for me since I use their VPN.
Vaultwarden for selfhosting.






