Ask HN: How do you manage your passwords in 2023?
89 points| pentab | 3 years ago
- secure
- easy to use
- accessible on multiple devices (home PC, work PC, and ideally phone)
I currently use a mixture of KeePassX (synced manually using SSH) and stored passwords (e.g., in my browser). But I keep thinking that there MUST be a better solution.
princevegeta89|3 years ago
I'm confident even if BW goes down I can still recover my data since the vault works offline too. While the browser extension could use some UX work the mobile apps have been top-notch and sharing passwords with my spouse has been a bliss.
I bought myself a dedicated server earlier in December and will be migrating to Vaultwarden pretty pretty soon.
luckman212|3 years ago
Can I ask why the desire to switch to Vaultwarden? I assume if a significant slice of the userbase did this, the project would suffer—so I'm asking this question genuinely as an avid Bitwarden supporter myself.
I hope they don't have to rely solely on VC funding, seems that VCs motives would be precisely orthogonal to my own in terms of privacy and feature roadmap.
zeeZ|3 years ago
mamcx|3 years ago
I wonder which one is truly transparent (I work mostly on Mac/iOS but still need other platforms)
redsparrow|3 years ago
robertlagrant|3 years ago
acjohnson55|3 years ago
My big goal now is to come up with a better solution for 2FA that works for me and my wife's shared accounts.
atonse|3 years ago
I understand the idea of putting both factors in one place is odd, but I feel it strikes the right balance between the convenience and security.
hartem_|3 years ago
ebfe1|3 years ago
HaloZero|3 years ago
clairity|3 years ago
i use 1password's built-in 2FA (TOTP), but only for a couple accounts as i find it unwieldy generally. i'm also keeping an eye on how passkeys develop over time.
LinuxBender|3 years ago
If KeePassXC one day becomes unmaintained I will make my own custom tool, probably using sqlite+openssl+bash. I only log into one semi-sensitive thing on my phone so I don't bother syncing to that device.
pentab|3 years ago
joshbaptiste|3 years ago
edent|3 years ago
It does all the things you ask for. With the paid version I can share passwords with my spouse for relatively unimportant things (like Netflix) in a reasonably secure manner.
I could self host and run it myself. But I'm not a multi-person team with decades of security engineering experience. So I gladly let someone else take on that burden.
princevegeta89|3 years ago
I'm very positive Bitwarden won't get hungry for money looking at their revenue models, but there's always Vaultwarden you can self host. It's pretty popular and secure. I'll be deploying soon for myself.
Corrado|3 years ago
tomduncalf|3 years ago
e3bc54b2|3 years ago
LightHugger|3 years ago
Octabrain|3 years ago
entropie|3 years ago
hnbear|3 years ago
The biggest challenge with passwords was finding a tool for the whole family, which is more important than the most secure. If not, then it won't be used and we'll be back at the days of sharing "the family password" on everything. Yes, that password is on HIBP.
As a couple we have a shared vault that most things go into. We have equal access, she's a full admin.
As a family we have a shared vault for lower-tier things that the kids also need access to.
They all know to create passwords in 1Pass and save them into their vaults. It's not always perfect, but it's a great start. Generally we'll do 2FA within 1Pass, which is another weakness, but again, some 2FA is better than no 2FA, and OTP is vastly better than SMS.
Also saves a lot of problems with the kids (in this case ages 10+) not knowing their iCloud, Roblox, etc passwords. They're all saved, either of us can look them up.
The kids have had their accounts hacked and socially engineered, and also seen friends share their passwords which turn out to be their passwords to everything, and so get their more important stuff hacked (eg. as a teen their Snapchat seems pretty vital).
Overall 1Pass has a great security track record, their support has been friendly and useful, and I've had friends of friends I respect work their who are pretty trustworthy.
It's not the best app (but having used some others it's also pretty good).
Personally I have Yubikeys for 2FA for critical services that support them.
I also don't want to have to support this myself. Password access is pretty critical, and has a low SLA, must work. I've done on-call tech-support for over a decade, I don't do it at home. So, no home-hosted stuff.
maccard|3 years ago
My only complaint is that it doesn't let me use a yubikey as a primary method of authentication on windows - all my other devices have biometric authentication.
Topolomancer|3 years ago
varjolintu|3 years ago
dorfsmay|3 years ago
atonse|3 years ago
Used it personally for nearly a decade and introduced it at work. Happy 1Password Business users and that gives all our employees free personal accounts (that we can’t see or touch) as an added benefit.
renaissance_tea|3 years ago
I have wireguard VPN on all my devices tunneled into my server. I also self-host the VPN since vaultwarden runs on a local Docker intranet.
If people are interested, I was going to write a step by step blog.
Less technical, but I also get yubikey and duo 2factor push auth out of the box with Vaultwarden! (Open source rust implementation of Bitwarden)
was_a_dev|3 years ago
pentagrama|3 years ago
On mobile you can enable the option to auto fill passwords for apps, and let you use the fingerprint sensor to access the list quickly > select the account > auto fill :)
plibither8|3 years ago
No privacy or security issues now since I own all my data, no subscription fees, and no complaints till now with the self-hosted setup. Definitely would recommend!
[0] https://github.com/dani-garcia/vaultwarden
dwightgunning|3 years ago
With the recent LastPass exposure, the supply-chain attack on PyTorch, needing to be vigilent and avoid granting apps access to my cloud drive, I've actually just been reviewing my setup and workflow.
Here's what I'm planning to change...
Phone: Switching from MiniKeePass to KeePassium. I've found it's not too difficult to build KeePassium from source and install without needing an Apple Developer subscription. This means I can properly audit the code and control/verify all updates.
Laptops: Start building KeePassXC from source. In the short term, I'll be more diligent in obtaining updated versions from trusted sources and using PGP to verify the package.
File sync: Start storing the password file on a self-hosted file server. Having recently setup Tailscale on all my devices, it's now convenient to manage Samba and remove cloud storage from the system. In case the SMB share is inaccessible, I'll fallback to the backups kept by KeePassium and use cron+rsync to maintain an secondary copy on my laptop.
Backups: I'm planning to periodically backup to a hardware keypad encrypted USB drive. In comparison to a regular USB / external drive, the hardware encryption makes it harder for somebody to quickly make a copy of the password file and take it away to be brute-forced.
Would welcome any pointers on things I may not be considering or suggestions for improvement!
xnyanta|3 years ago
Used keepass and pass for years but got fed up with them. Switched to 1Password this year and never looked back.
hasbot|3 years ago
OJFord|3 years ago
thealig|3 years ago
antback|3 years ago
kolinko|3 years ago
andy_ppp|3 years ago
softwaredoug|3 years ago
https://chrome.google.com/webstore/detail/icloud-passwords/p...
firecall|3 years ago
How at risk am I?
If I move to something else, are those services not just at risk too at some point?
I’d hope LP would be doing more at this point.
IDK! Help!
throw_getAjerb|3 years ago
If you’re using Apple stuff almost exclusively (safari, iOS, osx) it seems to offer best integration. I have light password sharing needs. It can airdrop passwords to people In my contacts, but they won’t get password changes.
I made sure to make my device and Apple ID passwords very strong. I’m not sure which it encrypts with. But with FaceID, it’s not a big deal to make a iPhone passcode and actual long pass phrase and not a PIN number.
My main concern is I don’t feel I have a lot of transparency in how it works. And using passwords outside the Apple ecosystem will be difficult.
simsim981|3 years ago
For Linux and windows i would use keepassx.
outcoldman|3 years ago
- it does not understand that some accounts are used on multiple domains, does not allow you to modify domains, or have more than one. For example something like microsoft.com, live.com, microsoftpassword.com. I believe maybe microsoft cleaned it up and use now only one domain, but websites like that still exist.
- multiple accounts for the same website, just need to have a title to name them. Say you have 2 AWS account and each has a user root. How would you identify them?
- password sharing is a big issue as well, within the family.
Adraghast|3 years ago
At minimum, Apple needs to make Keychain a standalone app instead of a half-baked settings dialog for it to even be considered an option imo.
Spooky23|3 years ago
jon-wood|3 years ago
kqr2|3 years ago
https://www.schneier.com/academic/passsafe/
mike-cardwell|3 years ago
worldsavior|3 years ago
mbirth|3 years ago
On top of that, it supports syncing the database via iCloud, WebDAV, SFTP, Dropbox and a few other services. And it uses a bog standard KeePass2 database for storage, so you can use it with KeePassXC on Windows or any other KP2-compatible app. This also means that there's always a way to get to your data should Strongbox disappear.
commandersaki|3 years ago
The first password manager I started with is LastPass in 2014 when it was recommended to me by a password security expert in academia. I used a memorable human generated passphrase with enough twists to get about 80 bits of entropy, so if my old encrypted data is in the wild (doubtful), I'm not really concerned about the recent breach.
I've since been all in on 1Password since 2017 after LastPass was getting progressively worse and I sought out a new password manager. I've examined the security design whitepaper and most of the choices when it comes to cryptographic protocol design is pretty good, no real homebrew and should stand the test of time, but there's still better choices that can be made about protocols such as PAKE that'd be better in 2023. Anyways, 1Password UI is pretty good.
I also make backups of 1Password using the command line interface incase they decide to kick me off their systems or something happens where I can't make payments for years. The backups are then encrypted using the scrypt tool.
If I was to get off password managers completely, I wouldn't bother with these password management tools like Keepass etc. as they constrain you to their UIs and don't do an adequate job of doing things like browser autofills. I'd rather just go back to a plaintext file and encrypt/decrypt with scrypt or age.
haunter|3 years ago
This GUI for it under Windows https://github.com/geluk/pass-winmenu
And this iOS app on phone https://github.com/mssun/passforios
D13Fd|3 years ago
boxrdhn|3 years ago
nipperkinfeet|3 years ago
marssaxman|3 years ago
Online password managers never made much sense to me; one by one, they eventually all get hacked. And why not? A centralized service storing thousands of people's credentials makes a great big juicy target. Their security is undoubtedly better than mine, but my personal laptop is not likely to be worth anyone's time.
For the same reason, I don't let browsers store passwords either.
xerxesaa|3 years ago
fimdomeio|3 years ago
metadaemon|3 years ago
xoa|3 years ago
Passwords though will have a very long tail even in the most optimistic scenarios, so yes password managers aren't going anywhere for a while yet. What I use right now is 1Password 7 with a slow migration towards Bitwarden clients and a self-hosted Vaultwarden server. I still have a standalone license and still have shared vaults in Dropbox, I will not be moving to the electron based 1P8. So end of the line on that decade+ journey I'm afraid, I'm disappointed with what happened with them but so it goes. Bitwarden/Vaultwarden seem solid to me so far though, and have client support across a range of devices. Nebula or Wireguard make keeping a bunch of selfhosted services accessible in a reasonably secure way pretty easy, and almost more importantly once setup have been rock solid reliable for me. Wrapping my head around them and making sure I had it all figured out certainly took a bit of time early on, but once setup it's Just Worked™ without being touched a single time ever again. No specific 3rd party dependencies is attractive.
If you have family/friends/coworkers to deal with though obviously the needs of the group are going to have to factor in on some level, and you may find you need to either run a few different things or compromise somewhat/pay more.
edent|3 years ago
I hope this is the year that WebAuthN goes mainstream - but it'll be a long time before a plurality of sites support it.
greggarious|3 years ago
This doesn’t work well on mobile though since hashed aren’t typable.
One of my New Years todos today is to set up a mnemonic for my phone.
That, paired with disappearing messages and making individual apps require a touchID will make it very difficult for folks to be… nebby.
Biometrics are easy to spoof or steal, whereas a fourteen digit mnemonic of the Shakespeare lines you used to quote will be easy to type, easy to remember, and take years and/or a Targeted effort to crack.
(Also I hope it goes without saying that nothing from Bill ever unlocked my box - examples are fictionalized.)
lampshades|3 years ago
The password manager is enough for me and just works (tm) with all my devices. It even supports 2fa. I used LastPass until the most recent hack. I prefer iClouds keychain so far.
The only problem is using Chrome. There are no extensions for keychain so I have to copy paste the password into Chromes manager if I want to use it. But Safari works for most of my purposes anyways.
I’ve only been on this setup for about a week but so far I love it. It’s so simple and works, I doubt I’ll ever move.
tsuujin|3 years ago
There are some UX things I would like to see improved, notably I would really like to manually edit the list of domains for a given password. Overall though I have been very happy and I feel like my daily needs are simplified.
sph|3 years ago
My email and Bitwarden itself are secured by two Yubikeys, one is always on my person on my keychain, the other is physically stored away from my house. I have an AirTag on my keychain because losing your keys is a pain in the butt.
This is a cheap yet very secure system for most people that care about security but are not persecuted by police or government agencies.
PaulKeeble|3 years ago
sureglymop|3 years ago
tejado|3 years ago
Smartcard and WebAuthn support are on the roadmap. Doing also a lot of modernization on the next weeks. https://github.com/tejado/Authorizer
nytesky|3 years ago
I miss having a solution that was locally synced across multi platform.
RockRobotRock|3 years ago
vinaypai|3 years ago
The password file on my server resides in a folder that's synced across all my computers using syncthing. My home server also runs an OpenVPN server so all my devices can talk to each other.
Everything is self hosted and runs on open source software. I'm pretty happy with my setup.
dethmetaljeff|3 years ago
charles_f|3 years ago
Keepass2android works very well. For the longest time I avoided the browser extension since it's a weak spot, and instead relied on auto-type. I finally caved in since most websites nowadays use a UI that asks for the user name first and then the password because reasons. The browser extension is very finicky and doesn't complete half of the time.
shellfishgene|3 years ago
sporkl|3 years ago
hasbot|3 years ago
pentab|3 years ago
snapplebobapple|3 years ago
Once passbolt adds offline storage of a copy of the vault to their extensions I may switch to that as I am a big fan of their system, it is just annoying for a home gamer to find their internet is down and then going to log in to their router to fix it finding the password manager doesn't work.
cmm|3 years ago
It's... fine, actually! And it all being open-source and using an open/documented/versioned database format decreases risks, also the browser extension is perfectly serviceable (certainly not worse than LP's abortion).
In short, I have absolutely no idea why I haven't made the jump long ago.
jcoletti|3 years ago
Edit: I see you didn't specifically mention Mac or Windows, but this one is Apple ecosystem only, currently.
manifoldgeo|3 years ago
It has clients for desktop on Linux, Mac, and Windows, and it's got Apple and Android mobile clients. There's also a browser plugin. I've had a great experience so far.
I also use KeepassX, though it's a lot less usable / portable.
References: 1: https://buttercup.pw
unknown|3 years ago
[deleted]
stranded22|3 years ago
Bitwarden is secured with my yubikey, with a 2FA code in another Authenticator app. Then, all my other OTP codes are within Bitwarden. For $10 a year, I am very happy with the service.
pinsl|3 years ago
frankyy|3 years ago
I have copy of keepass dbs on phone, private notebook and employer notebook. Once a month I doing backups, and I am updating these databases. Fresh passwords, for current month I'm holding unencrypted in email draft/todo list/google keep till full backup procedure.
arnonymous|3 years ago
Bitwarden clients really provide ease of use and I use it in combination with a Selfhosted bitwarden server called vaultwarden.
alphabettsy|3 years ago
CodexArcana|3 years ago
alsodumb|3 years ago
salil999|3 years ago
chewz|3 years ago
lotsofpulp|3 years ago
fortran77|3 years ago
lampshades|3 years ago
torstenvl|3 years ago
Personally, I think Enpass is the best of both worlds. The ecosystem isn't open source by default, but there are open source tools that get technical assistance from Enpass folks. And the experience is quite good, usually slightly less polished than BitWarden or 1Password, but sometimes slightly more polished (TOTP is a lot easier on Enpass than with 1Password). Lastly, it's local-first and offers a lifetime purchase for about $90.
rad_gruchalski|3 years ago
SAI_Peregrinus|3 years ago
vinaypai|3 years ago
sowbug|3 years ago
mdaniel|3 years ago
They have a bunch of "standard" questions in the drop-down list, like "first grade teacher" or whatever, but you can always just type your own since they're merely designed to be helpful. The answers they generate are built on top of their normal password generator, but I found the "battery horse staple" variety makes for the least amount of headache, although you could probably generate a PIN format if the target website accepted it since it'd be much easier to read to a customer service rep if it came to that (err, aside from the social hurdle of "what is your first grade teacher? ... 8675 ... no, I mean the teacher? ... yes, my answer is 8675" nonsense
newbieuser|3 years ago
rychco|3 years ago
alkonaut|3 years ago
For many logins I just use some re-used password with a prefix/suffix based on the service/site name, so I can usually get the password right without opening the manager or resetting the password.
bkraz|3 years ago
feyes|3 years ago
aborsy|3 years ago
wesapien|3 years ago
unknown|3 years ago
[deleted]
jmclnx|3 years ago
ScoobleDoodle|3 years ago
Thank you
klauserc|3 years ago
broose|3 years ago
rontheo|3 years ago
lormayna|3 years ago
dalex00|3 years ago
ScoobleDoodle|3 years ago
TylerE|3 years ago
kyoob|3 years ago
garbagetime|3 years ago
highhedgehog|3 years ago
highhedgehog|3 years ago
sirmike_|3 years ago
It just works.
eternityforest|3 years ago
SpiralLibrarium|3 years ago