KeePass with Keepass2Android on my phone with the vault synced via Dropbox. Use biometrics to access both apps. I also use Secure Password Generator on Firefox to get passwords + several options in KeePass (readable passphrase, diceware, etc.)
Absolutely necessary to have and use. KeePass offline works well for me. Clouds are for rain!
I used KeePass for years. Now I switched to BitWarden since it's open source and audited.
Bitwarden
I switched from LastPass to Bitwarden. I think they're great, being able to use a strong bespoke password for every service along with one nuclear missile arming grade password plus 2FA for the manager itself.
I don't know if this totally credible or not, but I found news that KeepassXC receives positive audit from independent security consultant. Very rare to happen in pass manager apps..
I got this news from Linux Magazine first as I remembered, so I think this is credible and best alternative solution for us to use KeepassXC than other (never heard other apps has been audits by independent security firms / consultants like this).
LastPass -> Enpass -> BitWarden
Tried KeePass (on Windows), 1Password and pass before settling with BitWarden.
KeepassXC on desktop with browser plugin, KeePassDX on android I find it less confusing to use than Keepass2Android.
It is only a bit difficult to setup sync, but you can use syncthing, or drive and it works nicely.
Currently I use Bitwarden on both my phone and my pc, but I'm looking into self hosting it with vaultwarden. This gives you access to premium features (such as TOTP support, for which I currently use Aegis Authenticator). It also gives you full control over your data.
I use Bitwarden. Used to use Last pass, but that got crappy a while back.
I like the simplicity of password-store. It's just a simple wrapper around a text editor, gpg, and git that allows you to make an encrypted, version controlled password repository that you can sync between devices using GitHub/Gitlab/etc. It also doesn't lock you in to any app since the passwords are just stored in gpg-encrypted files.
Password managers are a requirement for me these days. With how many breaches occur daily that we might not even know about you probably want a password that hasn't been reversed or used before. For me I don't know what I'd do without Bitwarden. I previously used LastPass until they added some restrictions and I figured out that Bitwarden was opensource. I don't currently run my own instance of it but easily could, keeping my passwords off other peoples computers.
I honestly don't know how anyone manages without one these days. How would you even keep track of it all? Even if you go the 'same password for everything' route of horrible security, different websites have different requirements for both username and password. Wouldn't be able keep it all straight at all.
I personally use 1password, which is better than Lastpass for sure. Probably not as good as Bitwarden, but I'm too lazy to switch a second time.
I don't use them. I see this as a putting all eggs in one basket strategy, if my master password was lost, hacked, hosting company shutdown, or for whatever reason refuse to do business with me, my entire life would be screwed.
Instead I use long passwords made of words, and for each site it will be a few letters off. They're easy for humans to remember because how similar they are, but due how hash works they are equivalent to unique passwords to hackers.
KeePass is the perfect tool for me ! The cybersecurity practice at work also use it,
So many answers for Bitwarden but I too will agree. It's my go-to ever since I've found out about it, I don't know any of my passwords apart from my Bitwarden vault master password tbh.
As with most things security it's about assessing your risk.
If you're a granny with a hand full of passwords then a notebook is probably fine.
I think for most people, who aren't CEOs, high value employees, or some kind of holder of the keys to a kingdom beyond their personal bank account, a solid full e2ee password manager that's cloud synced is a nice middle ground of security vs convenience. It beats a post it under keyboard or a notebook left on the night stand.
For those CEOs, or high value employees then something offline is in order. Or as I've seen others note perhaps a combo of full offline and cloud synced for less important logins.
I recommend Bitwarden as others have here. It seems to be the one that's come through unscathed thus far and the company behind it seems to be making the right moves to stay ahead of risks. https://bitwarden.com/help/is-bitwarden-audited/
They're much more than passwords managers nowadays, they're secrets managers. You can't store sensitive info like passport info, insurance cards, etc in a way that you know is safe if you make sure to use a unique and strong password as well as 2FA.
What are my thoughts on a password manager?
I think it’s both a good thing, and a crutch. I feel the fact that most services are rendered unusable without an account is sad, and with the 100’s of accounts one is expected to have a password manager is sadly needed if you can’t memorize a password or can make passwords with a consistent pass phrase.
Do I use one?
Nope, I have a password system which is good enough for most accounts that’s always more than 7 character long and unique for each account without being lost to me. The only time it has failed as when my work decided to have us change our passwords every quarter, and I ran out of password ideas.
If you are not using a password manager you are doing it wrong.
Using different passwords for different services protects you against data leaks opening attack vectors for all your services as well as malicious actors using your passwords like that as well as phishing impact.
A password manager is a must for reasonable security.
I use keepass. Local DB file with Master password. No hosted service or Browser extension is another layer of protection, of risk reduction. I manually copy/sync the DB file via cloud storage as a backup and for mobile use.
I use Browser password storage selectively. The most critical stuff definitely only belongs into my memory and password database.
As others have said, bitwarden. I've also heard good things about roboform.
I really love that bitwarden is not only open source but has been professionally code reviewed, and can be self hosted if you've got the knowledge to do so.
Of course, if you're self hosting it make sure you have a solid backup strategy for your vault.
I use Firefox's built in password manager because its crossplatform and I can use it on all my devices.
Lots of love for Bitwarden in this thread; I’d also like to pitch in with 1Password. It’s got a great UX and I even got my mom on board.
Used to use Lastpass since ~2013; really glad I switched last year. Lastpass has turned to absolute shit.
Yes, and Bitwarden. Strong master password, with 2FA, and randomly generated passwords for the rest. For deeply personal apps such as banking I do have another localized system though. I moved on from LastPass and never looked back.
switched from LastPass to Bitwarden and I couldn't look left or right
I love using 1Password!
Android
DROID DOES
Welcome to the droidymcdroidface-iest, Lemmyest (Lemmiest), test, bestest, phoniest, pluckiest, snarkiest, and spiciest Android community on Lemmy (Do not respond)! Here you can participate in amazing discussions and events relating to all things Android.
The rules for posting and commenting, besides the rules defined here for lemmy.world, are as follows:
Rules
1. All posts must be relevant to Android devices/operating system.
2. Posts cannot be illegal or NSFW material.
3. No spam, self promotion, or upvote farming. Sources engaging in these behavior will be added to the Blacklist.
4. Non-whitelisted bots will be banned.
5. Engage respectfully: Harassment, flamebaiting, bad faith engagement, or agenda posting will result in your posts being removed. Excessive violations will result in temporary or permanent ban, depending on severity.
6. Memes are not allowed to be posts, but are allowed in the comments.
7. Posts from clickbait sources are heavily discouraged. Please de-clickbait titles if it needs to be submitted.
8. Submission statements of any length composed of your own thoughts inside the post text field are mandatory for any microblog posts, and are optional but recommended for article/image/video posts.
Community Resources:
We are Android girls*,
In our Lemmy.world.
The back is plastic,
It's fantastic.
*Well, not just girls: people of all gender identities are welcomed here.
Our Partner Communities: