Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.
Nice try
A bit of a tangent but these are the right people to ask… What do you think when a site or app says that your password is too long?
keepassxc
With gnupg, git, and a hardware security token. Also known as “pass”.
Bitwarden
Mostly i get by by not telling others how or where I keep my passwords
Do you add 1 and then ! or ! And then 1 to secure your passwords?
pass: the standard unix password manager for tech-savvy people. It’s dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.
My dumbass reading through these comments: “keep ass… ehehehehe”
Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.
Piece of paper.
Proton Pass for me since I use their VPN.
Vaultwarden for selfhosting.
I don’t particularly trust any password manager. If it can be breached, possibly, has been or a chance to be breached, then I don’t trust it. I have a document of passwords locked behind a VeraCrypt container hosted locally. I trust nothing in the cloud or some remote program.
That’s fair, but you’ve lost the ability to log access attempts for individual services, timeout sessions etc.
There are completely selfhost options for this
Bitwarden
To further this, if you actually move over to any password manager please regenerate all of your duplicate passwords with something 20+ characters. It’s almost pointless to have a PW Manager if you’re using the same weak password everywhere.
Make a new strong password for your master password too; I’d recommend a phrase of four moderately long words like “BattleshipMonitorPaintingPrinter” and perhaps a little postit note doodle drawing to remember it until it’s hammered home.
Alternatively, writing down the master password somewhere secure, like in a safe, would also be good if you have to pass on important accounts to descendants.
Or a USB with a Gpg encrypted text file locked with a slightly easier password.
That’s my reason for wanting to switch to a password manager. Everything gets some long random string that would be insane to type anyway. Or using passkeys, if supported, though I’ll have to research how that works.
My biggest problem is backups. I like the method of Aegis authenticator. It just stores some number of past (encrypted) databases. Each change is a new file. This way rsync takes care of both backups and version control. If I accidentally rsync a corrupted file, it doesn’t matter much. And I can verify them with Rhash, just like all files that don’t change (like photos).
I’m fairly sure you can self host Bitwarden, so it might be possible to have backups in a similar way
I think Vaultwarden is the self-hosted version
Keepassxc/keepassdx, synced with syncthings/basicsync.
Using a headscale/tailscale setup so things stay synced even when i am not home.
keepassxc






