2023 was a record-breaking year for cybersecurity in a bad way. Ransomware payments hit a record high of $1.1 billion, which is likely to…

  • ebits21@lemmy.ca
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    4 months ago

    I use Bitwarden for passwords. Just works so well.

    KeepassXC and KeePassium for TOTP codes. I keep the database in the cloud but sync a key with Syncthing that’s needed to unlock the database on the devices themselves.

    • Lem453@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      4 months ago

      Locally hosted bitwarden (vault warden) that is only accessible on your local network is the way to go. When a new sync is needed away from home, wireguard VPN to connect back in makes everything nice and secure. Otherwise most of the time the vault is cached to the device locally so you don’t need to phone home to access passwords.

    • milicent_bystandr@lemm.ee
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      And I do keepassdx on Android, with a (phone-specific) database synced with syncthing


      P.S. syncthing is fantastic: I hope more people consider hosting discovery servers and especially relays

  • pathief@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    I’ve been using Proton Pass since it launched and I think it’s really really good.

    Positives:

    • Nice integration with both desktop and mobile
    • Integrated in the proton suite, which I was already using
    • Allows you to generate an email alias for each login automatically. Websites will never have your real email and you can easily generate a new alias if one has been compromised
    • Supports 2 factor authentication via TOTP, works really well

    Negatives:

    • No passkey support yet
    • Free version only supports like 5 email alias
  • guillem@aussie.zone
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    If you are into the command line, pass is also neat. You can even have your keys in a git repo and access it with a FOSS Android app (requires some dedication to set it up). It’s very useful to feed passwords to scripts without hardcoding them in the source.

  • Kekzkrieger@feddit.de
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 months ago

    I use keepass with my database on onedrive.

    Then i connect every device to said onedrive account, copy the private key manually on each device that i need to use.

    I secure my databse with said private key + a passphrase.

    Might not be the best setup, but i feel like with passphrase+key i am secure enough to have the db file in the cloud.

  • madcaesar@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    KeePass for me. I keep my encrypted vault in my 2 factor encrypted gdrive. Get the best of both worlds. No traditional cloud that’s a target for hackers and I have passes I can share across devices.

  • jabjoe@feddit.uk
    link
    fedilink
    English
    arrow-up
    0
    ·
    4 months ago

    No love for Nextcloud Passwords or Passman? Both have plugins for Nextcloud and have Android Apps.

    • lolgcat@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      No love for Nextcloud

      Pretty much in general for me now. I gave it an honest go for six years but there were at least four instances where a server upgrade required nontrivial intervention to bring it back.

      Syncthing + Keepass[DX] has been solid for me.

    • NostraDavid@programming.dev
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      For Keepass users: KeepassXC can read your keepass file just fine, but KeepassXC can also run on Linux, whereas Keepass runs only on Windows.

    • Xavier@lemmy.ca
      link
      fedilink
      arrow-up
      0
      ·
      4 months ago

      Ah, I suppose it’s TOTP/HOTP or HMAC challenge.

      I am waiting for FIDO2 to work between keepassxc and yubikey. 🥳

    • BrikoX@lemmy.zipOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      4 months ago

      I know they recently published the code for their clients, so that’s a plus. But I can’t find any independent audits for their architecture or clients.

      While all mentioned options does have independent audits done.

  • navi@lemmy.tespia.org
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    I really enjoy 1Password for easy vault sharing between family members. I was able to get my (not so technically literate) siblings and dad onto my family plan. Baby steps!

  • coffinwood@feddit.de
    link
    fedilink
    arrow-up
    0
    ·
    4 months ago

    No mention of Enpass? Stores more than just passwords, can be synced locally over wifi or in the cloud without using Enpass servers.