Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.

  • anon_8675309@lemmy.world
    link
    fedilink
    arrow-up
    1
    ·
    6 hours ago

    Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.

  • Toasticus@piefed.social
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    9 hours ago

    I don’t particularly trust any password manager. If it can be breached, possibly, has been or a chance to be breached, then I don’t trust it. I have a document of passwords locked behind a VeraCrypt container hosted locally. I trust nothing in the cloud or some remote program.

    • Bane_Killgrind@lemmy.dbzer0.com
      link
      fedilink
      English
      arrow-up
      2
      ·
      4 hours ago

      That’s fair, but you’ve lost the ability to log access attempts for individual services, timeout sessions etc.

      There are completely selfhost options for this

    • BlueOysterCultist@lemmy.zip
      link
      fedilink
      arrow-up
      19
      arrow-down
      1
      ·
      1 day ago

      To further this, if you actually move over to any password manager please regenerate all of your duplicate passwords with something 20+ characters. It’s almost pointless to have a PW Manager if you’re using the same weak password everywhere.

      Make a new strong password for your master password too; I’d recommend a phrase of four moderately long words like “BattleshipMonitorPaintingPrinter” and perhaps a little postit note doodle drawing to remember it until it’s hammered home.

      Alternatively, writing down the master password somewhere secure, like in a safe, would also be good if you have to pass on important accounts to descendants.

      • That’s my reason for wanting to switch to a password manager. Everything gets some long random string that would be insane to type anyway. Or using passkeys, if supported, though I’ll have to research how that works.

        My biggest problem is backups. I like the method of Aegis authenticator. It just stores some number of past (encrypted) databases. Each change is a new file. This way rsync takes care of both backups and version control. If I accidentally rsync a corrupted file, it doesn’t matter much. And I can verify them with Rhash, just like all files that don’t change (like photos).

  • DarkSirrush@piefed.ca
    link
    fedilink
    English
    arrow-up
    13
    ·
    1 day ago

    Keepassxc/keepassdx, synced with syncthings/basicsync.

    Using a headscale/tailscale setup so things stay synced even when i am not home.

    • Leigh Weigh@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      Have this as my backup just in case bitwarden goes somewhere. I tried to run it as my daily but, it just doesn’t feel nice for some reason.

  • spaghettiwestern@sh.itjust.works
    link
    fedilink
    arrow-up
    7
    ·
    1 day ago

    A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.

    The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.

    One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.