Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Sweevo
Nov 8, 2007

i sometimes throw cables away

i mean straight into the bin without spending 10+ years in the box of might-come-in-handy-someday first

im a fucking monster

https://www.youtube.com/watch?v=n5GzlOpf3KA

Adbot
ADBOT LOVES YOU

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
i put poo poo i don't care much about in my browser pass manager

important poo poo goes into keep rear end

Cold on a Cob
Feb 6, 2006

i've seen so much, i'm going blind
and i'm brain dead virtually

College Slice
never store or autofill your email passwords, that poo poo is your weakest link right there

Bored Online
May 25, 2009

We don't need Rome telling us what to do.
1password. it seems fine enough that im not gonna fuq with migrating on a whim.

echinopsis
Apr 13, 2004

by Fluffdaddy
lastpass fukkewn rules

heeeeps

akadajet
Sep 14, 2003

echinopsis posted:

lastpass fukkewn rules

heeeeps

this

burning swine
May 26, 2004



keepass + nextcloud

don't use a password manager that has browser integration

mobby_6kl
Aug 9, 2009

by Fluffdaddy
A notepad

qsvui
Aug 23, 2003
some crazy thing
keep rear end

CRIP EATIN BREAD
Jun 24, 2002

Hey stop worrying bout my acting bitch, and worry about your WACK ass music. In the mean time... Eat a hot bowl of Dicks! Ice T



Soiled Meat
I like lastpass, but I don’t use it. I like it because it’s such a gently caress up and causes panic all the time.

RadiRoot
Feb 3, 2007
Bitwarden

Qtotonibudinibudet
Nov 7, 2011



Omich poluyobok, skazhi ty narkoman? ya prosto tozhe gde to tam zhivu, mogli by vmeste uyobyvat' narkotiki
Buttwarden after a while of using keep rear end and zxcpass

HAIL eSATA-n
Apr 7, 2007


Cold on a Cob posted:

i put poo poo i don't care much about in my browser pass manager

important poo poo goes into keep rear end

this is the way

echinopsis
Apr 13, 2004

by Fluffdaddy

burning swine posted:

don't use a password manager that has browser integration

I presume you say this because on some level, an exploit could open up in the browser and in last pass at the same time and someone could access my passwords?

205b
Mar 25, 2007

1password user checking in. I've been wary ever since they took a bunch of VC money last year, but the client quality seems to be holding up so far (and the clients are quite nice)

just to make a point in favor of browser integration, it's not purely a matter of convenience, it also means the client can warn you if you're about to get phished by goog1e.com. but the attack surface is admittedly larger

El Mero Mero
Oct 13, 2001

dashlane has still been my manager of choice, but I memorize my primarily email address and don't keep that in it.

I'm thinking of maybe transitioning out a few of the more sensitive ones to keepass + google drive or something.

fart simpson
Jul 2, 2005

DEATH TO AMERICA
:xickos:

just use a brainwallet, op

Billa
Jul 12, 2005

The Emperor protects.
Intergalactic planetary planetary intergalactic!

Raymond T. Racing
Jun 11, 2019

Progressive JPEG posted:

I used 1pass for a couple years until realizing that using it via a browser extension is a bad idea and risks e.g. a flaw in the browser or extension quickly leading to arbitrary websites seeing everything in it

but 1pass’ linux support is:
1) browser extension or
2) gently caress off

I went with option 2 and am now using bitkeeper

oh also I used to have my 2fa/totp codes directly in the password manager, but that also seemed like a bad idea, so now I keep them in a separate program. namely Authy but I don’t have any particular preference for it

1Password X seems to be completely fine. Unless you autofill something you shouldn't, there's really no way for a webpage to ever see anything in it.

https://support.1password.com/1password-x-security/

Vomik
Jul 29, 2003

This post is dedicated to the brave Mujahideen fighters of Afghanistan

Progressive JPEG posted:

I used 1pass for a couple years until realizing that using it via a browser extension is a bad idea and risks e.g. a flaw in the browser or extension quickly leading to arbitrary websites seeing everything in it

but 1pass’ linux support is:
1) browser extension or
2) gently caress off

I went with option 2 and am now using bitkeeper

oh also I used to have my 2fa/totp codes directly in the password manager, but that also seemed like a bad idea, so now I keep them in a separate program. namely Authy but I don’t have any particular preference for it

does bitkeeper mean bitwarden? or keeper?

if bitwarden then since it’s electron it’s also stored in a browser :nsa:

Last Chance
Dec 31, 2004

i do not trust browser autofill extensions. only safari + icloud keychain if that counts.

Agile Vector
May 21, 2007

scrum bored



Last Chance posted:

i do not trust browser autofill extensions. only safari + icloud keychain if that counts.

this for mobile but also it pulls from 1password as well. i appreciate when it hops into 1p to select and it also adds the otp to the clipboard for the next screen

i switched to the sub when i realized keeping devices across several platforms on maintained clients exceeded the annual rate even if i bought on sale and in bundles

Progressive JPEG
Feb 19, 2003

Buff Hardback posted:

1Password X seems to be completely fine. Unless you autofill something you shouldn't, there's really no way for a webpage to ever see anything in it.

https://support.1password.com/1password-x-security/

it’s effectively dependent on browser sandboxing working perfectly and that historically has not been the case to put it mildly

better to just keep the software that holds all the keys separate from the software that handles all the untrusted data

Vomik posted:

does bitkeeper mean bitwarden? or keeper?

if bitwarden then since it’s electron it’s also stored in a browser :nsa:

whoops yeah, edited

yeah it’s not great but I figure the trade off is acceptable since:
- it’s a separate process from the main browser
- I only open it when actually retrieving something, as opposed to a browser add on that would always be present

Dirty Beluga
Apr 17, 2007

Buy the ticket, take the ride
Fun Shoe
Notes in Outlook - it's encrypted!

Laslow
Jul 18, 2007
1password

that’s not the manager i use, but my password for everything. it’s so convenient.

Best Bi Geek Squid
Mar 25, 2016
op I just use the only pw manager given to me by god: my enormous brain

burning swine
May 26, 2004



passwords are stored in the balls

echinopsis
Apr 13, 2004

by Fluffdaddy
lastpass with browser integration




what’s actually hugely disturbing tho is how my ex managed to buy some poo poo from a print shop with my paypal. it was an accident and she paid me back, but what’s amazing is that she did it last year which at the time was perhaps understandable as it may have still been logged in etc, but since then i changed the password on my paypal and last pass so presumably there was no possible way for her to do it (choose my paypal over hers) unless it was just left logged in

it’s disturbing to me how little security paypal seems to have when you dive in. like google lets you see all open sessions etc and close them, same with facebook. but paypal? i find no way to do anything like that, just most options to make logging in quicker

Asleep Style
Oct 20, 2010

more like... assword manager

Billa
Jul 12, 2005

The Emperor protects.

Asleep Style posted:

more like... assword manager

OH HO HO HO

You said rear end!

mystes
May 31, 2006

Neslepaks posted:

i use pass. no browser integration because i dont trust browsers
Same

Trimson Grondag 3
Jul 1, 2007

Clapping Larry
so whats the difference in the security model etc that makes 1password preferable over lastpass? they both seem to come from similar origins and have similar functionality, is it just a matter of vulnerability track record?

Raymond T. Racing
Jun 11, 2019

Trimson Grondag 3 posted:

so whats the difference in the security model etc that makes 1password preferable over lastpass? they both seem to come from similar origins and have similar functionality, is it just a matter of vulnerability track record?

afaik 1Password has never been compromised (don't quote me on this i don't wanna be a secfuck) vs. lastpass's like 2. additionally, lastpass has the ability to reset your password using weird one time password things. i don't want that. if i get hosed i want it to be irrecoverable. 1Password has the secret key which tacks on another 128 bits of entropy, plus smaller company means generally more responsive w.r.t. support. 1password doesn't make weird false claims about 2fa like lastpass does, where 2fa doesn't allow for decryption of secrets, so there's no real point in offering 2fa on every vault unlock since it's just proving who you say you are, not that you have the master password to unlock the vault. this is a common complaint i see on the 1password forums "waaaaa i want to be prompted for 2fa every single time i unlock my vault"

echinopsis
Apr 13, 2004

by Fluffdaddy
1passwird creates a local database and can use cloud services like dropbox to share them around

lasspass is pure cloud based and it’s their server so super convenient

I THINK 1passwors now has their own servers?

both use top shelf encryption and encourage very strong behaviour

I appreciate that lass pass let’s me be slack tho so i can use touch id to open it and it’s fast and works so well

echinopsis
Apr 13, 2004

by Fluffdaddy
convenience over security imo

Arcteryx Anarchist
Sep 15, 2007

Fun Shoe
1Password moved off of third party repo hosting to offering their own storage both to not have to deal with supporting multiple providers (Dropbox, iCloud) and Dropbox making things a bit tougher for them iirc

echinopsis
Apr 13, 2004

by Fluffdaddy
shame there is no middle ground between free and 1password

like 20 a year? yep for sure

cowboy beepboop
Feb 24, 2001

lastpass had a thing once where attackers could gain access to your vault by you visiting a web page

echinopsis
Apr 13, 2004

by Fluffdaddy
that feeling when you never visited a page

Adbot
ADBOT LOVES YOU

Billa
Jul 12, 2005

The Emperor protects.
I have moved everything to Bitwarden, it is open source and audited and cool stuff.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply