Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.

    • BlueOysterCultist@lemmy.zip
      link
      fedilink
      arrow-up
      26
      arrow-down
      1
      ·
      10 days ago

      To further this, if you actually move over to any password manager please regenerate all of your duplicate passwords with something 20+ characters. It’s almost pointless to have a PW Manager if you’re using the same weak password everywhere.

      Make a new strong password for your master password too; I’d recommend a phrase of four moderately long words like “BattleshipMonitorPaintingPrinter” and perhaps a little postit note doodle drawing to remember it until it’s hammered home.

      Alternatively, writing down the master password somewhere secure, like in a safe, would also be good if you have to pass on important accounts to descendants.

      • That’s my reason for wanting to switch to a password manager. Everything gets some long random string that would be insane to type anyway. Or using passkeys, if supported, though I’ll have to research how that works.

        My biggest problem is backups. I like the method of Aegis authenticator. It just stores some number of past (encrypted) databases. Each change is a new file. This way rsync takes care of both backups and version control. If I accidentally rsync a corrupted file, it doesn’t matter much. And I can verify them with Rhash, just like all files that don’t change (like photos).

      • Mercer@lemmy.zip
        link
        fedilink
        arrow-up
        1
        ·
        8 days ago

        Or a USB with a Gpg encrypted text file locked with a slightly easier password.

  • brewery@feddit.uk
    link
    fedilink
    arrow-up
    19
    ·
    10 days ago

    Vaultwarden - self hosted bitwarden server that any bitwarden clients can connect to.

  • DarkSirrush@piefed.ca
    link
    fedilink
    English
    arrow-up
    18
    ·
    10 days ago

    Keepassxc/keepassdx, synced with syncthings/basicsync.

    Using a headscale/tailscale setup so things stay synced even when i am not home.

    • Leigh Weigh@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      10 days ago

      Have this as my backup just in case bitwarden goes somewhere. I tried to run it as my daily but, it just doesn’t feel nice for some reason.

      • Jolteon@lemmy.zip
        link
        fedilink
        arrow-up
        2
        ·
        9 days ago

        You also need a secondary service on your server if you want to keep them in sync.

        • Schlemmy@lemmy.ml
          link
          fedilink
          arrow-up
          1
          ·
          4 days ago

          Not really. Bitwarden is hosted by Bitwarden, why would you want to run the sync yourself? Vaultwarden is self hosted anyway.

  • spaghettiwestern@sh.itjust.works
    link
    fedilink
    arrow-up
    10
    ·
    10 days ago

    A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.

    The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.

    One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.

      • spaghettiwestern@sh.itjust.works
        link
        fedilink
        arrow-up
        5
        ·
        edit-2
        10 days ago

        Syncthing-fork from Fdroid.

        There were some repository ownership questions a few months back that were ironed out. In addition, Fdroid vets apps far better than Google ever has so I’m comfortable with the app’s security.

        • WhyJiffie@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          7 days ago

          In addition, Fdroid vets apps far better than Google ever has so I’m comfortable with the app’s security.

          I agree but they aren’t checking every version for malicious changes. they would likely only get to know if a user checks it and notices it, and the developer could just make the change for a single release version.

          of course that applies to any app but this handover/takeover was very sketchy.

  • trailee@sh.itjust.works
    link
    fedilink
    arrow-up
    9
    ·
    10 days ago

    1Password family account with spouse, kids, and my parents. Vault management, ease of sharing, and remote management for my parents is nice, along with multiplatform for everything important, and the price feels quite reasonable at $1/user/month. No major security incidents ever, and I was pleased by their core service design whitepaper that I read many years ago. But as they’ve become increasingly corporate over the past several years I’ve felt like they care less and less about individual users, and the CEO’s recent pledge to Omarchy really pissed me off. So it’s been a great service for me but I don’t recommend it for new users unless they like nazis. I pay for a year at a time so I haven’t scrambled to migrate my family to a new solution quickly, but it sounds like Vaultwarden is most likely the way to go next.

  • adamantkestrel@lemmy.blahaj.zone
    link
    fedilink
    arrow-up
    8
    ·
    10 days ago

    Seconding Bitwarden, have been with it since my previous one (Lastpass? I forget, it was red) moved most of the good functionality behind a paywall many years ago. 11/10 I usually pay for the subscription, I like their product and want them to have a little walkin’ around money. But currently on the free tier which is perfectly fine (2 devices when I used pro for 3, but I hardly use my laptop.

    • vandsjov@feddit.dk
      link
      fedilink
      arrow-up
      1
      ·
      8 days ago

      My journey as well. Paid for LastPass (bought 10 years for $20) and changed when they went too much shit.

  • zxqwas@lemmy.world
    link
    fedilink
    arrow-up
    6
    ·
    10 days ago

    Remember the password to my email. Create account on site. Log in and remain logged in. When eventually logged out click forgot password. Log into email and click reset link.

  • Asafum@lemmy.world
    link
    fedilink
    arrow-up
    5
    ·
    10 days ago

    I’m an old man yelling at clouds but I don’t trust any of the password storing technologies. I have a system of making/writing passwords and a save a short form of them on my pc. Without knowing a specific segment you’d never be able to guess what they were so the segment is the only thing I need to remember. Having to access accounts when not at home is a massive pain in the ass though lol