• Sunspear@piefed.social
        link
        fedilink
        English
        arrow-up
        15
        ·
        2 months ago

        Thing is, a large percentage of internet-connected users might have two or more devices. The simplicity offered by a cloud (be it hosted or selfhosted) password manager is a huge benefit.

        And unless you’re already running a syncthing-like service for something else, setting it up just for a password manager when other services provide it out of the box, is not worth the hassle usually.

        • quaff@lemmy.ca
          link
          fedilink
          English
          arrow-up
          5
          arrow-down
          1
          ·
          2 months ago

          I use KeePass on like… I dunno 5-6 devices? They all sync together via Syncthing. No server needed. My keepass db is just one of the things synced this way.

          Works pretty well.

          These are the apps I use:

          Desktop (Linux & macOS): KeePassXC Andrdoid: KeePassDX iOS: KeePassium

          The whole ecosystem can be used for free. But like… tip your open source devs yo.

          Syncing happens pretty quickly with Syncthing. So conflicts in the keepass DBs are very rare (maybe once a year if I’m impatient after a change on a different device). But they do happen, I’ll give you that. Some restraint (wait for sync) and checking (this is where sorting by modified helps!!!) what’s the latest change helps.

        • unexposedhazard@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          edit-2
          2 months ago

          Everyone has some kind of cloud service tho no? The database is encrypted so you can even sync it over googles cloud storage if you dont have nextcloud or syncthing.

        • lagoon8622@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 months ago

          I use one for work and the other for personal. They are both great, with slightly different convenience/security tradeoffs imo. Big fan of both, don’t know why it has to be one or the other for an OSS credentials manager

          Edit: part of what you’re paying for with BW is first-class native apps

          • AbidanYre@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Big fan of both, don’t know why it has to be one or the other for an OSS credentials manager

            On an individual level, you only need one or the other. But which one is best for you may be different than which one is best for me.

          • Asetru@feddit.org
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            Big fan of both, don’t know why it has to be one or the other for an OSS credentials manager

            20 bucks are kind of a reason tho?

      • Fmstrat@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        So is BitWarden if you self-hosted. The price increase is for a hosted service which Keepass does not provide.

        • john_t@piefed.ee
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 months ago

          If you can’t selfhost, then you can have your keepass file in your personal cloud. Many basic cloud services are free and the password file itself is encrypted so the cloud provider can’t access your passwords.

        • pulsewidth@lemmy.world
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          2 months ago

          (Edit - I misread as Bitwarden and went off on the wrong tangent. Vaultwarden is not centralized, and it’s FOSS - my bad.)

          The person you’re replying to already gave you one: it’s free.

          Second: its not a prime target for attack like centralized, hosted webservices are. See: LastPass being cracked and people’s login data stolen… Twice.

          Yes, it is cryptographically superior to LastPass, and attempts to design around their flaws - but the threat still exists because its a very tasty target on the open internet for cybercrime.

          My little Keepass DB synched over personal VPN by Syncthing? Much harder to find a vector for attack. But it does require more moving parts and maintenance.

          Each have their pros and cons.

          • the_crotch@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 months ago

            Web interface, no client software required. I can fire up a brand new machine and access my DB without installing anything.

          • lastweakness@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            2 months ago

            I realise now that I can think of one too. Which is that you don’t need to host it anywhere if you use something like Syncthing.

              • besmtt@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                ·
                2 months ago

                Bitwarden works offline. Obviously can’t save to the server, but reading from what’s already on your local machine works just fine.