cross-posted from: https://infosec.pub/post/42164102

Researchers demo weaknesses affecting some of the most popular options Academics say they found a series of flaws affecting three popular password managers, all of which claim to protect user credentials in the event that their servers are compromised.…

  • DigDoug@lemmy.world
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    6
    ·
    15 hours ago

    I know they’re convenient, but people should really stop using cloud-based password managers and start using local ones. I personally recommend KeepassXC.

    • fonix232@fedia.io
      link
      fedilink
      arrow-up
      9
      ·
      14 hours ago

      How do you recommend people sync between devices? What about devices that, for security reasons, do not allow flash drives or any external device to be plugged in?

      • thyristor@lemmy.pt
        link
        fedilink
        English
        arrow-up
        4
        ·
        14 hours ago

        I have my keepass file in a samba share on my raspberry pi running wireguard. But it’s easier just using nextcloud. Anyway, the file is encrypted.

        • fonix232@fedia.io
          link
          fedilink
          arrow-up
          4
          ·
          12 hours ago

          At that point, why bother with the setup of samba shares and nextcloud or syncthing or whatever else and not use VaultWarden with its built in sync over WireGuard/TailScale?

        • cecilkorik@piefed.ca
          link
          fedilink
          English
          arrow-up
          4
          ·
          11 hours ago

          Sadly this functionality is not included in KeepassXC, so I continue to use the original Keepass for this reason, but I agree, my setup is the same and I’m very happy with it.

      • DigDoug@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        14 hours ago

        You could use Github or similar. Your password file itself requires a password, so as long as the passwords are different you aren’t screwed if Github is compromised.

        Either that or you could keep it on your phone and type your password in manually - Keepass lets you generate passphrases which makes typing them a lot easier.

        Or you could store it on your own server and VPN in if you’re allowed to. It’s all pretty flexible.

        • fonix232@fedia.io
          link
          fedilink
          arrow-up
          4
          arrow-down
          2
          ·
          12 hours ago

          So, absolutely no difference in security compared to having a properly secured self-hosted VaultWarden instance. Gotcha.

          • DigDoug@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            3
            ·
            11 hours ago

            In the niche situation of not being allowed to connect USB drives to the computer you’re using? I guess.

            There’s nothing stopping you from keeping it on an offline device and typing them in manually.

    • Petter1@discuss.tchncs.de
      link
      fedilink
      English
      arrow-up
      3
      ·
      14 hours ago

      And keepass is perfectly cloud ready by placing the kdbx file into your cloud storage and sync using webDav or similar.