Hacker News new | ask | show | jobs
by sri_cyberdude 3905 days ago
I use opensource keepass. Sync my password db via dropbox. Totally works for me.
3 comments

Using Dropbox for Security seems like a oxymoron? I fail to see that as anything I am willing to use.
"Using Dropbox for sync". It's just an option. Password db is already encrypted, so it does not matter which service is used for sync :)
Why? The database itself is encrypted. Dropbox is just a easy way to sync it between devices.
I store the private keyfile outside of Dropbox. To me it's a very acceptable tradeoff.
What makes you trust LastPass to spread your database to your devices more? And what makes Dropbox so bad?
Dropbox runs a binary on your machine; that's enough to suspect them. Stick with an open source password manager and an open sync service (S3 plus a script? Or a third party client like Arq).
Yeah... I'm not in the RMS camp
Nothing to do with software freedom, everything to do with security/auditability.
Yeah, with Dropbox software running on your machine, you not only have to trust them not to snoop on you, you have to trust their non-auditable code to be ~perfect~ against exploitation by others.
Are there plugins for safari/firefox/chrome and does it work on ios and have a nice little cli?

I'm basically preparing to bail on lastpass with this news but need to have all my bases covered.

With KeePass I haven't felt the need for a browser plugin: Ctrl+C, Ctrl+V is easy enough for my tastes. Plus, in Windows the "auto fill" works more often than not (reducing things to just Ctrl+V in KeePass).

There are multiple KeePass clients on iOS and just about all of them support things like Dropbox sync.

A curses-based CLI for KeePass, KeePassC was just recently on HN: http://raymontag.github.io/keepassc/

Browser plugins saving me from having to copy/paste are a huge win in my opinion. Prevents me from accidentally copy/pasting things and makes for really nice login behavior.

I'll look at some of this tonight thanks!

> Are there plugins for safari/firefox/chrome

I just save+sync passwords in Firefox and use a strong master password. I (usually) only need to paste the password from Keepass once unless I elect to not save it (such as with financial logins).

> does it work on ios?

Google seems to return lots of results for iOS Keepass apps. You'll want to vet them on your own. I use KeePassDroid on Android and like it well enough.

I tend to use all 3 of the browsers for slightly different things so having plugins would be ideal but I suppose I could slum it with copy/paste as long as I follow the password/login route to reduce the chance a password gets exposed.

I forgot about my nexus tablet but android is the other thing to have a look into.

Yes there is a plugin for Firefox. Don't know about the others.
Does it work on mobile?
Yes, i have it running in my BlackBerry! Im pretty sure, iOS and Android alternatives would be available.
Yep. I have both an Android and iOS client that I use.