Hacker News new | ask | show | jobs
by gnud 2468 days ago
I store the keepass file in a cloud sync service. The file is encrypted.

The keepass application can perform "auto-type" which works for all sensible applications and websites that have username/password input fields and a log-in button.

Recently, more and more websites split the log-in into two screens, first email and then password. This completely breaks auto-type and is horrible in every way. Please don't do it.

3 comments

You're able to adjust auto-type for accounts that break the login into two pages. I learned this fairly recently as I had the same frustration as you. Ref: https://keepass.info/help/base/autotype.html
This works if your environment allows a) installing applications and b) cloud sync using consumer clouds (dropbox, gdrive, etc

You are right that this is a good approach for many it will certainly break for many as well.

> This works if your environment allows a) installing applications and b) cloud sync using consumer clouds (dropbox, gdrive, etc

Re a) https://keeweb.info/ toss this onto any ol' free tier web host you want. No app install necessary. It's not as nice as the apps, but it works.

Re b) Is there an environment that both has a web browser that you want password management with and doesn't let you access any consumer cloud sync service?

There sure is. Most big companies work that way I would imagine. I can install browser extensions, no problem but local apps are restricted. Also Dropbox and others are blocked at the corporate firewall level.
Surely in such a place, blocking all that access means they care about security and therefore provide you with a password management solution that you also have no choice over.

I mean, installing browser extensions to deliberately get around their security measures seems a little bit counterproductive. They aren't more secure than local apps. Do you take this company's security measures seriously or is it just some hurdle to get around for you?

> I can install browser extensions, no problem but local apps are restricted.

Yes, which is why I posted the alternative to installing an app. You can use Keepass + drive/dropbox sync without installing anything using keeweb.

You do not need to install apps to access drive, dropbox, etc...

PasswordWallet can auto-type across split login screens since it can be configured to pause between username/password.
You can configure this in KeePass as well, I've done this for a few sites I actually use a lot. But I can't be bothered for every single service that decides to re-invent login.