Password Manager Recommendations

Associate
Joined
28 Feb 2012
Posts
1,832
Location
London, UK
Starting to look into password managers as I've been using basically 2 passwords for everything and have started running into trouble.

Been looking into 1password and Lastpass. Any recommendations on which to use?

Don't see myself moving from iOS in the near future but am using Windows on my desktop with Chrome and my MBP 2016 is coming next month where I'll be using Safari so cross platform is essential.
 
Soldato
Joined
5 Mar 2010
Posts
12,339
I've started using lastpass, but not for any sites for finance - i.e. bank accounts, credit cards, paypal etc.

Keepass is fine for a solely offline function, however most people i speak to who use it, also backup their database to the cloud. Which makes it just as vulnerable as lastpass then.
 
Associate
Joined
3 Jun 2007
Posts
2,276
Location
Essex
can you make Keepass auto fill in webpages as you visit them or do you have to keep going back to the programme and clicking auto type??

I would prefer to have an offline solution but the nice thing about Lastpass is that i dont have to touch it for it to fill in details.
 
Soldato
Joined
2 Dec 2005
Posts
5,515
Location
Herts
I switched to keepass (and keepassx on linux) last week, it's ace.

can you make Keepass auto fill in webpages as you visit them or do you have to keep going back to the programme and clicking auto type??

Yep. If any password entries are found in the window title it will auto type. E.g. I have an entry called "Overclockers UK Forums" so to log in just click the username box and press the auto type hotkey.

Works most of the time, but not on sites which have generic titles for the log in page. There's a workaround for those occasions but I haven't figured it out yet.
 
Last edited:
Associate
Joined
3 Jun 2007
Posts
2,276
Location
Essex
Thanks Joey

whats the best option on windows? install or portable USB key? if using usb key can you make it auto start when you plug it in? say if i wanted to use it on another PC
 
Associate
OP
Joined
28 Feb 2012
Posts
1,832
Location
London, UK
But it looks like Keepas isn't a cross platform manager so that is straight out the window already.

Looking for something to use on my iPhone, MBP and windows desktop.
 
Associate
Joined
8 Jul 2010
Posts
2,260
Location
Derbyshire
Keepass

I'm not a fan of the online type.

however most people i speak to who use it, also backup their database to the cloud. Which makes it just as vulnerable as lastpass then.

Bledd where do you keep the database? :D

I have been a Lastpass user for over 5 years now and never once had any issues with it or the service they provide. I store pretty much everything in my Lastpass vault except for card information since that is saved in most of the sites I use and failing that I use Paypal wherever possible (mostly because I hate Verified By Visa but that's another matter).

Lastpass comes highly recommended!

But it looks like Keepas isn't a cross platform manager so that is straight out the window already.

Looking for something to use on my iPhone, MBP and windows desktop.

Lastpass works across multiple platforms and devices so everything will always be in sync with each other.

Stoner81.
 
Last edited:
Soldato
Joined
2 Dec 2005
Posts
5,515
Location
Herts
whats the best option on windows? install or portable USB key? if using usb key can you make it auto start when you plug it in? say if i wanted to use it on another PC

Multiple clients or one portable one on a USB is much of a muchness. I use different clients of different devices and keep the database shared with syncthing but you can use dropbox or whatever.

Keeping a portable install on a USB stick is fine as long as it runs on all the platforms you want to run it on. If you want to use it on anything that doesn't have a USB socket (mobile) you'll need to set up some sort of sync anyway so that's why I just went down that road.

I personally have the database set up with a long password (40 character 'diceware' style) and a key file. The idea with a key file (I use a particular photo) is that you manually copy it to each 'authorized' device. This makes it practically impossible for someone to get into your database even if e.g. your sync (dropbox or whatever) gets compromised AND they sniff your password e.g. with a keylogger, they still can't get in because the key file was never exposed. (Unless they get a keylogger onto your system AND are able to read your hard drive in which case you're screwed.)

But it looks like Keepas isn't a cross platform manager so that is straight out the window already.

Looking for something to use on my iPhone, MBP and windows desktop.

keepass is Windows and anything that can run with the Mono library (Linux, OSX, BSD, ...). keepassX is specifically for Linux. For Android there's KeePassDroid. For iOS it looks like there's something called minikeepass. It's a pity there's not something like fdroid for iOS because I don't know if I'd trust anything (especially free) from the iOS store.
 
Last edited:
Soldato
Joined
18 Oct 2002
Posts
18,296
Location
Brighton
But it looks like Keepas isn't a cross platform manager so that is straight out the window already.

Looking for something to use on my iPhone, MBP and windows desktop.

Keepass apps are available for all platforms.

Windows = Keepass
Mac = Keepassx
iOS = Keepass touch (not used this myself)
Android = Keepassdroid
 
Soldato
Joined
17 Jul 2008
Posts
7,369
Keepass apps are available for all platforms.

Windows = Keepass
Mac = Keepassx
iOS = Keepass touch (not used this myself)
Android = Keepassdroid

bit of a roller coaster ride there...

Keepass.. --- looks great yaaaaayyyy ill use it

no crosss platform... --- nOOOOOOOOOOOOOOOOOOOOOOO

YES IT IS!!! --- YAAAAAAAAY
 
Soldato
Joined
9 Mar 2010
Posts
2,838
I specifically use KyPass 3 on iOS (think it costs about £3)

Works great using Dropbox to keep in sync and even supports Touch ID.
 
Soldato
Joined
2 Dec 2005
Posts
5,515
Location
Herts
Potentially dumb question but if I do move to a password manager completely, should I not be using the "remember me" function in chrome/websites?

Up to you, depends how you use the Chrome one. As of 2013 it was a bad idea according to

http://security.stackexchange.com/q...fe-as-using-lastpass-if-you-leave-it-signed-i (and many other links, just search "chrome safe remember passwords")

but hopefully they've got a grip on that by now. You might want to clear them all and just use a proper password manager to be safe.

Edit: the link above makes one excellent point I've not seen before actually. In one case the built-in browser password store is better than a manual one like keepass etc.: at preventing phishing, because it will only fill in the password for the real site and can't be fooled by a similar-looking phishing site that might trick a human. Interesting.
 
Last edited:

D3K

D3K

Soldato
Joined
13 Nov 2014
Posts
3,722
I use LastPass.

Analyses your passwords for strength and repitition, gives you a score to work towards. Acts like a bookmark tool too. Also stores non-web-based info if you choose to (wifi/router pws, bank details, payment auto-fills).

Worth the £12 a year fee for the premium version. Would be dire if it got hacked, but I don't see it happening.
 
Back
Top Bottom