Need advice on a better way to manage all the passwords one has.
I'm against a password manager per se as they seem like honeypots. What methods do you all find useful?
Login to reply
Replies (8)
TLDR: host your own password manager.
Password managers are great, but you run the risk of the company getting hacked as has happened to LastPass and others. You could use something like Bitwarden and set up 2FA and use a Yubikey. This will protect you against your passwords getting hacked, but if the company’s servers go down then you’re screwed. If you enable cache then you might be ok, but you’re still relying on a third party to store your data and if you opt for the plan with yubikey you have to pay a ~$10 annual subscription.
Solution: host your own instance of Bitwarden (Vaultwarden). Not only do you get to keep the convenience of using a password manager, but you can rest easy knowing you’re hosting your data in your own server. This does require you spin up a server, which can be done fairly easily nowadays. I’m a big fan of StartOS from @Start9 they sell plug and play servers, but you can use an old laptop if you don’t want to buy new hardware.
I would suggest you keep the passwords to the Server and Vaultwarden on a piece of paper inside a tamper evident bag. This way you keep the gatekeeper passwords offline, and if someone were to come across those passwords at your house they would still need to know what to do with it (go to your server LAN address). There are some tradeoffs and nuances, but I think this is a pretty solid option
I use keepass clients on all my devices. If you really study it and understand its power. You'll realize there's nothing better.
But I'm an extreme ultra geek. On the extreme bleeding edge. From my perspective. No technology can be too powerful for me to max it out. It's a sickness..😩😆
#MorePower!!!..⚡⚡⚡⚡⚡
I self host Vaultwarden for most websites, and then I have KeepassXC locally and also stored on a flash drive with a physical password on the drive itself.
Also I use Linux the majority of the time now.
Create a simple cypher which you apply to the name of the service or site. Use two memorable scripture addresses in front and back.
Thnx. I'm wanting to get into self hosting. Going to buy a Start9 and start from there!
Thanks. I've committed to hosting my own server. Going to get a Start9. I'm slowly going down this path and can conceptualize what you're saying... thanks.
That’s great 👍🏼 Definitely join the Start9 telegram group, their support is second to none
Old school, keep a password protected calc sheet. Print it out and make hand updates.