I keep seeing people highly recommend them, but I’ve always thought it wasn’t very secure.

  • smiletolerantly@awful.systems
    link
    fedilink
    arrow-up
    24
    ·
    17 hours ago

    Can’t believe noone mentioned this yet:

    Any good password manager encrypts and decrypts your password file client side. The server should not even have the ability to read your passwords.

    Even in the case of a leak of all of the server’s data, as long as your password for the manager was good, you’ve got nothing to worry about.

    I’d say pick a PW manager where both client and server are open source. Pick a strong passphrase. Enjoy.

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      9 hours ago

      I like using Keepassxc with a file that is on a storage provider. Keeping the task of storing my file and decrypting it completely and utterly distinct. Don’t have to audit that the total solution is keeping things separate like they claim when there’s no risky interop in the first place.