Proton Pass Alternatives
from guymontag@lemmy.ml to privacy@lemmy.ml on 01 Jan 07:53
https://lemmy.ml/post/41082547

I personally love proton pass’s frontend app, but i don’t wanna host my data on proton’s servers(personal reasons). Is there any other password managers that support iOS, android, and browser extension, that is as good. (I tried bitwarden wasn’t good cuz on mobile I had to reenter master pass over and over. I tried keypassxc, but the frontend sucks and dealing with syncing between devices is a pain in the ass.) I appreciate everyone’s help!

#privacy

threaded - newest

human@slrpnk.net on 01 Jan 08:05 next collapse

If your main concern is usability, 1password works pretty well. The downsides are it’s paid, closed source, and I think they removed the option to use a local vault, so it might have to be cloud.

guymontag@lemmy.ml on 01 Jan 08:43 collapse

I’ll check it out. If it’s cheap I might be willing to try it. Its not like proton is FOSS.

theherk@lemmy.world on 01 Jan 08:53 collapse

WDYM? Isn’t it?

guymontag@lemmy.ml on 01 Jan 09:11 collapse

Only the frontend. Not the backend, so you can’t self host without modifying both browser extension and mobile app, along with rewriting a server from scratch.

theherk@lemmy.world on 01 Jan 09:49 collapse

Okay fair enough, but that is at least slightly different than saying Proton isn’t FOSS, but I understand.

They have a pretty good FOSS standing and audits for software they distribute. While that doesn’t make it easy to host privately, it does make it trivial to see how data is shipped to their servers.

Cat_Daddy@hexbear.net on 01 Jan 08:15 next collapse

I’m in the same boat. Wanted to do Bitwarden but their sign up process is garbage. It never sends me the confirmation email. I’d love to set up a keypassxc server, but didn’t know about the frontend issues.

guymontag@lemmy.ml on 01 Jan 08:43 collapse

The frontend for keypassxc isn’t necessarily horrible, it’s just proton pass feels like magic, while key pass feels just barely working. idk I remember it being kinda awkward

mortalic@lemmy.world on 01 Jan 08:48 next collapse

Bitwarden, is still the way to go. I say this as a proton customer. I’ve learned to work around it’s small annoyances

guymontag@lemmy.ml on 01 Jan 09:10 collapse

On mobile, I had to reenter the master password ever time I filled in a password. With a really safe, long, password, it was torture.

JASN_DE@feddit.org on 01 Jan 09:17 next collapse

How would this be any different with another app?

guymontag@lemmy.ml on 01 Jan 09:18 collapse

On proton pass, I just need a pin(which isn’t enabled by default, it should be tho)

JASN_DE@feddit.org on 01 Jan 09:23 next collapse

Same on Bitwarden.

Interstellar_1@lemmy.blahaj.zone on 01 Jan 09:41 collapse

It’s just a setting you enable in bitwarden settings

EntropyPure@lemmy.world on 01 Jan 09:30 collapse

That is something you can configure in the settings for the mobile app. To ask for the master password every time is default behavior, but it can also be set to a PIN or biometric instead.

favoredponcho@lemmy.zip on 01 Jan 09:29 next collapse

I don’t understand your issue with needing to enter your master password repeatedly with Bitwarden. You can use biometrics or a pass code to sign in on mobile. It’s pretty easy to enable in the settings. You enter master password once, turn on passcode or biometrics and then that’s it.

url@feddit.fr on 01 Jan 10:45 collapse

For me, I’m extra paranoid.. Someone can forcefully unlock with biometric

hitmyspot@aussie.zone on 01 Jan 11:00 next collapse

You can set a pin as an alternative. Pin would be easier to brute force but no different to a password when forcefully unlocked by coersion.

kepix@lemmy.world on 01 Jan 15:15 next collapse

i think you can alsk yubikey

jokeyrhyme@lemmy.ml on 03 Jan 00:01 collapse

there’s the lockdown or similar feature at the phone level in Android and iOS

if you’re in a situation where you don’t want someone to access Bitwarden, then you probably also want to stop them from using your browser with all the cookies and logins it currently has

so temporarily block all biometric access on your phone in such cases, and merrily enjoy biometric access when you’re physically safe again

on Android, it’s Power + Volume-Up, then Lockdown

favoredponcho@lemmy.zip on 04 Jan 15:20 collapse

Same on iOS too. Same buttons.

Teienkawi@beehaw.org on 01 Jan 09:42 next collapse

Ive found pencil/pen and paper and memorization work (ive been got by a bad download they cant scrape the paper) its old school but its pretty good not all eggs in one basket kind of thing

url@feddit.fr on 01 Jan 10:43 next collapse

Good luck, but I still recommend encrypted offline strong passwords

Nighed@feddit.uk on 07 Jan 15:21 collapse

All good until your house burns down/floods or something.

Teienkawi@beehaw.org on 08 Jan 06:20 collapse

Dizzyam. nice call. i didnt think of that. Those could be a problem but the pass words a quick grab away so if im alive they ok(flood would be worst clothes get wet. Fire im out the window) ill put them in zip locks.

Nighed@feddit.uk on 08 Jan 08:59 collapse

If they are serious passwords, look at putting them in a fireproof bag.

Otherwise, what happens if something happens when you are out?

Teienkawi@beehaw.org on 08 Jan 09:07 collapse

Nice Thank you this is good thinking

Nighed@feddit.uk on 08 Jan 09:13 collapse

Doesn’t have to be your main copy (those bags are annoying to use). But put a copy in there at least (and keep it up to date with the important ones)

DON’T put the paper in a plastic organiser etc, plastic melts/burns at lower temperature so can ruin them even if the bag would have otherwise been able to protect them.

TheJnx@piefed.social on 01 Jan 09:54 next collapse

Keepass is good, with Synching you can synchronize everything better

url@feddit.fr on 01 Jan 10:41 next collapse

Whats wrong with keepass. I’v been syncing with syncthing for years now. I still don’t know why frontend matters is not like you will use it every 10 minutes

guymontag@lemmy.ml on 02 Jan 08:35 next collapse

Idk it was so bad it was annoying me, when I tried. Maybe I should force myself to use for a month, and see the results.

JSens1998@lemmy.ml on 03 Jan 05:22 collapse

I get to keep the ass? I should switch to that.

RodgeGrabTheCat@sh.itjust.works on 01 Jan 10:51 next collapse

I don’t know if Syncthing is available on iOS but this works great to sync Keepass’s database between Linux and Android.

guymontag@lemmy.ml on 02 Jan 08:34 collapse

Synctrain is an ios syncthing client. It works great!

RodgeGrabTheCat@sh.itjust.works on 02 Jan 14:27 collapse

Good to know, thanks.

DieserTypMatthias@lemmy.ml on 01 Jan 11:26 next collapse

I tried bitwarden wasn’t good cuz on mobile I had to reenter master pass over and over

Setup fingerprint unlock and enable it in Bitwarden.

doodoo_wizard@lemmy.ml on 01 Jan 18:01 next collapse

Use bitwarden, go to Settings -> account security -> unlock with pin and turn it on. If it’s already on, toggle it off then on. You will be prompted to set your pin. Dont forget your master password.

guymontag@lemmy.ml on 02 Jan 08:30 collapse

I wont :) I should give bitwarden another try.

doodoo_wizard@lemmy.ml on 02 Jan 17:22 collapse

After you eventually settle on bitwarden, rotate all passwords and uninstall or clear out the contents of other password managers. From your replies in this thread it seems like you’ve used many different managers.

guymontag@lemmy.ml on 02 Jan 19:43 collapse

I’ve switched 5 times in one day

E_coli42@lemmy.world on 02 Jan 07:10 next collapse

What’s wrong with having your data on proton’s servers? I thought the app and browser extensions are verifiably only sending encrypted packets? Or do they only encrypt your password and send metadata as is?

guymontag@lemmy.ml on 02 Jan 07:45 collapse

I wanna use a different proton service, but using 2 services from proton is a bad idea.

E_coli42@lemmy.world on 02 Jan 20:25 collapse

Why

jokeyrhyme@lemmy.ml on 02 Jan 23:58 collapse

Use one service for one thing, so that when it gets disabled, only that one thing is affected.

ignorethecode.net/…/stop_uploading_your_data_to_g…

E_coli42@lemmy.world on 03 Jan 06:23 collapse

That’s fine as a general guideline, but does not need to be a steadfast rule. You can use your own judgement. I like ProtonPass’s SimpleLogin feature so I use that for email aliases. Its so nice and convenient.

viscacha@feddit.org on 02 Jan 07:48 next collapse

KeePassium on iOS and the .kdbx-files in your iCloud for sync? Strongbox for macOS.

guymontag@lemmy.ml on 02 Jan 08:32 collapse

I don’t wanna be reliant on icloud. Also keepassxc web ui sucks ass.

copyscam@lemmy.ml on 02 Jan 16:27 next collapse

I use ExpressVPN and their PW manager. I love it. It also has 2fa keys. Super dynamic and has worked on a few different phones I’ve had as well as browsers (Vivaldi, brave, etc)

guymontag@lemmy.ml on 02 Jan 19:43 collapse

I wouldn’t trust any of those vpns that do a shit ton of youtube sponsors. You should try mullvad.

copyscam@lemmy.ml on 02 Jan 23:30 collapse

not aware of youtube sponsorships or why that would matter. I’ve used it for like 4 years now and have had no problems.

Fokeu@lemmy.zip on 05 Jan 12:10 next collapse

KeepassXC

nitrolife@rekabu.ru on 01 Jan 08:40 next collapse

KeePassXC. I think you can install client on every OS.

Sirius006@sh.itjust.works on 06 Jan 22:13 collapse

If it can help you, I’m in the process of choosing a password manager for my small company and asked this (awesome) community for help.

I made a table with the results so far. You can find it here : sh.itjust.works/post/52850975

I’m still lost, but I hope it can help you…