TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: LastPass Alternatives

49 点作者 cripblip超过 2 年前
As I change passwords and research migrating from Lastpass, what are the current HN recommendations, Linux, Firefox, IOS please..

31 条评论

LinuxBender超过 2 年前
KeePassXC can be synchronized to&#x2F;from any public or private cloud platform using your existing sync tools specific to each platform. [1] The benefit being cloud-agnostic and avoiding vendor lock-in.<p>[1] - <a href="https:&#x2F;&#x2F;keepassxc.org&#x2F;docs&#x2F;#faq-cloudsync" rel="nofollow">https:&#x2F;&#x2F;keepassxc.org&#x2F;docs&#x2F;#faq-cloudsync</a>
评论 #34138953 未加载
hcal超过 2 年前
I just use Firefox sync. It integrated with iOS and Android. You just install the app and use the system settings to set Firefox as the default password store for the system. It works in all apps, as far as I can tell. I wish it integrated with Linux&amp; gnome a bit better, but I just work around that by bookmarking the browser link to the password page in Firefox.<p>I trust Mozilla more than any random app that advertises on random podcasts. I like that it warns me when sites I use have been compromised, and that it is generally easy to use. That said, I am not a security expert, so I am interested to see if anybody has any concerns about this setup.
评论 #34140595 未加载
评论 #34138886 未加载
manuel2258超过 2 年前
Bitwarden. Very straight forward and open source
评论 #34138226 未加载
评论 #34138710 未加载
评论 #34138189 未加载
评论 #34138828 未加载
评论 #34139028 未加载
评论 #34138693 未加载
sondr3超过 2 年前
Throughout the years I&#x27;ve tried most of the more popular ones on the market, some times forced via work and other times because I was curious.<p>- KeePassXC: tried this when I was looking for a self-hosted, open-source alternative to LastPass years ago. Was surprised at how well it worked, but syncing was too much of a hassle so I gave up fairly quickly.<p>- 1Password: my favorite of the bunch so far, great UI and UX, works seamlessly across all my devices with all the stuff I want and need: credit card info, logins, 2FA, automatic hidden email generation via Fastmail, easy sharing and family accounts work really well, CLI for use in scripts and now builtin SSH-key management. Not a huge fan of the subscription model, but probably the service I am most happy to pay for.<p>- LastPass: was forced to use this at my previous job, absolutely hated it. The UI and UX feels ten years behind 1Pass and Bitwarden, it&#x27;s slow and not nearly as featureful as the alternatives. I switched from them when they were bought out by LogMeIn, but it doesn&#x27;t look like the product has meaningfully changed since then.<p>- BitWarden: played around with this for a while, but didn&#x27;t switch from 1Pass mostly because I am not willing to host something like this myself and it costs the same as 1Pass with less features and polish.<p>Personally, I would recommend 1Pass for a &quot;it just works&quot; and Bitwarden hosted yourself if you want the same but on your own premises via <a href="https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden">https:&#x2F;&#x2F;github.com&#x2F;dani-garcia&#x2F;vaultwarden</a>.
评论 #34139223 未加载
评论 #34139067 未加载
评论 #34138917 未加载
评论 #34138939 未加载
评论 #34139365 未加载
评论 #34142011 未加载
3guk超过 2 年前
1Password for me - not overly happy that they moved over to a subscription based pricing, but I’ve been using it for years now and it works well across all of my devices.
评论 #34138381 未加载
SpeedilyDamage超过 2 年前
As someone historically adjacent to the security industry, and having worked with some of the best, all I can say for sure is that questions like these really bring out some of the worst, most bespoke, and operationally insecure password management strategies that fail miserably to understand the problem.<p>I use 1pass. I don’t know if they’re actually better. I wouldn’t recommend rolling your own here, however, even if you can’t think of why your solution would have flaws.<p>It takes a special kind of mind to accept the limitations of your perspective, and this is a field ripe with that exact kind of bias.
aborsy超过 2 年前
KeepassXC is a thick client password manager. Password store might be even more secure.<p>If you want “seamless sync of your secrets” by a trusted 3rd party with an online vault, well, then, Bitwarden or 1Password. But the architecture is roughly the same as that of lastpass (though they also encrypt URLs, and might have better KDF, and operational security).<p>In particular, you should assume that 3-letter agencies snapshot data in cloud placed at their feet, have your vault, and may attempt to crack it should that be needed.
评论 #34138865 未加载
marcrosoft超过 2 年前
Isn’t the solution obvious? Just don’t store the entire password in the manager. Add a memorized manual prefix or suffix to the randomly generated&#x2F;filled in password when you log in. Trust nobody. It’s not too much extra work and protects against anything like this in the future.
vhodges超过 2 年前
Keepass (I use KeepassXC on Linux, MacOS and Android) family or Bitwarden self hosted (never used) are probably going to be the top comments.
评论 #34174849 未加载
obblekk超过 2 年前
I use KeePass and just save the encrypted file in iCloud.<p>Easy, end to end encrypted, always up to date, free.<p><a href="https:&#x2F;&#x2F;open.substack.com&#x2F;pub&#x2F;magoop&#x2F;p&#x2F;how-to-manage-500-passwords-securely" rel="nofollow">https:&#x2F;&#x2F;open.substack.com&#x2F;pub&#x2F;magoop&#x2F;p&#x2F;how-to-manage-500-pas...</a>
评论 #34138817 未加载
lynndotpy超过 2 年前
I use and generally recommend 1password. I&#x27;ve used it on every major mobile and desktop OS browser. (I&#x27;ve had some issues on Android, but it was not a standard Android OS.) The UX is generally nice.<p>First, they encrypt with the secret key AND the master password. This is the most important thing, and I was shocked to learn Lastpass doesn&#x27;t do it.<p>Second, the master password runs through PBKDF2 with 100000 rounds, but a precursory Google search suggests the very earliest versions used around 10000. Lastpass&#x27;s problem was a low 5000 rounds, and did not update the number of rounds. I don&#x27;t know if 1password updates the number of rounds.<p>Third, they use a zero-knowledge proof protocol called &quot;secure remote password&quot;. When I was sharp in cryptography, this is what made me choose 1password over the others. I don&#x27;t understand all the details anymore, and I don&#x27;t know if it is &quot;post-quantum secure.&quot;<p>Fourth, the UX is nice and I can recommend it to anybody who is literate. (This is not a cynical take-- I don&#x27;t know how good the UX is for someone who is not fluent in a language 1password uses.) (Also, 1password recently released &quot;1password 8&quot;, a new UI. I have not tried it and cannot speak to it.)<p>Fifth, 1password&#x27;s biggest (only?) controversy was moving to a subscription model. I actually prefer this. (I want devs to be paid in perpetuity to keep this secure! I assume 1password has security holes somewhere, and I want 1password to pay their folks to find them first.)<p>Unfortunately, the monthly price &quot;billed annually&quot; is $3&#x2F;month, but it seems the true monthly price is hidden behind a signup wall. I feel comfortable assuming the price is less than $10 per month.<p>Sixth, and most importantly: If your payment lapses, you can still access all your passwords, but you no longer get sync. (But I have not tried this in practice.)<p>---<p>1password security whitepaper: <a href="https:&#x2F;&#x2F;1passwordstatic.com&#x2F;files&#x2F;security&#x2F;1password-white-paper.pdf" rel="nofollow">https:&#x2F;&#x2F;1passwordstatic.com&#x2F;files&#x2F;security&#x2F;1password-white-p...</a><p>1password security overview: <a href="https:&#x2F;&#x2F;support.1password.com&#x2F;1password-security&#x2F;" rel="nofollow">https:&#x2F;&#x2F;support.1password.com&#x2F;1password-security&#x2F;</a><p>Secure Remote Password (SRP) overview: <a href="https:&#x2F;&#x2F;blog.1password.com&#x2F;developers-how-we-use-srp-and-you-can-too&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.1password.com&#x2F;developers-how-we-use-srp-and-you...</a>
drabadur超过 2 年前
I use a KeePass database stored on iCloud, with the KeePassium client on IOS, and the KeePass client on Windows. Works like a charm.
andrewinardeer超过 2 年前
1Password.<p>The UX is simple enough so every person in my family from wife to kids can use it. Because ensuring your family&#x27;s cybersec is important as well. Teach your kids good cyber hygiene from day one.<p>1Password deals with the infra and software stack which is a time saver for me.
atomashevic超过 2 年前
I just switched to Bitwarden after seeing it recommended on HN a bunch of times. Bought a subscription right away.<p>I previously stored everything in Firefox, transfered it easily to Bitwarden. Linux app seems to work fine, tested in Firefox, Chrome, Android phone, smooth transition.<p>The only thing that I&#x27;ve noticed is that you have to change existing passwords manually by editing records in the vault, the Firefox extension does not prompt you to update password once it detects a succesful login with another one.
评论 #34143576 未加载
RcouF1uZ4gsC超过 2 年前
Does anyone know of an open source tool that will reliably export LastPass entries to the other formats or even a csv?<p>The LastPass exporter IME is very unreliable.
评论 #34138967 未加载
millyleaves超过 2 年前
Used to use Password Safe early on before switching to KeePassXC. Have the KDBX file synced across my phone and desktop with Syncthing
nytesky超过 2 年前
For a while I used an encrypted excel spreadsheet (AES-256 but no idea about other tuning) and stored in OneDrive. Could open just about anywhere since Office is everywhere and OneDrive pretty ubiquitous (I’m guessing no Linux though except Wine?). I have moved to BitWarden now because so many passwords a spreadsheet is cumbersome and prone to fat fingers.
supergenpassfan超过 2 年前
I use a locally saved version of supergenpass<p><a href="https:&#x2F;&#x2F;chriszarate.github.io&#x2F;supergenpass&#x2F;mobile&#x2F;" rel="nofollow">https:&#x2F;&#x2F;chriszarate.github.io&#x2F;supergenpass&#x2F;mobile&#x2F;</a><p>It combines an easily recalled password with domain to generate a longer password. I feel quite safe using this as no data is stored anywhere.
评论 #34139788 未加载
spencera超过 2 年前
I&#x27;ve tried Bitearden, and it&#x27;s great (and free) but the best option is 1Password if you ask me.
akoshodi超过 2 年前
Enpass, an offline password manager with option of syncing vault to third party apps like Dropbox or Google drive. <a href="https:&#x2F;&#x2F;www.enpass.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.enpass.io&#x2F;</a>
Configure0251超过 2 年前
I will add another voice in favour of Bitwarden. It even has some nice visual polish after many years. I pay the 10$ per year because that&#x27;s basically free and the value prop is obvious (to me). YMMV
longdudefromnl超过 2 年前
BitWarden as Home Assistant Addon. Make sure to also run the &#x27;Google Backup&#x27; addon for HA to have a backup for your passwords. Running it for 2+ years now (Raspberry Pi 3). Works like a charm.
nytesky超过 2 年前
I would love to use iCloud Keychain, but it doesn’t have extra fields, support OTP, or even really have a proper GUI.<p>Rumor was Apple uses 1pass internally???
评论 #34138920 未加载
nowherebeen超过 2 年前
Been using KeePassXC for the last five years.
taleodor超过 2 年前
Look at <a href="https:&#x2F;&#x2F;spectre.app&#x2F;" rel="nofollow">https:&#x2F;&#x2F;spectre.app&#x2F;</a>
TDiblik超过 2 年前
KeePass with db stored on OneDrive
xnx超过 2 年前
I&#x27;ve been very happy with the built-in Chrome&#x2F;Google password manager.
markuman123超过 2 年前
Passwords for nextcloud
Pabblo001超过 2 年前
+1 for - Bitwarden
mato超过 2 年前
vim ~&#x2F;docs&#x2F;passwords.gpg
评论 #34138779 未加载
highhedgehog超过 2 年前
bitwarden is the obvious choice