I dont agree with many things apple does at all, and I also think their password manager has flaws like revealing usernames without authentification.

It is pretty handy though, to have a file where the entries are stored unencrypted, and if the password manager detects an entry it prompts to decrypt exactly that field, maybe with a fingerprint.

KeepassDX needs to run in the background and be completely unlocked to even detect apps or password fields.

Do you know any existing app that can do this?

26 points

Bitwarden if you want it in the cloud, Keepass if you want it on the device. I’d recommend PrivacyGuides.org’s recommendations this time. They are rather careful as to what they recommend, still doesn’t mean they always get it right.

permalink
report
reply
10 points

You can also self-host Bitwarden using Vaultwarden.

permalink
report
parent
reply
6 points

You can also run Bitwarden proper locally but unless you really know how to run and maintain a web server I wouldn’t recommend this.

permalink
report
parent
reply
3 points
*

The official docker image uses a lot more resources than the vaultwarden container, but it allows significantly more than 100 users. If it’s just for yourself and your family I suggest just going with Vaultwarden.

permalink
report
parent
reply
3 points

Yes, but that is still cloud based. Keepass is local

permalink
report
parent
reply

Well, only if you host it in the cloud. Not if you host it at home, for example.

permalink
report
parent
reply
7 points

KeePassDX + Syncthing is the best solution.

permalink
report
parent
reply
1 point

Use that but its not about that topic. Its about storing unencrypted metadata (or usinh android Keystore for example) and having autofill work always even if the database is locked, and its quickly unlocked just for that entry

permalink
report
parent
reply
2 points

I don’t think any password managers that don’t have that feature currently are likely to implement this feature after the beating that LastPass took in the press about it:

LastPass breach is worse than you think because URLs were unencrypted

Maybe an app might be able to cache the metadata locally but I don’t think it would be something people expect to be unprotected at this point.

permalink
report
parent
reply
1 point

I like this solution but it’s not really entry level

permalink
report
parent
reply
1 point

What do you think about PrivacyTools.io? Are they on the same level as PrivacyGuides.org?

permalink
report
parent
reply
2 points

As announced on July 27th, and on Sept 14th, 2021, The Team Formerly Known As PrivacyTools.io – the entirety of the team providing privacy-related advice & services to you for the past couple years – has transitioned to PrivacyGuides.org and r/PrivacyGuides. Please join us there. :) For more recent news regarding The Reddit Blackout, see: https://lemmy.one/post/74432.

Taken straight from the privacytools.io subreddit description. This will tell you more.

Privacytools.io does seem to be quite outdated currently. There are other good sources out there however.

permalink
report
parent
reply
14 points

The recently released Proton Pass is also open-source and audited, keeps all the entries (including metadata) encrypted, and has a nice UI on mobile.

permalink
report
reply
2 points

it’s worth mentioning that protonpass unlocks biometrical on mobile devices and the browser-plugins support 6-digit pin codes.

permalink
report
parent
reply
2 points

Also, for little money gain unlimited mail aliases (and the desktop UI is also nice :) )

permalink
report
parent
reply
1 point
Deleted by creator
permalink
report
parent
reply
4 points
*

Kinda confused, you want a password manager that stores entries unencrypted but when you need them, the manager encrypts the entry and then prompts you for authetication to autofill the entry? That seems kinda dumb but if its just for convenience to not input your masterpassword everytime, keepassdx allows biometric unlocking. Think it’ll take as much time as what you described without potentially exposing any unencrypted entry info

Edit: Before someone jumps at my throat, security wise using biometrics is also kinda a no no but I understand not everyone has the same threat model so go for it if you want

permalink
report
reply

If I understand it correctly, the passwords are stored encrypted, but not the additional data, like website-URLs and app-names. This way the password manager only needs to temporarily decrypt a specific password when it’s needed for auto-fill. In regards to the passwords that’s probably a bit safer than keeping all the data and the passwords unencrypted in memory. But the cost is that all the other data is stored unencrypted.

permalink
report
parent
reply
4 points

Ohh thats kinda interesting I didnt know this. I appreciate the info

permalink
report
parent
reply
1 point

100%

permalink
report
parent
reply
3 points

Use KeePassXC. Audited, code, open-source, highly customizable, zero cloud stuff.

permalink
report
reply
3 points

Think its for mobile since they mentioned keepassdx

permalink
report
parent
reply
1 point

Yes I already use these. On Linux I use Kwallet, store my huge random Keepass password in there and unlock the Keepass database by fetching that password using a shortcut.

But still, then the password storage is open. Not as elegant as an on-demand password requester, especially on Android

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 6.2K

    Monthly active users

  • 2.9K

    Posts

  • 78K

    Comments