• Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 hours ago

    I finally exported all of my passwords from Firefox, Google, and iCloud, and dumped it all into my KeePass database (synced between all of devices via Syncthing - works very well). I’ve been slowly going through it, sorting entries not already in KeePass into their respective folders within the database (I’ve used KeePass since high school, I have a system 😅), deleting duplicates, and changing insecure passwords/adding 2FA as I come across them.

    After everything was imported to KeePass and backed up, I deleted all passwords from both accounts and turned off their password saving options. Also changed the “password autofill” option on my Pixel to Keepass2Android, so it’s now the only password handler on any device I own.

    Also filled the downloaded CSVs with random numbers and saved them, a few times, then permanently deleted them. No version history either.

      • BroBot9000@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        1 day ago

        … Physically back up your passwords too.

        Every password in your manager should be written in a little book somewhere in case of exactly that. Keep it with your birth certificate and other important documents.

        Doesn’t take a rocket scientist to figure that one out.

        • ColdSideOfYourPillow@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          17 minutes ago

          Almost all my passwords are 10K characters, I am NOT writing all of them down.

          Also, forgetting the master password just isn’t in my threat model. It should be, but I just can’t care enough for that aspect.

        • lemmyknow@lemmy.today
          link
          fedilink
          English
          arrow-up
          2
          ·
          10 hours ago

          A PHYSICAL PASSWORD BACK UP??? Are you CRAZY??? What if someone gets ahold of my passwords? Just like that, unencrypted? I don’t live alone. There’s people around me that could find said passwords and access said accounts!!!

      • Junkers_Klunker@feddit.dk
        link
        fedilink
        English
        arrow-up
        1
        ·
        10 hours ago

        Yea it was mostly meant as a joke, I do use a password manager and individual passwords for everything. My fiancé on the other hand, shes a lost cause, even though I did the complete setup for her she refuses to use it as it requires her to do something different (but I my opinion easier) than just typing the same password everywhere.

  • Charlxmagne@lemmy.world
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    5
    ·
    edit-2
    24 hours ago

    Use keepassxc, bitwarden became proprietary a while ago, I ain’t letting my password manager do a lastpass and make me a vic of crippling identity fraud

    • rockstarmode@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      17 hours ago

      bitwarden became proprietary a while ago

      I’m interested in hearing more about this. I recall there being a mixup in packaging and people asked a bunch of questions about licensing. But as far as I can tell the client and server code is still available as open source (under various licenses) and the repos are frequently updated.

      This is an honest question, I promise. I haven’t found anything that points to regular users being pushed to anything proprietary, and no new discussions since late 2024.

      • ipitco@lemmy.super.ynh.fr
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        10 hours ago

        Afaik they pushed code that belonged to them and might not entirely be legal to compile yourself due to the code having a different licence. I believe they have 2 things now: the code is still open source, but a part of it is not free to use. The code can still be compiled by using different libraries and I think they support both but it was hard to understand so I don’t really know.

        Also the affected code wasn’t on a super important feature iirc

        I might be completely wrong though