Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #263289 > unrolled thread
| Started by | <paulf@quillandmouse.com> |
|---|---|
| First post | 2023-11-09 17:20 +0100 |
| Last post | 2023-11-17 00:10 +0100 |
| Articles | 20 on this page of 33 — 19 participants |
Back to article view | Back to linux.debian.user
Password managers <paulf@quillandmouse.com> - 2023-11-09 17:20 +0100
Re: Password managers Todd Zullinger <tmz@pobox.com> - 2023-11-09 19:00 +0100
Re: Password managers <paulf@quillandmouse.com> - 2023-11-10 06:40 +0100
Re: Password managers <paulf@quillandmouse.com> - 2023-11-10 07:00 +0100
Re: Password managers Eric S Fraga <e.fraga@ucl.ac.uk> - 2023-11-10 12:50 +0100
Re: Password managers Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-09 19:50 +0100
Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-12 16:10 +0100
Re: Password managers Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-12 17:00 +0100
Re: Password managers Erwan David <erwan@rail.eu.org> - 2023-11-12 18:20 +0100
Re: Password managers Klaus Singvogel <deb-user-ml@singvogel.net> - 2023-11-13 15:20 +0100
Re: Password managers Erwan David <erwan@rail.eu.org> - 2023-11-13 15:30 +0100
Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-13 18:10 +0100
Re: Password managers Joe <joe@jretrading.com> - 2023-11-12 18:30 +0100
Re: Password managers Hans <hans.ullrich@loop.de> - 2023-11-12 19:00 +0100
Re: Password managers "der.hans" <deb-user@LuftHans.com> - 2023-11-09 21:10 +0100
Re: Password managers "der.hans" <deb-user@LuftHans.com> - 2023-11-10 03:30 +0100
Re: Password managers John Darrah <xyllyx@gmail.com> - 2023-11-10 01:40 +0100
Re: Password managers conover@panix.com (John Conover) - 2023-11-10 02:10 +0100
Re: Password managers Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-11-10 11:30 +0100
Re: Password managers Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-11-10 11:40 +0100
Re: Password managers Peter Hillier-Brook <phb@hbsys.plus.com> - 2023-11-10 12:50 +0100
Re: Password managers John Hasler <john@sugarbit.com> - 2023-11-13 18:50 +0100
Re: Password managers <paulf@quillandmouse.com> - 2023-11-14 04:00 +0100
Re: Password managers conover@panix.com (John Conover) - 2023-11-14 06:00 +0100
Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-14 17:40 +0100
Re: Password managers Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-14 21:10 +0100
Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-15 03:40 +0100
Re: Password managers Michel Verdier <mv524@free.fr> - 2023-11-15 09:50 +0100
Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-15 18:30 +0100
Re: Password managers <paulf@quillandmouse.com> - 2023-11-14 22:40 +0100
Re: Password managers Oliver Schode <oliver.schode@online.de> - 2023-11-16 06:10 +0100
Re: Password managers Michel Verdier <mv524@free.fr> - 2023-11-16 10:20 +0100
Re: Password managers Ryan Nowakowski <tubaman@fattuba.com> - 2023-11-17 00:10 +0100
Page 1 of 2 [1] 2 Next page →
| From | <paulf@quillandmouse.com> |
|---|---|
| Date | 2023-11-09 17:20 +0100 |
| Subject | Password managers |
| Message-ID | <HyfV7-4gzN-3@gated-at.bofh.it> |
Folks: I have a bash/GPG based password manager I wrote years ago, but I'd like to use something more "accepted/popular". The problem I have with the other password managers I've looked at is that you can store a very limited amount of information for each "account". For example, for one of my logins, I may have to store the answers to three security questions, an account login, email address, the actual password, and maybe the mobile phone number associated with the login. I also object to my password information being stored online by some password manager vendor. Does anyone know of a password manager which will store a variety of user-defined information for each login, and not store that information on the internet (and which is free as in beer)? Paul -- Paul M. Foster Personal Blog: http://noferblatz.com Company Site: http://quillandmouse.com Software Projects: https://gitlab.com/paulmfoster
[toc] | [next] | [standalone]
| From | Todd Zullinger <tmz@pobox.com> |
|---|---|
| Date | 2023-11-09 19:00 +0100 |
| Message-ID | <HyhtT-4hko-5@gated-at.bofh.it> |
| In reply to | #263289 |
[Multipart message — attachments visible in raw view] — view raw
Hi, paulf@quillandmouse.com wrote: > I have a bash/GPG based password manager I wrote years ago, but I'd > like to use something more "accepted/popular". The problem I have with > the other password managers I've looked at is that you can store a very > limited amount of information for each "account". For example, for > one of my logins, I may have to store the answers to three security > questions, an account login, email address, the actual password, and > maybe the mobile phone number associated with the login. I also object > to my password information being stored online by some password manager > vendor. > > Does anyone know of a password manager which will store a variety of > user-defined information for each login, and not store that information > on the internet (and which is free as in beer)? You may like pass[1]. It's a bash script which uses gpg, so it's somewhat familiar to what you've written in a sense. It supports random data via the --multiline (-m) option. It's locally hosted (though you can use online syncing tools if you want). There are a a good number of alternative clients for it as well, to suit various use cases or environments. [1] https://www.passwordstore.org/ -- Todd
[toc] | [prev] | [next] | [standalone]
| From | <paulf@quillandmouse.com> |
|---|---|
| Date | 2023-11-10 06:40 +0100 |
| Message-ID | <Hyspj-4o0O-1@gated-at.bofh.it> |
| In reply to | #263295 |
On Thu, 9 Nov 2023 12:46:23 -0500 Todd Zullinger <tmz@pobox.com> wrote: > Hi, > > paulf@quillandmouse.com wrote: > > I have a bash/GPG based password manager I wrote years ago, but I'd > > like to use something more "accepted/popular". The problem I have > > with the other password managers I've looked at is that you can > > store a very limited amount of information for each "account". For > > example, for one of my logins, I may have to store the answers to > > three security questions, an account login, email address, the > > actual password, and maybe the mobile phone number associated with > > the login. I also object to my password information being stored > > online by some password manager vendor. > > > > Does anyone know of a password manager which will store a variety of > > user-defined information for each login, and not store that > > information on the internet (and which is free as in beer)? > > You may like pass[1]. It's a bash script which uses gpg, so > it's somewhat familiar to what you've written in a sense. > > It supports random data via the --multiline (-m) option. > > It's locally hosted (though you can use online syncing tools > if you want). There are a a good number of alternative > clients for it as well, to suit various use cases or > environments. > > [1] https://www.passwordstore.org/ > Excellent suggestion! I can't get it to work properly, because there must be something fundamentally missing in my understanding of GPG, etc. To initiate the store, you use the following command: pass init <gpg-id> If I feed this my master password for the "gpg-id", the .gpg-id file in the password store shows my master password in the clear. This can't be right. None of the docs explain what a "gpg-id" actually is. I found some docs on Redhat's site where you could generate a gpg file: gpg --full-generate-key This asks a bunch of questions, and asks me for my master password. It generates a file: ~/.gnupg/pubring.kbx, and add a couple of hex strings in ~/.gnupg/private-keys-v1.d. Seems like I should be using one of those strings as my private key for gpg-id, but which one? I'm really not sure what to give the init command for a gpg-id. Any help would be much appreciated. Paul -- Paul M. Foster Personal Blog: http://noferblatz.com Company Site: http://quillandmouse.com Software Projects: https://gitlab.com/paulmfoster
[toc] | [prev] | [next] | [standalone]
| From | <paulf@quillandmouse.com> |
|---|---|
| Date | 2023-11-10 07:00 +0100 |
| Message-ID | <HysIF-4o7K-1@gated-at.bofh.it> |
| In reply to | #263322 |
On Fri, 10 Nov 2023 00:39:08 -0500 <paulf@quillandmouse.com> wrote: > On Thu, 9 Nov 2023 12:46:23 -0500 > Todd Zullinger <tmz@pobox.com> wrote: > > > > > [1] https://www.passwordstore.org/ > > > > Excellent suggestion! > > I can't get it to work properly, because there must be something > fundamentally missing in my understanding of GPG, etc. > > To initiate the store, you use the following command: > > pass init <gpg-id> > > If I feed this my master password for the "gpg-id", the .gpg-id file > in the password store shows my master password in the clear. This > can't be right. None of the docs explain what a "gpg-id" actually is. > > I found some docs on Redhat's site where you could generate a gpg > file: > > gpg --full-generate-key > > This asks a bunch of questions, and asks me for my master password. It > generates a file: ~/.gnupg/pubring.kbx, and add a couple of hex > strings in ~/.gnupg/private-keys-v1.d. Seems like I should be using > one of those strings as my private key for gpg-id, but which one? > > I'm really not sure what to give the init command for a gpg-id. Any > help would be much appreciated. > > Paul > Sorry for the confusion. I figured it out. The gpg-id is the ID I used when I set up the gpg key mentioned above. I was able to set up pass and add password entries. Paul -- Paul M. Foster Personal Blog: http://noferblatz.com Company Site: http://quillandmouse.com Software Projects: https://gitlab.com/paulmfoster
[toc] | [prev] | [next] | [standalone]
| From | Eric S Fraga <e.fraga@ucl.ac.uk> |
|---|---|
| Date | 2023-11-10 12:50 +0100 |
| Message-ID | <Hyybn-4rAD-1@gated-at.bofh.it> |
| In reply to | #263295 |
On Thursday, 9 Nov 2023 at 12:46, Todd Zullinger wrote: > You may like pass[1]. It's a bash script which uses gpg, so > it's somewhat familiar to what you've written in a sense. +1 *and* it has an Emacs interface which is very easy to use. -- Eric S Fraga via gnus (Emacs 30.0.50 2023-06-19) on Debian 12.0
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <2695bd53d63c@ewoof.net> |
|---|---|
| Date | 2023-11-09 19:50 +0100 |
| Message-ID | <Hyigh-4hRf-9@gated-at.bofh.it> |
| In reply to | #263289 |
On 9 Nov 2023 11:05 -0500, from paulf@quillandmouse.com: > Does anyone know of a password manager which will store a variety of > user-defined information for each login, and not store that information > on the internet (and which is free as in beer)? KeepassXC if you want a primarily GUI solution which also happens to be open source. (There's also a command-line version keepassxc-cli which can either be driven from the command line or used interactively in a terminal session.) pass if you want something which mimics your homegrown solution. Any decent password manager should have a free-form notes field and I can confirm that KeepassXC 2.7.4 (which is the version currently packaged in Bookworm) searches in the notes field when I type into the search field in the GUI. -- Michael Kjörling 🔗 https://michael.kjorling.se “Remember when, on the Internet, nobody cared that you were a dog?”
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-11-12 16:10 +0100 |
| Message-ID | <Hzkg3-4UHx-73@gated-at.bofh.it> |
| In reply to | #263301 |
On 10/11/2023 01:48, Michael Kjörling wrote: > KeepassXC if you want a primarily GUI solution which also happens to > be open source. (There's also a command-line version keepassxc-cli > which can either be driven from the command line or used interactively > in a terminal session.) Having system booted from Debian Live image (assume some disaster), how many packaged have to be installed to get access to passwords stored by KeePassXC?
[toc] | [prev] | [next] | [standalone]
| From | Michael Kjörling <2695bd53d63c@ewoof.net> |
|---|---|
| Date | 2023-11-12 17:00 +0100 |
| Message-ID | <Hzl2p-4UXZ-1@gated-at.bofh.it> |
| In reply to | #263423 |
On 12 Nov 2023 22:07 +0700, from manikulin@gmail.com (Max Nikulin): > Having system booted from Debian Live image (assume some disaster), how many > packaged have to be installed to get access to passwords stored by > KeePassXC? I don't know about Debian Live images, but from an up-to-date install of my _very_ minimal VM setup (Bookworm with only the standard and ssh-server tasks installed), "apt-get install keepassxc" pulls in 142 packages totalling about 91 MB of downloads. Many of those packages are fairly obviously generally GUI-related and not directly related to KeepassXC specifically, so on a live image, which already has a GUI, it would be much less. > # apt-get -u install keepassxc > [...] > The following NEW packages will be installed: > adwaita-icon-theme at-spi2-common at-spi2-core dconf-gsettings-backend > dconf-service fontconfig fontconfig-config fonts-dejavu-core > fonts-font-awesome gsettings-desktop-schemas gtk-update-icon-cache > hicolor-icon-theme keepassxc libatk-bridge2.0-0 libatk1.0-0 libatspi2.0-0 > libavahi-client3 libavahi-common-data libavahi-common3 libbotan-2-19 > libcairo-gobject2 libcairo2 libcolord2 libcups2 libdatrie1 libdconf1 > libdeflate0 libdouble-conversion3 libdrm-amdgpu1 libdrm-common libdrm-intel1 > libdrm-nouveau2 libdrm-radeon1 libdrm2 libegl-mesa0 libegl1 libepoxy0 > libevdev2 libfontconfig1 libfribidi0 libgbm1 libgdk-pixbuf-2.0-0 > libgdk-pixbuf2.0-bin libgdk-pixbuf2.0-common libgl1 libgl1-mesa-dri > libglapi-mesa libglvnd0 libglx-mesa0 libglx0 libgraphite2-3 libgtk-3-0 > libgtk-3-bin libgtk-3-common libgudev-1.0-0 libharfbuzz0b libice6 > libinput-bin libinput10 libjbig0 libjpeg62-turbo liblcms2-2 liblerc4 > libllvm15 libmd4c0 libminizip1 libmtdev1 libpango-1.0-0 libpangocairo-1.0-0 > libpangoft2-1.0-0 libpciaccess0 libpcre2-16-0 libpcsclite1 libpixman-1-0 > libqrencode4 libqt5concurrent5 libqt5core5a libqt5dbus5 libqt5gui5 > libqt5network5 libqt5qml5 libqt5qmlmodels5 libqt5quick5 libqt5svg5 > libqt5waylandclient5 libqt5waylandcompositor5 libqt5widgets5 > libqt5x11extras5 librsvg2-2 librsvg2-common libsensors-config libsensors5 > libsm6 libthai-data libthai0 libtiff6 libtspi1 libwacom-common libwacom9 > libwayland-client0 libwayland-cursor0 libwayland-egl1 libwayland-server0 > libwebp7 libx11-xcb1 libxcb-dri2-0 libxcb-dri3-0 libxcb-glx0 libxcb-icccm4 > libxcb-image0 libxcb-keysyms1 libxcb-present0 libxcb-randr0 > libxcb-render-util0 libxcb-render0 libxcb-shape0 libxcb-shm0 libxcb-sync1 > libxcb-util1 libxcb-xfixes0 libxcb-xinerama0 libxcb-xinput0 libxcb-xkb1 > libxcomposite1 libxcursor1 libxdamage1 libxfixes3 libxi6 libxinerama1 > libxkbcommon-x11-0 libxkbcommon0 libxrandr2 libxrender1 libxshmfence1 > libxtst6 libxxf86vm1 libz3-4 libzxcvbn0 qt5-gtk-platformtheme > qttranslations5-l10n qtwayland5 x11-common > 0 upgraded, 142 newly installed, 0 to remove and 0 not upgraded. > Need to get 90.9 MB of archives. > After this operation, 379 MB of additional disk space will be used. -- Michael Kjörling 🔗 https://michael.kjorling.se “Remember when, on the Internet, nobody cared that you were a dog?”
[toc] | [prev] | [next] | [standalone]
| From | Erwan David <erwan@rail.eu.org> |
|---|---|
| Date | 2023-11-12 18:20 +0100 |
| Message-ID | <HzmhP-4VR8-1@gated-at.bofh.it> |
| In reply to | #263425 |
Le 12/11/2023 à 16:53, Michael Kjörling a écrit : > On 12 Nov 2023 22:07 +0700, from manikulin@gmail.com (Max Nikulin): >> Having system booted from Debian Live image (assume some disaster), how many >> packaged have to be installed to get access to passwords stored by >> KeePassXC? > I don't know about Debian Live images, but from an up-to-date install > of my _very_ minimal VM setup (Bookworm with only the standard and > ssh-server tasks installed), "apt-get install keepassxc" pulls in 142 > packages totalling about 91 MB of downloads. > > Many of those packages are fairly obviously generally GUI-related and > not directly related to KeepassXC specifically, so on a live image, > which already has a GUI, it would be much less. > Note that you may have less dependencies with kpcli (a cli client for keepass password files)
[toc] | [prev] | [next] | [standalone]
| From | Klaus Singvogel <deb-user-ml@singvogel.net> |
|---|---|
| Date | 2023-11-13 15:20 +0100 |
| Message-ID | <HzFXb-5aYa-9@gated-at.bofh.it> |
| In reply to | #263427 |
Erwan David wrote: > Note that you may have less dependencies with kpcli (a cli client for > keepass password files) I always was peering at kpcli. Do you have any experience switching between the CLI (kpcli) and the GUI (keepassxc) version frequently? Is this flawless possible to switch from the one to the other and back, or is it something which can't easily to be done? Thanks in advance. Best regards, Klaus. -- Klaus Singvogel GnuPG-Key-ID: 1024R/5068792D 1994-06-27
[toc] | [prev] | [next] | [standalone]
| From | Erwan David <erwan@rail.eu.org> |
|---|---|
| Date | 2023-11-13 15:30 +0100 |
| Message-ID | <HzG6R-5b9X-3@gated-at.bofh.it> |
| In reply to | #263482 |
Le 13/11/2023 à 15:11, Klaus Singvogel a écrit : > Erwan David wrote: >> Note that you may have less dependencies with kpcli (a cli client for >> keepass password files) > I always was peering at kpcli. > > Do you have any experience switching between the CLI (kpcli) and the GUI (keepassxc) version frequently? > > Is this flawless possible to switch from the one to the other and back, or is it something which can't easily to be done? > > Thanks in advance. > > Best regards, > Klaus. That was a bad idea : lokking closer I see that kpcli does not support the latest keepass file format (v4) -- Erwan David
[toc] | [prev] | [next] | [standalone]
| From | Max Nikulin <manikulin@gmail.com> |
|---|---|
| Date | 2023-11-13 18:10 +0100 |
| Message-ID | <HzIBH-5cOE-1@gated-at.bofh.it> |
| In reply to | #263483 |
On 13/11/2023 21:29, Erwan David wrote: > That was a bad idea : lokking closer I see that kpcli does not support > the latest keepass file format (v4) Trying "apt search" I have noticed some python tool "secrets" having python3-pykeepass in its dependency. Does anybody use it (or at least have tried it)? My specific interest is recovery scenario when usually used (and tuned) system is not available, so minimal dependencies matter when a Live image is booted. It seems KeePassXC implements secret.service D-Bus API. Can gnome-keyring/kwallet/KeePassXC be used instead of "native" application for particular desktop or actually there are various lock-ins (e.g. anything other than gnome-keyring is call to trouble in Gnome)?
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2023-11-12 18:30 +0100 |
| Message-ID | <Hzmrv-4VUk-3@gated-at.bofh.it> |
| In reply to | #263423 |
On Sun, 12 Nov 2023 22:07:33 +0700 Max Nikulin <manikulin@gmail.com> wrote: > On 10/11/2023 01:48, Michael Kjörling wrote: > > KeepassXC if you want a primarily GUI solution which also happens to > > be open source. (There's also a command-line version keepassxc-cli > > which can either be driven from the command line or used > > interactively in a terminal session.) > > Having system booted from Debian Live image (assume some disaster), > how many packaged have to be installed to get access to passwords > stored by KeePassXC? > As always, it depends on what you already have. Much of that enormous list may already be there. From a fairly large sid installation: Install: libtspi1:amd64 (0.3.15-0.3, automatic), libzxcvbn0:amd64 (2.5+dfsg-1, automatic), keepassxc:amd64 (2.7.4+dfsg.1-2), libbotan-2-19:amd64 (2.19.3+dfsg-1, automatic) An alternative strategy is to keep the database backed up on a USB device or uSD card etc. I do that anyway for laptop use, not storing the database on the laptop itself. You could also install PortableApps (and KeepassXC Portable) on the card, and have the passwords available on any Windows machine without leaving anything behind on that machine. Whatever you do, it's always a good idea to copy the database to somewhere fairly safe whenever you update it. Or there are other rescue-type distributions which have keepasxc, such as Parted Magic. Knoppix has keepassx, but I'm not sure about file compatibility with that fork. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Hans <hans.ullrich@loop.de> |
|---|---|
| Date | 2023-11-12 19:00 +0100 |
| Message-ID | <HzmUy-4W4l-1@gated-at.bofh.it> |
| In reply to | #263429 |
Am Sonntag, 12. November 2023, 18:23:20 CET schrieb Joe: What about kwallet? Should run on other window managers than plasma5 as well. Hans
[toc] | [prev] | [next] | [standalone]
| From | "der.hans" <deb-user@LuftHans.com> |
|---|---|
| Date | 2023-11-09 21:10 +0100 |
| Message-ID | <HyjvH-4iLt-1@gated-at.bofh.it> |
| In reply to | #263289 |
[Multipart message — attachments visible in raw view] — view raw
Am 09. Nov, 2023 schwätzte paulf@quillandmouse.com so: moin moin Paul, > Folks: > > I have a bash/GPG based password manager I wrote years ago, but I'd > like to use something more "accepted/popular". The problem I have with > the other password managers I've looked at is that you can store a very > limited amount of information for each "account". For example, for > one of my logins, I may have to store the answers to three security > questions, an account login, email address, the actual password, and > maybe the mobile phone number associated with the login. I also object > to my password information being stored online by some password manager > vendor. > > Does anyone know of a password manager which will store a variety of > user-defined information for each login, and not store that information > on the internet (and which is free as in beer)? In KeePass-based projects like KeePassXC you can store the usual title, username, password, URL and notes in the main screen/tab. In the advanced tab you can store further key/value pairs. This works well for storing random strings for security questions and answers. The responses can been starred out like password entries are. There isn't a keyboard shortcut to copy them, but there is a menu drop down, so you can get the values without having to open the entry. There's also an option to add attachments. I say KeePass-based because KeePass was the original project. KeePassX was a port of the windows KeePass project to Linux and other platforms. KeePassXC is a more active, community developed fork of KeePassX. I've been using the latter two for many, many years. Thanks to the developers and packagers for the projects! All 3 are using KeePass file formats. There are other packages that understand the formats. F-Droid has several if you're wanting some of your passwords on your phone. Because it's a common format you have some choice into which tool you want to use. There are also some command line options. The biggest lack I've seen for host-your-own is that there isn't a secure way to do partial sync between password files. For instance, I don't need all my passwords on my phone, so would like to have phone.kdbx with just the few I need, but be able to sync with my everything.kdbx file if changes are made in one or the other. KeePassXC FAQ on file formats. https://keepassxc.org/docs/#faq-format ciao, der.hans > Paul -- # https://www.SpiralArray.com https://www.PhxLinux.org # "You want weapons? We're in a library! Books! The best weapons in the # world! This room's the greatest arsenal we could have - arm yourselves!" # -- the Doctor: Doctor Who, Tooth and Claw, 2006
[toc] | [prev] | [next] | [standalone]
| From | "der.hans" <deb-user@LuftHans.com> |
|---|---|
| Date | 2023-11-10 03:30 +0100 |
| Message-ID | <Hyprr-4m9r-13@gated-at.bofh.it> |
| In reply to | #263305 |
[Multipart message — attachments visible in raw view] — view raw
Am 09. Nov, 2023 schwätzte der.hans so: moin moin, below I said KeePassXC doesn't have a way of syncing passwords with another password database file. Tonight I was looking at KeePassXC SSH integration documentation and I see there is a sharing option, KeeShare. "KeeShare allows you to share a subset of your credentials with others and vice versa." In my example of my phone the others are myself and I :). https://keepassxc.org/docs/KeePassXC_UserGuide#_database_sharing_with_keeshare I will experiment and see if I can get sharing to work the way I want it to. ciao, der.hans > Am 09. Nov, 2023 schwätzte paulf@quillandmouse.com so: > > moin moin Paul, > >> Folks: >> >> I have a bash/GPG based password manager I wrote years ago, but I'd >> like to use something more "accepted/popular". The problem I have with >> the other password managers I've looked at is that you can store a very >> limited amount of information for each "account". For example, for >> one of my logins, I may have to store the answers to three security >> questions, an account login, email address, the actual password, and >> maybe the mobile phone number associated with the login. I also object >> to my password information being stored online by some password manager >> vendor. >> >> Does anyone know of a password manager which will store a variety of >> user-defined information for each login, and not store that information >> on the internet (and which is free as in beer)? > > In KeePass-based projects like KeePassXC you can store the usual title, > username, password, URL and notes in the main screen/tab. > > In the advanced tab you can store further key/value pairs. This works well > for storing random strings for security questions and answers. > > The responses can been starred out like password entries are. There isn't > a keyboard shortcut to copy them, but there is a menu drop down, so you > can get the values without having to open the entry. > > There's also an option to add attachments. > > I say KeePass-based because KeePass was the original project. KeePassX was > a port of the windows KeePass project to Linux and other platforms. > KeePassXC is a more active, community developed fork of KeePassX. I've > been using the latter two for many, many years. > > Thanks to the developers and packagers for the projects! > > All 3 are using KeePass file formats. There are other packages that > understand the formats. F-Droid has several if you're wanting some of your > passwords on your phone. Because it's a common format you have some choice > into which tool you want to use. There are also some command line options. > > The biggest lack I've seen for host-your-own is that there isn't a secure > way to do partial sync between password files. For instance, I don't need > all my passwords on my phone, so would like to have phone.kdbx with just > the few I need, but be able to sync with my everything.kdbx file if > changes are made in one or the other. > > KeePassXC FAQ on file formats. > > https://keepassxc.org/docs/#faq-format > > ciao, > > der.hans > >> Paul > > -- # https://www.SpiralArray.com https://www.PhxLinux.org # It's up to the reader to make the book interesting. # An author has only the opportunity to make it uninteresting. - der.hans
[toc] | [prev] | [next] | [standalone]
| From | John Darrah <xyllyx@gmail.com> |
|---|---|
| Date | 2023-11-10 01:40 +0100 |
| Message-ID | <HynIZ-4l6G-1@gated-at.bofh.it> |
| In reply to | #263289 |
On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote: > Folks: > > Does anyone know of a password manager which will store a variety of > user-defined information for each login, and not store that > information > on the internet (and which is free as in beer)? > Take a look at 'secrets' which is a Gnome native app. It uses a database and key file compatible with Password Safe. -- john
[toc] | [prev] | [next] | [standalone]
| From | conover@panix.com (John Conover) |
|---|---|
| Date | 2023-11-10 02:10 +0100 |
| Message-ID | <Hyoc1-4lvQ-1@gated-at.bofh.it> |
| In reply to | #263311 |
John Darrah writes:
> On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote:
> > Folks:
> >
> > Does anyone know of a password manager which will store a variety of
> > user-defined information for each login, and not store that
> > information
> > on the internet (and which is free as in beer)?
> >
>
> Take a look at 'secrets' which is a Gnome native app. It uses a
> database and key file compatible with Password Safe.
>
Pass works well, too. http://www.passwordstore.org/.
Uses gpg encryption.
John
--
John Conover, conover@panix.com, http://www.johncon.com/
[toc] | [prev] | [next] | [standalone]
| From | Timothy M Butterworth <timothy.m.butterworth@gmail.com> |
|---|---|
| Date | 2023-11-10 11:30 +0100 |
| Message-ID | <HywVY-4qW0-11@gated-at.bofh.it> |
| In reply to | #263312 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Nov 10, 2023 at 3:11 AM John Conover <conover@panix.com> wrote: > John Darrah writes: > > On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote: > > > Folks: > > > > > > Does anyone know of a password manager which will store a variety of > > > user-defined information for each login, and not store that > > > information > > > on the internet (and which is free as in beer)? > > > > > > > Take a look at 'secrets' which is a Gnome native app. It uses a > > database and key file compatible with Password Safe. > I have been looking for a password manager that was as simple and easy to use as password manager and Secrets is definitely it. Thanks so much for pointing out this program. > > Pass works well, too. http://www.passwordstore.org/. > Uses gpg encryption. > > John > > -- > > John Conover, conover@panix.com, http://www.johncon.com/ > > -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/ ⠈⠳⣄⠀⠀
[toc] | [prev] | [next] | [standalone]
| From | Timothy M Butterworth <timothy.m.butterworth@gmail.com> |
|---|---|
| Date | 2023-11-10 11:40 +0100 |
| Message-ID | <Hyx5D-4qZm-21@gated-at.bofh.it> |
| In reply to | #263328 |
[Multipart message — attachments visible in raw view] — view raw
On Fri, Nov 10, 2023 at 5:25 AM Timothy M Butterworth < timothy.m.butterworth@gmail.com> wrote: > > > On Fri, Nov 10, 2023 at 3:11 AM John Conover <conover@panix.com> wrote: > >> John Darrah writes: >> > On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote: >> > > Folks: >> > > >> > > Does anyone know of a password manager which will store a variety of >> > > user-defined information for each login, and not store that >> > > information >> > > on the internet (and which is free as in beer)? >> > > >> > >> > Take a look at 'secrets' which is a Gnome native app. It uses a >> > database and key file compatible with Password Safe. >> > > I have been looking for a password manager that was as simple and easy to > use as password manager and Secrets is definitely it. Thanks so much for > pointing out this program. > I spoke to soon Password Safe is now available for Linux. https://sourceforge.net/projects/passwordsafe/files/Linux/1.18.0/ I used to run Password Safe in Wine. It is so good to see that it has been ported to linux. > >> >> Pass works well, too. http://www.passwordstore.org/. >> Uses gpg encryption. >> >> John >> >> -- >> >> John Conover, conover@panix.com, http://www.johncon.com/ >> >> > > -- > ⢀⣴⠾⠻⢶⣦⠀ > ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system > ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/ > ⠈⠳⣄⠀⠀ > -- ⢀⣴⠾⠻⢶⣦⠀ ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/ ⠈⠳⣄⠀⠀
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web