Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #263289 > unrolled thread

Password managers

Started by<paulf@quillandmouse.com>
First post2023-11-09 17:20 +0100
Last post2023-11-17 00:10 +0100
Articles 20 on this page of 33 — 19 participants

Back to article view | Back to linux.debian.user


Contents

  Password managers <paulf@quillandmouse.com> - 2023-11-09 17:20 +0100
    Re: Password managers Todd Zullinger <tmz@pobox.com> - 2023-11-09 19:00 +0100
      Re: Password managers <paulf@quillandmouse.com> - 2023-11-10 06:40 +0100
        Re: Password managers <paulf@quillandmouse.com> - 2023-11-10 07:00 +0100
      Re: Password managers Eric S Fraga <e.fraga@ucl.ac.uk> - 2023-11-10 12:50 +0100
    Re: Password managers Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-09 19:50 +0100
      Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-12 16:10 +0100
        Re: Password managers Michael Kjörling <2695bd53d63c@ewoof.net> - 2023-11-12 17:00 +0100
          Re: Password managers Erwan David <erwan@rail.eu.org> - 2023-11-12 18:20 +0100
            Re: Password managers Klaus Singvogel <deb-user-ml@singvogel.net> - 2023-11-13 15:20 +0100
              Re: Password managers Erwan David <erwan@rail.eu.org> - 2023-11-13 15:30 +0100
                Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-13 18:10 +0100
        Re: Password managers Joe <joe@jretrading.com> - 2023-11-12 18:30 +0100
          Re: Password managers Hans <hans.ullrich@loop.de> - 2023-11-12 19:00 +0100
    Re: Password managers "der.hans" <deb-user@LuftHans.com> - 2023-11-09 21:10 +0100
      Re: Password managers "der.hans" <deb-user@LuftHans.com> - 2023-11-10 03:30 +0100
    Re: Password managers John Darrah <xyllyx@gmail.com> - 2023-11-10 01:40 +0100
      Re: Password managers conover@panix.com (John Conover) - 2023-11-10 02:10 +0100
        Re: Password managers Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-11-10 11:30 +0100
          Re: Password managers Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2023-11-10 11:40 +0100
            Re: Password managers Peter Hillier-Brook <phb@hbsys.plus.com> - 2023-11-10 12:50 +0100
    Re: Password managers John Hasler <john@sugarbit.com> - 2023-11-13 18:50 +0100
      Re: Password managers <paulf@quillandmouse.com> - 2023-11-14 04:00 +0100
        Re: Password managers conover@panix.com (John Conover) - 2023-11-14 06:00 +0100
        Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-14 17:40 +0100
          Re: Password managers Anssi Saari <anssi.saari@debian-user.mail.kapsi.fi> - 2023-11-14 21:10 +0100
            Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-15 03:40 +0100
              Re: Password managers Michel Verdier <mv524@free.fr> - 2023-11-15 09:50 +0100
                Re: Password managers Max Nikulin <manikulin@gmail.com> - 2023-11-15 18:30 +0100
          Re: Password managers <paulf@quillandmouse.com> - 2023-11-14 22:40 +0100
        Re: Password managers Oliver Schode <oliver.schode@online.de> - 2023-11-16 06:10 +0100
          Re: Password managers Michel Verdier <mv524@free.fr> - 2023-11-16 10:20 +0100
          Re: Password managers Ryan Nowakowski <tubaman@fattuba.com> - 2023-11-17 00:10 +0100

Page 1 of 2  [1] 2  Next page →


#263289 — Password managers

From<paulf@quillandmouse.com>
Date2023-11-09 17:20 +0100
SubjectPassword managers
Message-ID<HyfV7-4gzN-3@gated-at.bofh.it>
Folks:

I have a bash/GPG based password manager I wrote years ago, but I'd
like to use something more "accepted/popular". The problem I have with
the other password managers I've looked at is that you can store a very
limited amount of information for each "account". For example, for
one of my logins, I may have to store the answers to three security
questions, an account login, email address, the actual password, and
maybe the mobile phone number associated with the login. I also object
to my password information being stored online by some password manager
vendor.

Does anyone know of a password manager which will store a variety of
user-defined information for each login, and not store that information
on the internet (and which is free as in beer)?

Paul

-- 
Paul M. Foster
Personal Blog: http://noferblatz.com
Company Site: http://quillandmouse.com
Software Projects: https://gitlab.com/paulmfoster

[toc] | [next] | [standalone]


#263295

FromTodd Zullinger <tmz@pobox.com>
Date2023-11-09 19:00 +0100
Message-ID<HyhtT-4hko-5@gated-at.bofh.it>
In reply to#263289

[Multipart message — attachments visible in raw view] — view raw

Hi,

paulf@quillandmouse.com wrote:
> I have a bash/GPG based password manager I wrote years ago, but I'd
> like to use something more "accepted/popular". The problem I have with
> the other password managers I've looked at is that you can store a very
> limited amount of information for each "account". For example, for
> one of my logins, I may have to store the answers to three security
> questions, an account login, email address, the actual password, and
> maybe the mobile phone number associated with the login. I also object
> to my password information being stored online by some password manager
> vendor.
> 
> Does anyone know of a password manager which will store a variety of
> user-defined information for each login, and not store that information
> on the internet (and which is free as in beer)?

You may like pass[1].  It's a bash script which uses gpg, so
it's somewhat familiar to what you've written in a sense.

It supports random data via the --multiline (-m) option.

It's locally hosted (though you can use online syncing tools
if you want).  There are a a good number of alternative
clients for it as well, to suit various use cases or
environments.

[1] https://www.passwordstore.org/

-- 
Todd

[toc] | [prev] | [next] | [standalone]


#263322

From<paulf@quillandmouse.com>
Date2023-11-10 06:40 +0100
Message-ID<Hyspj-4o0O-1@gated-at.bofh.it>
In reply to#263295
On Thu, 9 Nov 2023 12:46:23 -0500
Todd Zullinger <tmz@pobox.com> wrote:

> Hi,
> 
> paulf@quillandmouse.com wrote:
> > I have a bash/GPG based password manager I wrote years ago, but I'd
> > like to use something more "accepted/popular". The problem I have
> > with the other password managers I've looked at is that you can
> > store a very limited amount of information for each "account". For
> > example, for one of my logins, I may have to store the answers to
> > three security questions, an account login, email address, the
> > actual password, and maybe the mobile phone number associated with
> > the login. I also object to my password information being stored
> > online by some password manager vendor.
> > 
> > Does anyone know of a password manager which will store a variety of
> > user-defined information for each login, and not store that
> > information on the internet (and which is free as in beer)?
> 
> You may like pass[1].  It's a bash script which uses gpg, so
> it's somewhat familiar to what you've written in a sense.
> 
> It supports random data via the --multiline (-m) option.
> 
> It's locally hosted (though you can use online syncing tools
> if you want).  There are a a good number of alternative
> clients for it as well, to suit various use cases or
> environments.
> 
> [1] https://www.passwordstore.org/
> 

Excellent suggestion!

I can't get it to work properly, because there must be something
fundamentally missing in my understanding of GPG, etc.

To initiate the store, you use the following command:

pass init <gpg-id>

If I feed this my master password for the "gpg-id", the .gpg-id file in
the password store shows my master password in the clear. This can't be
right. None of the docs explain what a "gpg-id" actually is.

I found some docs on Redhat's site where you could generate a gpg file:

gpg --full-generate-key

This asks a bunch of questions, and asks me for my master password. It
generates a file: ~/.gnupg/pubring.kbx, and add a couple of hex strings
in ~/.gnupg/private-keys-v1.d. Seems like I should be using one of
those strings as my private key for gpg-id, but which one?

I'm really not sure what to give the init command for a gpg-id. Any
help would be much appreciated.

Paul

-- 
Paul M. Foster
Personal Blog: http://noferblatz.com
Company Site: http://quillandmouse.com
Software Projects: https://gitlab.com/paulmfoster

[toc] | [prev] | [next] | [standalone]


#263325

From<paulf@quillandmouse.com>
Date2023-11-10 07:00 +0100
Message-ID<HysIF-4o7K-1@gated-at.bofh.it>
In reply to#263322
On Fri, 10 Nov 2023 00:39:08 -0500
<paulf@quillandmouse.com> wrote:

> On Thu, 9 Nov 2023 12:46:23 -0500
> Todd Zullinger <tmz@pobox.com> wrote:
> 
> > 
> > [1] https://www.passwordstore.org/
> > 
> 
> Excellent suggestion!
> 
> I can't get it to work properly, because there must be something
> fundamentally missing in my understanding of GPG, etc.
> 
> To initiate the store, you use the following command:
> 
> pass init <gpg-id>
> 
> If I feed this my master password for the "gpg-id", the .gpg-id file
> in the password store shows my master password in the clear. This
> can't be right. None of the docs explain what a "gpg-id" actually is.
> 
> I found some docs on Redhat's site where you could generate a gpg
> file:
> 
> gpg --full-generate-key
> 
> This asks a bunch of questions, and asks me for my master password. It
> generates a file: ~/.gnupg/pubring.kbx, and add a couple of hex
> strings in ~/.gnupg/private-keys-v1.d. Seems like I should be using
> one of those strings as my private key for gpg-id, but which one?
> 
> I'm really not sure what to give the init command for a gpg-id. Any
> help would be much appreciated.
> 
> Paul
> 

Sorry for the confusion. I figured it out. The gpg-id is the ID I used
when I set up the gpg key mentioned above. I was able to set up pass
and add password entries.

Paul

-- 
Paul M. Foster
Personal Blog: http://noferblatz.com
Company Site: http://quillandmouse.com
Software Projects: https://gitlab.com/paulmfoster

[toc] | [prev] | [next] | [standalone]


#263330

FromEric S Fraga <e.fraga@ucl.ac.uk>
Date2023-11-10 12:50 +0100
Message-ID<Hyybn-4rAD-1@gated-at.bofh.it>
In reply to#263295
On Thursday,  9 Nov 2023 at 12:46, Todd Zullinger wrote:
> You may like pass[1].  It's a bash script which uses gpg, so
> it's somewhat familiar to what you've written in a sense.

+1

*and* it has an Emacs interface which is very easy to use.

-- 
Eric S Fraga via gnus (Emacs 30.0.50 2023-06-19) on Debian 12.0

[toc] | [prev] | [next] | [standalone]


#263301

FromMichael Kjörling <2695bd53d63c@ewoof.net>
Date2023-11-09 19:50 +0100
Message-ID<Hyigh-4hRf-9@gated-at.bofh.it>
In reply to#263289
On 9 Nov 2023 11:05 -0500, from paulf@quillandmouse.com:
> Does anyone know of a password manager which will store a variety of
> user-defined information for each login, and not store that information
> on the internet (and which is free as in beer)?

KeepassXC if you want a primarily GUI solution which also happens to
be open source. (There's also a command-line version keepassxc-cli
which can either be driven from the command line or used interactively
in a terminal session.)

pass if you want something which mimics your homegrown solution.

Any decent password manager should have a free-form notes field and I
can confirm that KeepassXC 2.7.4 (which is the version currently
packaged in Bookworm) searches in the notes field when I type into the
search field in the GUI.

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”

[toc] | [prev] | [next] | [standalone]


#263423

FromMax Nikulin <manikulin@gmail.com>
Date2023-11-12 16:10 +0100
Message-ID<Hzkg3-4UHx-73@gated-at.bofh.it>
In reply to#263301
On 10/11/2023 01:48, Michael Kjörling wrote:
> KeepassXC if you want a primarily GUI solution which also happens to
> be open source. (There's also a command-line version keepassxc-cli
> which can either be driven from the command line or used interactively
> in a terminal session.)

Having system booted from Debian Live image (assume some disaster), how 
many packaged have to be installed to get access to passwords stored by 
KeePassXC?

[toc] | [prev] | [next] | [standalone]


#263425

FromMichael Kjörling <2695bd53d63c@ewoof.net>
Date2023-11-12 17:00 +0100
Message-ID<Hzl2p-4UXZ-1@gated-at.bofh.it>
In reply to#263423
On 12 Nov 2023 22:07 +0700, from manikulin@gmail.com (Max Nikulin):
> Having system booted from Debian Live image (assume some disaster), how many
> packaged have to be installed to get access to passwords stored by
> KeePassXC?

I don't know about Debian Live images, but from an up-to-date install
of my _very_ minimal VM setup (Bookworm with only the standard and
ssh-server tasks installed), "apt-get install keepassxc" pulls in 142
packages totalling about 91 MB of downloads.

Many of those packages are fairly obviously generally GUI-related and
not directly related to KeepassXC specifically, so on a live image,
which already has a GUI, it would be much less.

> # apt-get -u install keepassxc
> [...]
> The following NEW packages will be installed:
>   adwaita-icon-theme at-spi2-common at-spi2-core dconf-gsettings-backend
>   dconf-service fontconfig fontconfig-config fonts-dejavu-core
>   fonts-font-awesome gsettings-desktop-schemas gtk-update-icon-cache
>   hicolor-icon-theme keepassxc libatk-bridge2.0-0 libatk1.0-0 libatspi2.0-0
>   libavahi-client3 libavahi-common-data libavahi-common3 libbotan-2-19
>   libcairo-gobject2 libcairo2 libcolord2 libcups2 libdatrie1 libdconf1
>   libdeflate0 libdouble-conversion3 libdrm-amdgpu1 libdrm-common libdrm-intel1
>   libdrm-nouveau2 libdrm-radeon1 libdrm2 libegl-mesa0 libegl1 libepoxy0
>   libevdev2 libfontconfig1 libfribidi0 libgbm1 libgdk-pixbuf-2.0-0
>   libgdk-pixbuf2.0-bin libgdk-pixbuf2.0-common libgl1 libgl1-mesa-dri
>   libglapi-mesa libglvnd0 libglx-mesa0 libglx0 libgraphite2-3 libgtk-3-0
>   libgtk-3-bin libgtk-3-common libgudev-1.0-0 libharfbuzz0b libice6
>   libinput-bin libinput10 libjbig0 libjpeg62-turbo liblcms2-2 liblerc4
>   libllvm15 libmd4c0 libminizip1 libmtdev1 libpango-1.0-0 libpangocairo-1.0-0
>   libpangoft2-1.0-0 libpciaccess0 libpcre2-16-0 libpcsclite1 libpixman-1-0
>   libqrencode4 libqt5concurrent5 libqt5core5a libqt5dbus5 libqt5gui5
>   libqt5network5 libqt5qml5 libqt5qmlmodels5 libqt5quick5 libqt5svg5
>   libqt5waylandclient5 libqt5waylandcompositor5 libqt5widgets5
>   libqt5x11extras5 librsvg2-2 librsvg2-common libsensors-config libsensors5
>   libsm6 libthai-data libthai0 libtiff6 libtspi1 libwacom-common libwacom9
>   libwayland-client0 libwayland-cursor0 libwayland-egl1 libwayland-server0
>   libwebp7 libx11-xcb1 libxcb-dri2-0 libxcb-dri3-0 libxcb-glx0 libxcb-icccm4
>   libxcb-image0 libxcb-keysyms1 libxcb-present0 libxcb-randr0
>   libxcb-render-util0 libxcb-render0 libxcb-shape0 libxcb-shm0 libxcb-sync1
>   libxcb-util1 libxcb-xfixes0 libxcb-xinerama0 libxcb-xinput0 libxcb-xkb1
>   libxcomposite1 libxcursor1 libxdamage1 libxfixes3 libxi6 libxinerama1
>   libxkbcommon-x11-0 libxkbcommon0 libxrandr2 libxrender1 libxshmfence1
>   libxtst6 libxxf86vm1 libz3-4 libzxcvbn0 qt5-gtk-platformtheme
>   qttranslations5-l10n qtwayland5 x11-common
> 0 upgraded, 142 newly installed, 0 to remove and 0 not upgraded.
> Need to get 90.9 MB of archives.
> After this operation, 379 MB of additional disk space will be used.

-- 
Michael Kjörling                     🔗 https://michael.kjorling.se
“Remember when, on the Internet, nobody cared that you were a dog?”

[toc] | [prev] | [next] | [standalone]


#263427

FromErwan David <erwan@rail.eu.org>
Date2023-11-12 18:20 +0100
Message-ID<HzmhP-4VR8-1@gated-at.bofh.it>
In reply to#263425
Le 12/11/2023 à 16:53, Michael Kjörling a écrit :
> On 12 Nov 2023 22:07 +0700, from manikulin@gmail.com (Max Nikulin):
>> Having system booted from Debian Live image (assume some disaster), how many
>> packaged have to be installed to get access to passwords stored by
>> KeePassXC?
> I don't know about Debian Live images, but from an up-to-date install
> of my _very_ minimal VM setup (Bookworm with only the standard and
> ssh-server tasks installed), "apt-get install keepassxc" pulls in 142
> packages totalling about 91 MB of downloads.
>
> Many of those packages are fairly obviously generally GUI-related and
> not directly related to KeepassXC specifically, so on a live image,
> which already has a GUI, it would be much less.
>
Note that you may have less dependencies with kpcli (a cli client for 
keepass password files)

[toc] | [prev] | [next] | [standalone]


#263482

FromKlaus Singvogel <deb-user-ml@singvogel.net>
Date2023-11-13 15:20 +0100
Message-ID<HzFXb-5aYa-9@gated-at.bofh.it>
In reply to#263427
Erwan David wrote:
> Note that you may have less dependencies with kpcli (a cli client for
> keepass password files)

I always was peering at kpcli.

Do you have any experience switching between the CLI (kpcli) and the GUI (keepassxc) version frequently?

Is this flawless possible to switch from the one to the other and back, or is it something which can't easily to be done?

Thanks in advance.

Best regards,
	Klaus.
-- 
Klaus Singvogel
GnuPG-Key-ID: 1024R/5068792D  1994-06-27

[toc] | [prev] | [next] | [standalone]


#263483

FromErwan David <erwan@rail.eu.org>
Date2023-11-13 15:30 +0100
Message-ID<HzG6R-5b9X-3@gated-at.bofh.it>
In reply to#263482
Le 13/11/2023 à 15:11, Klaus Singvogel a écrit :
> Erwan David wrote:
>> Note that you may have less dependencies with kpcli (a cli client for
>> keepass password files)
> I always was peering at kpcli.
>
> Do you have any experience switching between the CLI (kpcli) and the GUI (keepassxc) version frequently?
>
> Is this flawless possible to switch from the one to the other and back, or is it something which can't easily to be done?
>
> Thanks in advance.
>
> Best regards,
> 	Klaus.

That was a bad idea : lokking closer I see that kpcli does not support 
the latest keepass file format (v4)

-- 
Erwan David

[toc] | [prev] | [next] | [standalone]


#263496

FromMax Nikulin <manikulin@gmail.com>
Date2023-11-13 18:10 +0100
Message-ID<HzIBH-5cOE-1@gated-at.bofh.it>
In reply to#263483
On 13/11/2023 21:29, Erwan David wrote:
> That was a bad idea : lokking closer I see that kpcli does not support 
> the latest keepass file format (v4)

Trying "apt search" I have noticed some python tool "secrets" having 
python3-pykeepass in its dependency. Does anybody use it (or at least 
have tried it)? My specific interest is recovery scenario when usually 
used (and tuned) system is not available, so minimal dependencies matter 
when a Live image is booted.

It seems KeePassXC implements secret.service D-Bus API. Can 
gnome-keyring/kwallet/KeePassXC be used instead of "native" application 
for particular desktop or actually there are various lock-ins (e.g. 
anything other than gnome-keyring is call to trouble in Gnome)?

[toc] | [prev] | [next] | [standalone]


#263429

FromJoe <joe@jretrading.com>
Date2023-11-12 18:30 +0100
Message-ID<Hzmrv-4VUk-3@gated-at.bofh.it>
In reply to#263423
On Sun, 12 Nov 2023 22:07:33 +0700
Max Nikulin <manikulin@gmail.com> wrote:

> On 10/11/2023 01:48, Michael Kjörling wrote:
> > KeepassXC if you want a primarily GUI solution which also happens to
> > be open source. (There's also a command-line version keepassxc-cli
> > which can either be driven from the command line or used
> > interactively in a terminal session.)  
> 
> Having system booted from Debian Live image (assume some disaster),
> how many packaged have to be installed to get access to passwords
> stored by KeePassXC?
> 
As always, it depends on what you already have. Much of that enormous
list may already be there.

From a fairly large sid installation:

Install: libtspi1:amd64 (0.3.15-0.3, automatic), libzxcvbn0:amd64
(2.5+dfsg-1, automatic), keepassxc:amd64 (2.7.4+dfsg.1-2),
libbotan-2-19:amd64 (2.19.3+dfsg-1, automatic)

An alternative strategy is to keep the database backed up on a USB
device or uSD card etc. I do that anyway for laptop use, not
storing the database on the laptop itself. You could also install
PortableApps (and KeepassXC Portable) on the card, and have the
passwords available on any Windows machine without leaving anything
behind on that machine. Whatever you do, it's always a good idea to
copy the database to somewhere fairly safe whenever you update it.

Or there are other rescue-type distributions which have keepasxc, such
as Parted Magic. Knoppix has keepassx, but I'm not sure about file
compatibility with that fork.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#263431

FromHans <hans.ullrich@loop.de>
Date2023-11-12 19:00 +0100
Message-ID<HzmUy-4W4l-1@gated-at.bofh.it>
In reply to#263429
Am Sonntag, 12. November 2023, 18:23:20 CET schrieb Joe:
What about kwallet? Should run on other window managers than plasma5 as well.

Hans

[toc] | [prev] | [next] | [standalone]


#263305

From"der.hans" <deb-user@LuftHans.com>
Date2023-11-09 21:10 +0100
Message-ID<HyjvH-4iLt-1@gated-at.bofh.it>
In reply to#263289

[Multipart message — attachments visible in raw view] — view raw

Am 09. Nov, 2023 schwätzte paulf@quillandmouse.com so:

moin moin Paul,

> Folks:
>
> I have a bash/GPG based password manager I wrote years ago, but I'd
> like to use something more "accepted/popular". The problem I have with
> the other password managers I've looked at is that you can store a very
> limited amount of information for each "account". For example, for
> one of my logins, I may have to store the answers to three security
> questions, an account login, email address, the actual password, and
> maybe the mobile phone number associated with the login. I also object
> to my password information being stored online by some password manager
> vendor.
>
> Does anyone know of a password manager which will store a variety of
> user-defined information for each login, and not store that information
> on the internet (and which is free as in beer)?

In KeePass-based projects like KeePassXC you can store the usual title,
username, password, URL and notes in the main screen/tab.

In the advanced tab you can store further key/value pairs. This works well
for storing random strings for security questions and answers.

The responses can been starred out like password entries are. There isn't
a keyboard shortcut to copy them, but there is a menu drop down, so you
can get the values without having to open the entry.

There's also an option to add attachments.

I say KeePass-based because KeePass was the original project. KeePassX was
a port of the windows KeePass project to Linux and other platforms.
KeePassXC is a more active, community developed fork of KeePassX. I've
been using the latter two for many, many years.

Thanks to the developers and packagers for the projects!

All 3 are using KeePass file formats. There are other packages that
understand the formats. F-Droid has several if you're wanting some of your
passwords on your phone. Because it's a common format you have some choice
into which tool you want to use. There are also some command line options.

The biggest lack I've seen for host-your-own is that there isn't a secure
way to do partial sync between password files. For instance, I don't need
all my passwords on my phone, so would like to have phone.kdbx with just
the few I need, but be able to sync with my everything.kdbx file if
changes are made in one or the other.

KeePassXC FAQ on file formats.

https://keepassxc.org/docs/#faq-format

ciao,

der.hans

> Paul

-- 
#  https://www.SpiralArray.com   https://www.PhxLinux.org
# "You want weapons? We're in a library! Books! The best weapons in the
# world! This room's the greatest arsenal we could have - arm yourselves!"
# -- the Doctor: Doctor Who, Tooth and Claw, 2006

[toc] | [prev] | [next] | [standalone]


#263317

From"der.hans" <deb-user@LuftHans.com>
Date2023-11-10 03:30 +0100
Message-ID<Hyprr-4m9r-13@gated-at.bofh.it>
In reply to#263305

[Multipart message — attachments visible in raw view] — view raw

Am 09. Nov, 2023 schwätzte der.hans so:

moin moin,

below I said KeePassXC doesn't have a way of syncing passwords with
another password database file. Tonight I was looking at KeePassXC SSH
integration documentation and I see there is a sharing option, KeeShare.

"KeeShare allows you to share a subset of your credentials with others and
vice versa."

In my example of my phone the others are myself and I :).

https://keepassxc.org/docs/KeePassXC_UserGuide#_database_sharing_with_keeshare

I will experiment and see if I can get sharing to work the way I want it
to.

ciao,

der.hans

> Am 09. Nov, 2023 schwätzte paulf@quillandmouse.com so:
>
> moin moin Paul,
>
>> Folks:
>> 
>> I have a bash/GPG based password manager I wrote years ago, but I'd
>> like to use something more "accepted/popular". The problem I have with
>> the other password managers I've looked at is that you can store a very
>> limited amount of information for each "account". For example, for
>> one of my logins, I may have to store the answers to three security
>> questions, an account login, email address, the actual password, and
>> maybe the mobile phone number associated with the login. I also object
>> to my password information being stored online by some password manager
>> vendor.
>> 
>> Does anyone know of a password manager which will store a variety of
>> user-defined information for each login, and not store that information
>> on the internet (and which is free as in beer)?
>
> In KeePass-based projects like KeePassXC you can store the usual title,
> username, password, URL and notes in the main screen/tab.
>
> In the advanced tab you can store further key/value pairs. This works well
> for storing random strings for security questions and answers.
>
> The responses can been starred out like password entries are. There isn't
> a keyboard shortcut to copy them, but there is a menu drop down, so you
> can get the values without having to open the entry.
>
> There's also an option to add attachments.
>
> I say KeePass-based because KeePass was the original project. KeePassX was
> a port of the windows KeePass project to Linux and other platforms.
> KeePassXC is a more active, community developed fork of KeePassX. I've
> been using the latter two for many, many years.
>
> Thanks to the developers and packagers for the projects!
>
> All 3 are using KeePass file formats. There are other packages that
> understand the formats. F-Droid has several if you're wanting some of your
> passwords on your phone. Because it's a common format you have some choice
> into which tool you want to use. There are also some command line options.
>
> The biggest lack I've seen for host-your-own is that there isn't a secure
> way to do partial sync between password files. For instance, I don't need
> all my passwords on my phone, so would like to have phone.kdbx with just
> the few I need, but be able to sync with my everything.kdbx file if
> changes are made in one or the other.
>
> KeePassXC FAQ on file formats.
>
> https://keepassxc.org/docs/#faq-format
>
> ciao,
>
> der.hans
>
>> Paul
>
>

-- 
#  https://www.SpiralArray.com   https://www.PhxLinux.org
#  It's up to the reader to make the book interesting.
#  An author has only the opportunity to make it uninteresting. - der.hans

[toc] | [prev] | [next] | [standalone]


#263311

FromJohn Darrah <xyllyx@gmail.com>
Date2023-11-10 01:40 +0100
Message-ID<HynIZ-4l6G-1@gated-at.bofh.it>
In reply to#263289
On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote:
> Folks:
> 
> Does anyone know of a password manager which will store a variety of
> user-defined information for each login, and not store that
> information
> on the internet (and which is free as in beer)?
> 

Take a look at 'secrets' which is a Gnome native app. It uses a
database and key file compatible with Password Safe.

-- john

[toc] | [prev] | [next] | [standalone]


#263312

Fromconover@panix.com (John Conover)
Date2023-11-10 02:10 +0100
Message-ID<Hyoc1-4lvQ-1@gated-at.bofh.it>
In reply to#263311
John Darrah writes:
> On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote:
> > Folks:
> > 
> > Does anyone know of a password manager which will store a variety of
> > user-defined information for each login, and not store that
> > information
> > on the internet (and which is free as in beer)?
> > 
> 
> Take a look at 'secrets' which is a Gnome native app. It uses a
> database and key file compatible with Password Safe.
>

Pass works well, too. http://www.passwordstore.org/.
Uses gpg encryption.

    John

-- 

John Conover, conover@panix.com, http://www.johncon.com/

[toc] | [prev] | [next] | [standalone]


#263328

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2023-11-10 11:30 +0100
Message-ID<HywVY-4qW0-11@gated-at.bofh.it>
In reply to#263312

[Multipart message — attachments visible in raw view] — view raw

On Fri, Nov 10, 2023 at 3:11 AM John Conover <conover@panix.com> wrote:

> John Darrah writes:
> > On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote:
> > > Folks:
> > >
> > > Does anyone know of a password manager which will store a variety of
> > > user-defined information for each login, and not store that
> > > information
> > > on the internet (and which is free as in beer)?
> > >
> >
> > Take a look at 'secrets' which is a Gnome native app. It uses a
> > database and key file compatible with Password Safe.
>

I have been looking for a password manager that was as simple and easy to
use as password manager and Secrets is definitely it. Thanks so much for
pointing out this program.



>
> Pass works well, too. http://www.passwordstore.org/.
> Uses gpg encryption.
>
>     John
>
> --
>
> John Conover, conover@panix.com, http://www.johncon.com/
>
>

-- 
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄⠀⠀

[toc] | [prev] | [next] | [standalone]


#263329

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2023-11-10 11:40 +0100
Message-ID<Hyx5D-4qZm-21@gated-at.bofh.it>
In reply to#263328

[Multipart message — attachments visible in raw view] — view raw

On Fri, Nov 10, 2023 at 5:25 AM Timothy M Butterworth <
timothy.m.butterworth@gmail.com> wrote:

>
>
> On Fri, Nov 10, 2023 at 3:11 AM John Conover <conover@panix.com> wrote:
>
>> John Darrah writes:
>> > On Thu, 2023-11-09 at 16:03 -0800, paulf@quillandmouse.com wrote:
>> > > Folks:
>> > >
>> > > Does anyone know of a password manager which will store a variety of
>> > > user-defined information for each login, and not store that
>> > > information
>> > > on the internet (and which is free as in beer)?
>> > >
>> >
>> > Take a look at 'secrets' which is a Gnome native app. It uses a
>> > database and key file compatible with Password Safe.
>>
>
> I have been looking for a password manager that was as simple and easy to
> use as password manager and Secrets is definitely it. Thanks so much for
> pointing out this program.
>

I spoke to soon Password Safe is now available for Linux.
https://sourceforge.net/projects/passwordsafe/files/Linux/1.18.0/ I used to
run Password Safe in Wine. It is so good to see that it has been ported to
linux.


>
>>
>> Pass works well, too. http://www.passwordstore.org/.
>> Uses gpg encryption.
>>
>>     John
>>
>> --
>>
>> John Conover, conover@panix.com, http://www.johncon.com/
>>
>>
>
> --
> ⢀⣴⠾⠻⢶⣦⠀
> ⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
> ⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
> ⠈⠳⣄⠀⠀
>


-- 
⢀⣴⠾⠻⢶⣦⠀
⣾⠁⢠⠒⠀⣿⡁ Debian - The universal operating system
⢿⡄⠘⠷⠚⠋⠀ https://www.debian.org/
⠈⠳⣄⠀⠀

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web