Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Will never understand why people use managed password management services when things like the KeePass KDBX format exist.


Multiple devices? Central management? I use KeePass so I don't know, but I assume there are valid reasons


You can use KeePassium for mobile, store your kdbx file on ftp or google drive. Not difficult. Takes only one time setup then all good for life.


If you wish to understand, all you have to do is ask someone outside the hn-tech-bubble.


"someone outside the hn-tech-bubble" saves their passwords in excel sheet without protection.


That's not far enough outside the bubble. People just reuse passwords, or add a suffix to a base password, or forget their passwords and email reset each login.


Basically the entire password manager space is the result of "security fatigue". Telling everyone that every single unimportant website they log into requires a unique high security password makes people use bad solutions that make their security worse, like storing all their passwords in a cloud-based single point of failure.


when you have an employee leave your company can you reroll or disable all their work account passwords in keepass? (no; this is good for the user and not useful for the org, but that’s the use case.)


Yes. Because their passwords should be linked only to their own work accounts and not be shared passwords. Even if you used lastpass at work, nothing stops an employee from storing it again somewhere else.


If I were going to steal passwords for my company, I'd steal them before I quit / got fired or did something illegal.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: