hhmx.de

Föderation EN Di 18.03.2025 18:24:06

New Privacy Guides article πŸ”βœ¨
by me:

If you want to keep your password manager local-only, KeePassXC is a great solution!

It's free,
Open-source,
Easy to install and use,
Doesn't require an account,
Works on Linux, macOS, and Windows,
And the team is here! πŸ‘‰ @keepassxc

Here's how to set it up with a YubiKey: privacyguides.org/articles/202

Föderation EN Di 18.03.2025 19:05:20

@Em0nM4stodon @keepassxc Been using KeePass for years, love KeePassXC.
Because you use files undr your control, I have one for passwords and a separate one for TOTP, plus autolock after 2 minutes.
Since I can't afford a Yubikey. πŸ™ƒ

Föderation EN Di 18.03.2025 20:22:31

@sintrenton This is a wonderful way to use it as well!πŸ‘

Föderation EN Di 18.03.2025 19:21:40

@Em0nM4stodon @keepassxc and don’t forget to mention, it has a good working autotype on osx. I can’t live without it in a citrix environment.

Föderation EN Di 18.03.2025 19:36:03

@Em0nM4stodon @keepassxc It's also worth mentioning that a vareity of encryption methods are built into KPXC, figured that out when my phone decrypted my database in *minutes* instead of seconds.

Turns out not every ARM processor has multiple cryptoprocessors (-_-).

Föderation EN Di 18.03.2025 20:04:09

@Em0nM4stodon @keepassxc And . I sync it using Nextcloud from Mac to OpenBSD to Windows to Kali. Brilliant piece of software.

Föderation EN Di 18.03.2025 20:20:08

@Em0nM4stodon @keepassxc The way it interacts with it's Extension is kind of a pain

Föderation EN Di 18.03.2025 20:37:17

@Em0nM4stodon @keepassxc Thanks for the guide!

"you should first make sure that you either have a secure backup for this Challenge-Response" – good you mention that! Fro me, it left the question: and how do I do that?

I still wish it would be possible to use the Yubikey as *alternative* to the passphrase, not an XOR. So a tap on the key, when available, saves me from typing the long phrase – but if the key's "gone", I still can get in with the phrase…

Föderation · Di 18.03.2025 22:02:11

@IzzyOnDroid

Your can do it by chaining: have your regular store with a very long, random and complex Password that you'd never memorise or type. Write it down on a piece of paper and put it into a steel safe as backup

And then create a second keepass file, that uses a hardware key (e.g. @nitrokey ) to unlock. Into it, put ONLY the passwort to the regular file in an entry in the folder β€žAutoOpenβ€œ that has the local filesystem path to the regular file in the β€žURLβ€œ field. (See https://keepassxc.org/docs/KeePassXC_UserGuide#_automatic_database_opening)

This way, for regular usage, you use the convenience method via hardware key and second file, which will in turn unlock your regular file automatically.

If you loose your hardware key, you take the backup sheet of paper from the steel safe.

@Em0nM4stodon @keepassxc

Föderation EN Mi 19.03.2025 00:14:40

@Friesenkiwi @keepassxc @Em0nM4stodon @nitrokey that would work, but is not what I'd call intuitive πŸ™ˆ I can use a Yubikey to log on to my machine. Or I do not put in the key, and then can enter a password. No linking between the two. That's what I'd imagine there.

Well, icing on the cake (but nice icing)…

Föderation EN Di 18.03.2025 22:58:04

@IzzyOnDroid @Em0nM4stodon @keepassxc because I wanted to be on the safe side I invested in a second key πŸ˜ƒ

Föderation EN Mi 19.03.2025 00:15:21

@old_school that's why I kept my fingers off this πŸ™ˆ @Em0nM4stodon @keepassxc