I dont agree with many things apple does at all, and I also think their password manager has flaws like revealing usernames without authentification.

It is pretty handy though, to have a file where the entries are stored unencrypted, and if the password manager detects an entry it prompts to decrypt exactly that field, maybe with a fingerprint.

KeepassDX needs to run in the background and be completely unlocked to even detect apps or password fields.

Do you know any existing app that can do this?

  • Devjavu@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    28
    arrow-down
    2
    ·
    11 months ago

    Bitwarden if you want it in the cloud, Keepass if you want it on the device. I’d recommend PrivacyGuides.org’s recommendations this time. They are rather careful as to what they recommend, still doesn’t mean they always get it right.

      • FoxBJK@midwest.social
        link
        fedilink
        English
        arrow-up
        6
        ·
        11 months ago

        You can also run Bitwarden proper locally but unless you really know how to run and maintain a web server I wouldn’t recommend this.

        • qaz@lemmy.world
          link
          fedilink
          arrow-up
          3
          ·
          edit-2
          11 months ago

          The official docker image uses a lot more resources than the vaultwarden container, but it allows significantly more than 100 users. If it’s just for yourself and your family I suggest just going with Vaultwarden.

            • qaz@lemmy.world
              link
              fedilink
              arrow-up
              1
              ·
              11 months ago

              You don’t. I meant to say that only large organizations need the official Bitwarden docker setup, but I did not communicate that clearly enough.

          • Rootiest@lemm.ee
            cake
            link
            fedilink
            English
            arrow-up
            5
            arrow-down
            1
            ·
            11 months ago

            I think what they meant is that one option uses network connectivity while the other functions entirely offline

          • Devjavu@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            2
            ·
            11 months ago

            Which would make it hardly accessible outside of your home. Still not locally saved as well. And imho if he is not sure which password manager he should choose, he should maybe not self host just yet.

            • Ekpu@lemmy.world
              link
              fedilink
              arrow-up
              4
              arrow-down
              1
              ·
              11 months ago

              Bitwarden keeps a local encrypted copy of the database and only connects to the server for synchronisation.

                • Oisteink@feddit.nl
                  link
                  fedilink
                  arrow-up
                  2
                  arrow-down
                  1
                  ·
                  11 months ago

                  Maybe because it seems you claim self-hosting bit warden is cloud only and that self-hosted is not accessible outside the house?
                  Note: I do not recommending self-hosting bitwarden

                  • Vexz@kbin.social
                    link
                    fedilink
                    arrow-up
                    2
                    ·
                    11 months ago

                    Note: I do not recommending self-hosting bitwarden

                    Why not? I have my own instance running on my NAS and I love to have it self-hosted because this way I keep the passwords where I know nobody else can get them.

      • Pantherina@feddit.deOP
        link
        fedilink
        arrow-up
        1
        ·
        11 months ago

        Use that but its not about that topic. Its about storing unencrypted metadata (or usinh android Keystore for example) and having autofill work always even if the database is locked, and its quickly unlocked just for that entry