i think i will switch from my selfhosted #vaultwarden instance to #keepassxc + #keepassdx with syncthing. keepassxc feels more organized and its clients are proper foss
@hi On #Linux I use #KeePassXC, but not sure if a bsd port exist. On #Android there is #KeePassDX. It does involve using local databases and does not use the cloud.

Since the #BitWarden apps (desktop, #Android) and extension (#Firefox) keep getting slower and slower, not to mention, ugly as hell, I'm testing #KeePassXC and #KeePassDX again.

I used #KeePass some years ago, but the "convenience" of syncing passwords across multiple devices made me switch to BW. Now, thanks to #Syncthing I can have the best of both worlds: syncing and fast apps on my devices.

Mir gehen langsam die (umsetzbaren) Ideen aus.

Es laufen hier #QubesOS, #GrapheneOS, #OpenWRT, #Proxmox, #Yunohost

Der E-Book-Reader ist von #PocketBook.

Apps kommen per #Accrescent und #Obtainium.

Die wenigen Smart-Home-Devices haben #Tasmota.

Gebootet wird per #Coreboot.

Eingeloggt wird per HW Fido2 Provider, #KeePassDX, passage und (mangels Alternative) #Yubikey.

#DiDay #DID #DigitalIndependenceDay #DUT #DUTgemacht #UnplugTrump

hw-fido2-provider

hw-fido2-provider

Codeberg.org

Apparently, to use passkeys under GrapheneOS with KeepassDX, if you used an old version of kp before, you have to go to the system settings, disable the password/passkey service, and set it to keepassdx again.

It didn't work for me before, now it does.

(No google services required)

#grapheneos #keepassdx #passkeys

Le he preguntado a la IA algo tan sencillo que aunque me ahorro ver entre tanto docs perfectamente lo pude haber descubierto por mi cuenta xD

Llevo rato quejandome de #KeepassDX por no encontrar una función para que una base de datos se abra automáticamente, pues con una ya voy sobrada, tan solo era tocar el simbolo de la estrella junto a una base y listo 

Viendo que #KeepassDX agregó una función de que si por cosas de la vida dejas el teléfono encendido con una base de datos abierta cualquier persona no pueda ver tu información privada (contraseñas, OTP, etc) porque pide pasar por una segunda autenticación para ver esos datos mas sensibles

Yo esto sinceramente lo veo inútil por dos razones, el ladron o ladrona no sabra siquiera que estara tocando, y segundo yo para nada me despego de este teléfono xDD

Drei beliebte cloudbasierte Passwort-Manager wurden von Sicherheitsforschern als anfällig eingestuft: eprint.iacr.org/2026/058

Auf Android könntest du stattdessen eine lokale Lösung wie #KeePassDX in Kombination mit #Syncthing verwenden, wenn du mehrere Geräte hast. Dadurch entfällt das Vertrauen in Dritte.

3 popular cloud-based password managers have been shown to be vulnerable by security researchers: https://eprint.iacr.org/2026/058

On Android, consider using a local solution like #keepassdx with #syncthing if you have multiple devices: No third party trust is necessary.

Zero Knowledge (About) Encryption: A Comparative Security Analysis of Three Cloud-based Password Managers

Zero Knowledge Encryption is a term widely used by vendors of cloud-based password managers. Although it has no strict technical meaning, the term conveys the idea that the server, who stores encrypted password vaults on behalf of users, is unable to learn anything about the contents of those vaults. The security claims made by vendors imply that this should hold even if the server is fully malicious. This threat model is justified in practice by the high sensitivity of vault data, which makes password manager servers an attractive target for breaches (as evidenced by a history of attacks). We examine the extent to which security against a fully malicious server holds true for three leading vendors who make the Zero Knowledge Encryption claim: Bitwarden, LastPass and Dashlane. Collectively, they have more than 60 million users and 23% market share. We present 12 distinct attacks against Bitwarden, 7 against LastPass and 6 against Dashlane. The attacks range in severity, from integrity violations of targeted user vaults to the complete compromise of all the vaults associated with an organisation. The majority of the attacks allow recovery of passwords. We have disclosed our findings to the vendors and remediation is underway. Our attacks showcase the importance of considering the malicious server threat model for cloud-based password managers. Despite vendors’ attempts to achieve security in this setting, we uncover several common design anti-patterns and cryptographic misconceptions that resulted in vulnerabilities. We discuss possible mitigations and also reflect more broadly on what can be learned from our analysis by developers of end-to-end encrypted systems.

IACR Cryptology ePrint Archive

KeePassXC - Passwörter sicher und synchronisiert abspeichern

Mit diesem Passwortmanager hast du alle deine Passwörter im Griff und über die Browsererweiterung kannst du Passwörter im Webbrowser ganz einfach automatisch ausfüllen.

#KeePassDX #KeePassXC #Android #did #Linux

https://gnulinux.ch/keepassxc-passwoerter-sicher-und-synchronisiert-abspeichern

KeePassXC - Passwörter sicher und synchronisiert abspeichern

Mit diesem Passwortmanager hast du alle deine Passwörter im Griff und über die Browsererweiterung kannst du Passwörter im Webbrowser ganz einfach automatisch ausfüllen.

GNU/Linux.ch