Okay, Fediverse, help a nerd out.

Ditching #Bitwarden. Genuine thanks to that crew, but y'all take care, I'm out.

Consensus seems to be @keepassxc #KeePassXC and sync over @syncthing #Syncthing (the latter already a core workflow for all my devices).

What is the consensus on the mobile app? Must be #freesoftware #libresoftware for Android #GrapheneOS @GrapheneOS preferably on @fdroidorg #fdroid

Gracias amigos

@jameshowell I've been using #keepass2android for a couple of years now (syncing done via #Nextcloud) . Happy with it, but it doesn't seem to be on @fdroidorg.

I think #keepassdx is, though. I remember having a look at it in the past, but not sure why I didn't switch. Maybe because it didn't work with shared key databases, which is a hard requirement for me as my partner and I have several shared accounts.

@keepassxc @syncthing @GrapheneOS

@jameshowell Also see KeePassChi, especially the reasons for that recent fork. It might not be fully stable yet, but the original sloppifying might be a concern in a longer run.
KeePassDX Passkey Vault | F-Droid - Free and Open Source Android App Repository

Manage Passkey / Password in a local and open-source vault

@bignose @jameshowell @fdroidorg @keepassxc @syncthing @GrapheneOS thanks for the tip; I just tried the KeepassXC android app and while it mostly seems functional, syncing seems to be completely broken. Whenever I try to sync changes on mobile it throws an exception. However the sloppification of the main app worries me too; I'm also considering switching to Vaultwarden on the back end and keeping all the Bitwarden front-end apps.

@joat @bignose @jameshowell @fdroidorg @keepassxc @syncthing @GrapheneOS it should work but we can't be sure official BW clients stay compatible with vaultwarden.

I'm testing graphene + keepassxc + syncthing. I faced filesystem permission issues with keepassdx... so I'm trying keepass2android and that seems better. Both mobile apps are recommended by keepassxc (see FAQ)

@yax @bignose @jameshowell @fdroidorg @keepassxc @syncthing @GrapheneOS yeah it was keepass2android I tried, also on GrapheneOS... sync threw an exception every time
@joat @bignose @jameshowell @fdroidorg @keepassxc @syncthing @GrapheneOS 😐 not yet encountered... it was my best bet
@jameshowell Sincere question: why are you dumping BW?
(just curious if there are things I should be aware of, as a user)
Bitwarden scrubs 'Always free' and 'Inclusion' values from its website as longtime execs step down

What is going on with the beloved open-source password manager?

Fast Company
@jameshowell okay, that doesn’t sound great. Probably time to back up some data and start looking at options.
@jameshowell not sure about the consensus but use this exact configuration for my passwords. I use #KeePassDX on my Android phone.

@jameshowell I used Aegis for 2FA on Android (fork) for a while. It was good but then I realized that my passwords/tokens were much safer in KeepassXC on my Qubes laptop.

I don't see it as a big imposition to require my laptop to access sensitive accounts.

If something needs minute-by-minute contact from me on mobile its probably part of a dark pattern anyway.

@jameshowell @keepassxc @[email protected] @GrapheneOS @fdroidorg Everyone's already mentioned KeePassDX, but don't miss keepass-mode, which uses keepassxc-cli under the hood
@jameshowell @keepassxc @syncthing @GrapheneOS @fdroidorg I am using both Bitwarden (as it's easy with auto fill logins, not sure how to do it with keepassxc) and also have keepassxc syncing over syncthing. Syncthing could sometime miss syncing, didn't happen to keepassxc, but I've logsec syncing over syncthing and I'm not getting a few journals synced between devices. So probably need to work out how to resolve sync issues before migrating?