Not sure if this is the right place to ask, but recommendations for personal and family password management?

I finally switched to Firefox on my phone, because Chrome “privacy”. And then when trying to find out how enable password storage, I accidentally set up Microsoft Authenticator as password management phone-wide. Realizing this meant cross-app password management, I finally accepted that my old approach of politely ignoring the problem and manually memorizing algorithmic passwords is no longer tenable. I honestly would prefer the anti-privacy approach where every service just uses oAuth and only one provider has my password, but we’re not there today, so time to learn the new tech.

So basically, what’s the current OSS best-practice for a one-stop-shop password management software? I know “OSS” and “big safe cloud storage provider” are kind of oxymoronic, but imho encrypted-cloud-storage is the best tradeoff between security and convenience.

And, ideally, something I could get my kids onto as well and manage some shared family-PWs as well, since I assume their password management strategies are either “reset every time” or “just use the same PW everywhere and it’s a ticking time-bomb”.

  • BuckShot@beehaw.org
    link
    fedilink
    arrow-up
    4
    ·
    edit-2
    1 year ago

    I’ve used Bitwarden for ages and it fits your needs very well. Sharing the login info will allow the rest of your family to access the passwords and TOTPs too. Bitwarden does charge for TOTP use, but Aegis is amazing to use along with Bitwarden. You could setup Aegis on your device and then, if you wanted someone else to have access, you’d just export the data so they could import it into their Aegis app.

      • BuckShot@beehaw.org
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        Good to know, I didn’t talk about self hosting as it seemed like OP was aiming for it to be through a cloud provider. Its rad Bitwarden has both options and security is top notch either way!

        • Pxtl@lemmy.caOP
          link
          fedilink
          arrow-up
          0
          ·
          edit-2
          1 year ago

          I mean I’m okay to self-host something if there’s a secure and safe and automatically backed-up solution. But realistically that’s just “3rd-party paid cloud” like DigitalOcean. I could run a service on the pi I use for files and minecraft, but I’d still have to figure out making sure the service is secure and backed-up.

          edit: I guess hoping that vaultwarden-server was a nice easy package already sitting in the Debian apt repos was too much to hope for right?

          edit2: wow lemmy really poops the bed at deleted replies with replies doesn’t it?

  • JakenVeina@lemm.ee
    link
    fedilink
    arrow-up
    3
    ·
    edit-2
    1 year ago

    KeePass.

    It’s got an app for basically all platforms, and you retain complete control over your data. Passwords go into an encrypted file, and you maintain that however you see fit.

  • Resco@lem.afiz.org
    link
    fedilink
    arrow-up
    1
    ·
    8 days ago

    Hello

    We are using for years home and business gnupg (for public/private keys) + pass + QtPass + git (for remote central storage). We are using it even as a team with shared keys.

  • dave@feddit.uk
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    1 year ago

    Despite the breach, LastPass has been pretty solid for me for over a decade. Syncs across devices, easy sharing between family members, etc. If your master pw and iteration counts are in the green, even them losing your data is relatively low risk, apart from exposing the sites you have accounts for, which is equal parts privacy & security issue. If I wasn’t so invested in LP, I would probably go elsewhere but since the horse has bolted…

    I’ve also heard good things about Bitwarden and KeePass but can’t speak to how easy they are to set up.