Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.
Bitwarden
pass: the standard unix password manager for tech-savvy people. It’s dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.
with that you need to type the unlock password for every single read and search, right?
No, you can configure the timeout in
gpg-agent.conf. I’ve set mine to a few hours.
keepassxc
With gnupg, git, and a hardware security token. Also known as “pass”.
Mostly i get by by not telling others how or where I keep my passwords
Do you add 1 and then ! or ! And then 1 to secure your passwords?
I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again \s
Vaultwarden
I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again
I’ve already seen someone do that, a certain family member. At first I found it funny when they asked an LLM about their WiFi password, which was some gibberish. But it worked. There’s no way something like that would be default across entire product line.
Indeed, when I asked, I got “I gave it screenshots of everything because I didn’t know what to type where”.
Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.
I use KeePass database for all my passwords and other database for recovery passwords (like from 2FA codes etc). I have it synced in my Nextcloud and ProtonDrive (In case my Nextcloud would fuck up).
KeePass database in cloud storage, synced to my phone.
Proton Pass for me since I use their VPN.
Vaultwarden for selfhosting.
I write down a password hint on a physical piece of paper.
Since the primary threat vector is remote access and not physical access, I’d argue that is fine.
Additionally the password hint has to pass through several thought chains in order to provide the actual password.
I do wish sites would up front tell you what the password requirements were when you logged in though.
Nice try
A bit of a tangent but these are the right people to ask… What do you think when a site or app says that your password is too long?
I think the site stores my password in its original form, without hashing. its way too common, even at high profile services like banks, university or government systems.
I’m glad they told me and didn’t just truncate it forcing me to reset everytime.
Piece of paper.
Self host. Keepass, NAS with a sync app across devices. Occasional manual backup. Probably overkill.








