61

Brain-based management is getting too exhausting, and isn't even fully possible with a larger quantity of online accounts.

top 50 comments
sorted by: hot top new old
[-] BurgerBaron@quokk.au 1 points 5 minutes ago* (last edited 4 minutes ago)

Self host. Keepass, NAS with a sync app across devices. Occasional manual backup. Probably overkill.

[-] huquad@lemmy.ml 1 points 3 hours ago* (last edited 3 hours ago)

I ask AI to make me a random password for "x" service. Whenever I need to remember it, I just ask again \s

Vaultwarden

[-] user224@lemmy.sdf.org 1 points 26 minutes ago

I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again

I've already seen someone do that, a certain family member. At first I found it funny when they asked an LLM about their WiFi password, which was some gibberish. But it worked. There's no way something like that would be default across entire product line.
Indeed, when I asked, I got "I gave it screenshots of everything because I didn't know what to type where".

[-] Hossenfeffer@feddit.uk 1 points 3 hours ago* (last edited 3 hours ago)

I use Password123$ everywhere.

[-] edgyspazkid@lemmy.wtf 2 points 5 hours ago

I use KeePass database for all my passwords and other database for recovery passwords (like from 2FA codes etc). I have it synced in my Nextcloud and ProtonDrive (In case my Nextcloud would fuck up).

[-] SorteKanin@feddit.dk 2 points 6 hours ago

KeePass database in cloud storage, synced to my phone.

[-] prole@lemmy.blahaj.zone 1 points 6 hours ago

Have you considered trying pass phrases? Weirdly, they can sometimes be easier to remember depending on where you take it from.

[-] Lushed_Lungfish@lemmy.ca 1 points 6 hours ago

I write down a password hint on a physical piece of paper.

Since the primary threat vector is remote access and not physical access, I'd argue that is fine.

Additionally the password hint has to pass through several thought chains in order to provide the actual password.

I do wish sites would up front tell you what the password requirements were when you logged in though.

[-] Michal@programming.dev 2 points 8 hours ago
[-] bertlewirth@lemmy.world 5 points 13 hours ago* (last edited 13 hours ago)

A bit of a tangent but these are the right people to ask... What do you think when a site or app says that your password is too long?

[-] helpImTrappedOnline@lemmy.world 1 points 7 hours ago

I'm glad they told me and didn't just truncate it forcing me to reset everytime.

[-] ExtraJudgement@lemmy.world 4 points 18 hours ago* (last edited 18 hours ago)

With gnupg, git, and a hardware security token. Also known as "pass".

[-] Son_of_Macha@lemmy.cafe 13 points 1 day ago* (last edited 1 day ago)
[-] orenj@leminal.space 4 points 21 hours ago

Mostly i get by by not telling others how or where I keep my passwords

[-] vandsjov@feddit.dk 2 points 10 hours ago

Do you add 1 and then ! or ! And then 1 to secure your passwords?

[-] Ordoviz@lemmy.ml 12 points 1 day ago

pass: the standard unix password manager for tech-savvy people. It's dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.

[-] anon_8675309@lemmy.world 3 points 1 day ago

Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.

[-] TryingToBeGood@reddthat.com 3 points 1 day ago

Piece of paper.

[-] eggpl4nt@lemmy.world 2 points 22 hours ago

My dumbass reading through these comments: "keep ass... ehehehehe"

[-] PeteWheeler@lemmy.world 4 points 1 day ago

Proton Pass for me since I use their VPN.

Vaultwarden for selfhosting.

[-] Toasticus@piefed.social 3 points 1 day ago

I don't particularly trust any password manager. If it can be breached, possibly, has been or a chance to be breached, then I don't trust it. I have a document of passwords locked behind a VeraCrypt container hosted locally. I trust nothing in the cloud or some remote program.

[-] Bane_Killgrind@lemmy.dbzer0.com 2 points 22 hours ago

That's fair, but you've lost the ability to log access attempts for individual services, timeout sessions etc.

There are completely selfhost options for this

[-] crandall@lemmy.today 66 points 2 days ago
[-] BlueOysterCultist@lemmy.zip 23 points 2 days ago

To further this, if you actually move over to any password manager please regenerate all of your duplicate passwords with something 20+ characters. It’s almost pointless to have a PW Manager if you’re using the same weak password everywhere.

Make a new strong password for your master password too; I’d recommend a phrase of four moderately long words like “BattleshipMonitorPaintingPrinter” and perhaps a little postit note doodle drawing to remember it until it’s hammered home.

Alternatively, writing down the master password somewhere secure, like in a safe, would also be good if you have to pass on important accounts to descendants.

[-] Mercer@lemmy.zip 1 points 9 hours ago

Or a USB with a Gpg encrypted text file locked with a slightly easier password.

load more comments (3 replies)
[-] DarkSirrush@piefed.ca 16 points 1 day ago

Keepassxc/keepassdx, synced with syncthings/basicsync.

Using a headscale/tailscale setup so things stay synced even when i am not home.

[-] hexagonwin@lemmy.today 21 points 2 days ago
[-] Schlemmy@lemmy.ml 11 points 1 day ago

BitWarden and a self hosted VaultWarden

load more comments (2 replies)
[-] brewery@feddit.uk 17 points 2 days ago

Vaultwarden - self hosted bitwarden server that any bitwarden clients can connect to.

[-] poccalyps@sh.itjust.works 15 points 2 days ago
load more comments (1 replies)

A few years ago I set up KeepassXC using Syncthing temporarily to sync the database across all my devices. I fully expected to have to move to Nextcloud for database file management.

The KeepassXC / Syncthing combination has worked so well that I have no reason to change it. The databases are seamlessly synced across all devices (including my phone) without requiring any attention from me. Database issues due to multiple device use are almost nonexistent.

One note: For me Syncthing works much better with multiple devices using a star topology. When I initially set up a mesh configuration I had regular file sync issues. With a star topology they are very rare.

load more comments (4 replies)
[-] zxqwas@lemmy.world 6 points 1 day ago

Remember the password to my email. Create account on site. Log in and remain logged in. When eventually logged out click forgot password. Log into email and click reset link.

[-] vandsjov@feddit.dk 1 points 10 hours ago

That was what I did 20 years ago

[-] trailee@sh.itjust.works 8 points 2 days ago

1Password family account with spouse, kids, and my parents. Vault management, ease of sharing, and remote management for my parents is nice, along with multiplatform for everything important, and the price feels quite reasonable at $1/user/month. No major security incidents ever, and I was pleased by their core service design whitepaper that I read many years ago. But as they’ve become increasingly corporate over the past several years I’ve felt like they care less and less about individual users, and the CEO’s recent pledge to Omarchy really pissed me off. So it’s been a great service for me but I don’t recommend it for new users unless they like nazis. I pay for a year at a time so I haven’t scrambled to migrate my family to a new solution quickly, but it sounds like Vaultwarden is most likely the way to go next.

Seconding Bitwarden, have been with it since my previous one (Lastpass? I forget, it was red) moved most of the good functionality behind a paywall many years ago. 11/10 I usually pay for the subscription, I like their product and want them to have a little walkin' around money. But currently on the free tier which is perfectly fine (2 devices when I used pro for 3, but I hardly use my laptop.

[-] vandsjov@feddit.dk 1 points 10 hours ago

My journey as well. Paid for LastPass (bought 10 years for $20) and changed when they went too much shit.

[-] chunes@lemmy.world 3 points 1 day ago

nice try hax0r

[-] Bugamn@lemmy.zip 6 points 2 days ago
[-] Fleppensteijn@sh.itjust.works 5 points 2 days ago

Firefox remembers my passwords. For other things, text documents stored in a Veracrypt container

load more comments
view more: next ›
this post was submitted on 01 Oct 2026
61 points (96.9% liked)

Ask Lemmy

41668 readers
2101 users here now

A Fediverse community for open-ended, thought provoking questions


Rules: (interactive)


1) Be nice and; have funDoxxing, trolling, sealioning, racism, toxicity and dog-whistling are not welcomed in AskLemmy. Remember what your mother said: if you can't say something nice, don't say anything at all. In addition, the site-wide Lemmy.world terms of service also apply here. Please familiarize yourself with them


2) All posts must end with a '?'This is sort of like Jeopardy. Please phrase all post titles in the form of a proper question ending with ?


3) No spamPlease do not flood the community with nonsense. Actual suspected spammers will be banned on site. No astroturfing.


4) NSFW is okay, within reasonJust remember to tag posts with either a content warning or a [NSFW] tag. Overtly sexual posts are not allowed, please direct them to either !asklemmyafterdark@lemmy.world or !asklemmynsfw@lemmynsfw.com. NSFW comments should be restricted to posts tagged [NSFW].


5) This is not a support community.
It is not a place for 'how do I?', type questions. If you have any questions regarding the site itself or would like to report a community, please direct them to Lemmy.world Support or email info@lemmy.world. For other questions check our partnered communities list, or use the search function.


6) No US Politics.
Please don't post about current US Politics. If you need to do this, try !politicaldiscussion@lemmy.world or !uspolitics@lemmy.world


7) No Hit-and-Run questions.
Please don't delete your post for no apparent reason. If you plan on deleting a question later, say so in the post, or if you feel that you have a good reason to remove it, message a mod beforehand. It's not fair to the ones who took their time to answer, and it's not in the spirit of the community.


8) No Bots.
Posts or comments from bots, LLM's, AIs, Neural Networks, Transformers, or Marvin the Paranoid Android are not welcome in AskLemmy. Real humans only please.


Reminder: The terms of service apply here too.

Partnered Communities:

Tech Support

No Stupid Questions

You Should Know

Reddit

Jokes

Ask Ouija


Logo design credit goes to: tubbadu


founded 3 years ago
MODERATORS