from Hacker News

KeePassXC 2.6.0 Released

by varjolintu on 7/8/20, 11:22 AM with 174 comments

  • by preek on 7/8/20, 1:03 PM

    I've been using KeePassXC ever since switching from OSX to Debian Linux. On OSX, I used 1Password and have been an advocate for years.

    However, after being forced to upgrade (and pay again) multiple times due to API changes, and the integration stopped working with various browsers, I wasn't a happy customer anymore. KeePassXC works just as good, if not better. I'm using it on Debian, with browser extensions and on iOS (and sometimes even on my old Macbook Pro on OSX). Being FOSS, I'm not afraid anymore that stuff will stop working at some point, because some proprietary API is deprecated.

  • by siraben on 7/8/20, 12:40 PM

    KeePassXC + Nextcloud has surplanted any other password manager for me for the last two years. The OTP integration is great as well.
  • by room505 on 7/8/20, 1:24 PM

    I've been using the original KeePass for a long time. I'm an architect, not a coder/software developer. So my question is a bit naive on this forum, but why is KeePass 10mb installed and KeePassXC 108mb if they do the same thing? I like that KeePass has plugins that I can tailor to my needs. Does KeePassXC make the same security software changes as KeePass? I forgot one more question, can I use KeePass2Android if I switched?
  • by Paul-ish on 7/8/20, 4:10 PM

    If you like KeePassXC you should consider donating. I donate $5 a month because it's worth paying for good software.

    https://keepassxc.org/donate/

  • by rburhum on 7/8/20, 12:36 PM

    I am assuming there are ways to turn off health checks to “ Have I Been Pwned”. I never want my local password manager to do outcalls for any reason...
  • by trabant00 on 7/8/20, 1:13 PM

    Another option you should consider: https://www.passwordstore.org/

    It's just a bash script that used gpg and git. I find it the most KISS solution. Not available on phones but I don't trust my phone with my secrets anyway.

  • by the_svd_doctor on 7/8/20, 3:00 PM

    How trusted are the iOS/Android app compared to the "mainstream" desktop clients like KeepassXC ? I'm a bit wary of downloading a "random client" from the App Store. Are those audited/trusted as much ?
  • by ilitirit on 7/8/20, 12:47 PM

    Does anyone know if the browser integration is similar to/better than Lastpass or Bitwarden? Does it even have browser integration?
  • by Sander_Marechal on 7/8/20, 3:28 PM

    Word of warning: Don't use KeePassXC when your co-workers use KeePass2 using a network drive. KeePassXC doesn't support KP2's sync protocol. You'll clobber other people's changes when you save using XC. It took us a few weeks before we noticed that many passwords were missing.
  • by mlukaszek on 7/8/20, 3:49 PM

    Also a user. Works well in general, although I continue to be sad to see the arrogance during argumenting in an issue that is a valid and necessary usecase for many people using online banking. https://github.com/keepassxreboot/keepassxc/issues/725
  • by i_am_proteus on 7/8/20, 1:22 PM

    KeepassXC with the .pdb synced with git and locally-distributed .key files has been my go-to for years. I don't use browser extensions.
  • by sandreas on 7/8/20, 2:58 PM

    I'm excited to try this out. Just to mention two interesting projects:

    On MacOS I use: https://macpassapp.org/ (Open Source)

    I always wanted to try: https://www.passbolt.com/ (Self-hostable)

  • by elric on 7/8/20, 1:07 PM

    While we're on the subject of password managers ... I'm still looking for one with decent multi-user & group support, with audit trails, which is self-hosted. Bitwarden sounded promising, but I'm put off by their MS based stack and their pricing model. Any other recommendations would be greatly appreciated.
  • by mwexler on 7/8/20, 12:47 PM

    Thoughts on comparing this to bitwarden? Pros, cons?
  • by awill on 7/8/20, 5:38 PM

    Years ago I used KeePassX. It became stale, ugly, and didn't have a good Android app. KeePassX then moved to .NET, and didn't work well on Linux, so I looked around. I settled on enpass as it was a paid app without a subscription, and withyour choice of sync/backup. Enpass has excellent desktop/mobile apps with sync using your choice of cloud service. I'm very happy with it.
  • by qwerty456127 on 7/10/20, 1:05 PM

    Why do people insist on putting everything, even passwords, in folders? I find categorizing files, let alone passwords, into a strict taxonomy a particularly hard job of questionable usefulness.

    It would be much handier if we could just tag the records with a number of tags + add a description and/or comment rather than put it in a folder. I always use search rather than manual folder tree navigation anyway.

  • by eric1293 on 7/8/20, 10:09 PM

    How does Keepassxc compare to other password managers (passwordstore with gpg-agent/gnome keyring, 1password, Bitwarden, etc) in terms of protecting secrets when the vault is unlocked?

    For example, part of data may be held unencrypted in RAM that could be read by OS or other programs. Any use of TPM?

  • by virgilp on 7/8/20, 5:21 PM

    Wait, so there's Keepass, KeepassX and KeepassXC? I understand the X is cross-platform (initially was linux-only) whereas presumably Keepass is win-only; but what's the "community fork" for? Why not improve KeepassX? And why don't KeepassX and Keepass merge now?
  • by gigababe on 7/9/20, 4:13 PM

    I used to use KeePass and KeePassXC for years at a time, but the amount of time I have saved not having to mess with syncing issues more than makes up for the ~$30 a year for 1password that always works across windows, linux, ios and mac.
  • by amedvednikov on 7/8/20, 2:27 PM

    Is it better than KeePassX?
  • by muska3 on 7/8/20, 3:58 PM

    I'm curious why would anyone on Windows use KeePassXC instead of KeePass. Are KeePass plugins compatible?
  • by phonebucket on 7/8/20, 3:26 PM

    Has anyone migrated from Lastpass to KeePassXC? Was it difficult?
  • by donmb on 7/8/20, 3:02 PM

    I like the simplicity/design of KeePassX more than XC
  • by runxel on 7/8/20, 1:05 PM

    Been on the "regular" KeePass all along.

    Should I switch?