💾 Archived View for gemini.ctrl-c.club › ~fte368 › 2023 › 2023-03-08_lastpass.gmi captured on 2023-07-22 at 17:25:39. Gemini links have been rewritten to link to archived content

View Raw

More Information

⬅️ Previous capture (2023-03-20)

-=-=-=-=-=-=-

It's worth to resist IT managers

For some time my IT manager put pressure on me to use LastPass for managing my passwords. I always thought this is a bad idea and refused.

I don't think it's a good idea to provide your passwords to any cloud provider to manage them. This opens up a whole bunch of new attack vectors and requires to trust the provider, all it's employees and sub-contractors to do things right. Added to this there is the possibility of backdoor access for three letter agencies.

That's why I always used a local password manager to manage my passwords. KeePass created "the standard" for this - at least for the database format used.

There are several apps and desktop programs using the KeePass format, so your password files can be shared between phones, tablets and computers and you even can carry them around on an USB stick.

Now that LastPass got hacked again I got proved to be right again. Never let a cloud provider manage your passwords!

The original Keepass program

KeePassXC, a good alternative implementation for the desktop

KeePassDX, a good Android app

Strongbox, an iOS app