What do you use for syncing your password manager between your Android phone and your PC? Apparently Nextcloud doesn’t support two-way syncing on Android for some reason, and Syncthing-Fork is still untrustworthy since the disastrous handover. The AI generated profile picture of researchxxl doesn’t exactly inspire confidence either, neither does his GitHub bio:

Hi! My name is Jonas and I like to use my coding skills from games and modding to continue work on the Syncthing for Android wrapper.

Everything about this person screams vibe coder.

Bitwarden is an alternative, but I don’t like how non-standard it is. It’s cumbersome to manage and backup, meanwhile the KeePass format is just a file that I can backup wherever and however I want and there are many frontends to choose from.

Have you solved this?

  • GlenRambo@jlai.lu
    link
    fedilink
    English
    arrow-up
    1
    ·
    17 hours ago

    Do you store TOTP in a seperate KeePass?

    For me swappog between two Keepass DBs is annoying. I can’t find anything that will sync my 2FAs.

    • fizzle@quokk.au
      link
      fedilink
      English
      arrow-up
      3
      ·
      16 hours ago

      I don’t. Kinda seems silly to me.

      To access a keepass file you already need 2 factors: the master password and access to the file.

      • GlenRambo@jlai.lu
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        Its not really 2 factors if it’s stored in the same DB though.

        I came from Bitwarden where the community recommendation was to not store passwords and 2FA together in the cloud. If a beach orccurs and you lose both then there wasn’t a point in having the 2FA.

        Less of a risk with a local solution but still not sure.

        • fizzle@quokk.au
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 hours ago

          Yes, it is two factor, it’s just that there is no additional factors required to get the TOTP.

          If you don’t use a password manager then you just remember your passwords. In this case the second factor is having access to a device that has your TOTP generator.

          If you use keepass then you remember the password for your password db, and to access your passwords or TOTP you need access to a device with your keepass db.

        • Tibi@discuss.tchncs.de
          link
          fedilink
          English
          arrow-up
          1
          ·
          6 hours ago

          If u have 2fa in the same database u can login on devices you don’t trust. E.g. a coworkers computer/public computer in library.

            • Tibi@discuss.tchncs.de
              link
              fedilink
              English
              arrow-up
              1
              ·
              6 hours ago

              Well yes, but no. If you only operate your password store on devices you trust, then even typing in your password on a device with a keylogger active, won’t compromise your account since you have the 2nd factor (e.g. the TOTPs)