Use bitwarden, go to Settings -> account security -> unlock with pin and turn it on. If it’s already on, toggle it off then on. You will be prompted to set your pin. Dont forget your master password.
Privacy
A place to discuss privacy and freedom in the digital world.
Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.
In this community everyone is welcome to post links and discuss topics related to privacy.
Some Rules
- Posting a link to a website containing tracking isn't great, if contents of the website are behind a paywall maybe copy them into the post
- Don't promote proprietary software
- Try to keep things on topic
- If you have a question, please try searching for previous discussions, maybe it has already been answered
- Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
- Be nice :)
Related communities
much thanks to @gary_host_laptop for the logo design :)
I tried bitwarden wasn’t good cuz on mobile I had to reenter master pass over and over
Setup fingerprint unlock and enable it in Bitwarden.
I don’t understand your issue with needing to enter your master password repeatedly with Bitwarden. You can use biometrics or a pass code to sign in on mobile. It’s pretty easy to enable in the settings. You enter master password once, turn on passcode or biometrics and then that’s it.
For me, I'm extra paranoid.. Someone can forcefully unlock with biometric
You can set a pin as an alternative. Pin would be easier to brute force but no different to a password when forcefully unlocked by coersion.
i think you can alsk yubikey
Bitwarden, is still the way to go. I say this as a proton customer. I've learned to work around it's small annoyances
On mobile, I had to reenter the master password ever time I filled in a password. With a really safe, long, password, it was torture.
That is something you can configure in the settings for the mobile app. To ask for the master password every time is default behavior, but it can also be set to a PIN or biometric instead.
How would this be any different with another app?
On proton pass, I just need a pin(which isn’t enabled by default, it should be tho)
Same on Bitwarden.
It's just a setting you enable in bitwarden settings
Keepass is good, with Synching you can synchronize everything better
Whats wrong with keepass. I'v been syncing with syncthing for years now. I still don't know why frontend matters is not like you will use it every 10 minutes
If your main concern is usability, 1password works pretty well. The downsides are it's paid, closed source, and I think they removed the option to use a local vault, so it might have to be cloud.
I’ll check it out. If it’s cheap I might be willing to try it. Its not like proton is FOSS.
WDYM? Isn’t it?
Only the frontend. Not the backend, so you can’t self host without modifying both browser extension and mobile app, along with rewriting a server from scratch.
Okay fair enough, but that is at least slightly different than saying Proton isn’t FOSS, but I understand.
They have a pretty good FOSS standing and audits for software they distribute. While that doesn’t make it easy to host privately, it does make it trivial to see how data is shipped to their servers.
I don't know if Syncthing is available on iOS but this works great to sync Keepass's database between Linux and Android.
I'm in the same boat. Wanted to do Bitwarden but their sign up process is garbage. It never sends me the confirmation email. I'd love to set up a keypassxc server, but didn't know about the frontend issues.
The frontend for keypassxc isn’t necessarily horrible, it’s just proton pass feels like magic, while key pass feels just barely working. idk I remember it being kinda awkward
Ive found pencil/pen and paper and memorization work (ive been got by a bad download they cant scrape the paper) its old school but its pretty good not all eggs in one basket kind of thing
Good luck, but I still recommend encrypted offline strong passwords