LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-05-2012, 02:56 AM   #1
siddartha
LQ Newbie
 
Registered: Aug 2012
Posts: 27

Rep: Reputation: Disabled
KeepassX vs FPM2 vs Password Safe


Lately I discovered that I depent on a password manager. But that's easier said than done.

On Windows I go for KeePass Classic. On Linux, I'm lost. I see theese three are currently developed. I see there are many others with no activity in the past few years. And that's bad for security.

Right now I went for simplicity's sake with KeePassX. Because it handles KeePass 1.x files. But there is no trace of documentation. I am using it only because I rely on the security of the container made by KeePass. But I read the new version 1.24 adds new security features:

Header data in KDB files is now authenticated (to prevent silent data removal attacks; thanks to P. Gasti and K. B. Rasmussen).
The content part of a KDB file now contains 32 random bytes (generated each time the file is saved, by a cryptographically secure pseudo-random number generator using system entropy) to prevent content guessing attacks using the content hash.

I have no idea when these will follow into KeePassX given the lack of information. Also, the old format means no Unicode support and less flexibility in the fields of a recording.

KeePass 2.x can run with the help of Mono. But I've seen far smaller projects than Mono excusing itself: we're not paid to do that, or the classical OS anwer: code it yourself. Given these are all my passwords, and it's only one basket I'm less willing to add another unreliable variable to this mix.

What do you know about the others? What would you advise?
 
Old 09-05-2012, 07:46 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,323
Blog Entries: 28

Rep: Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141Reputation: 6141
I also use KeepassX from keepassx.org and am quite happy with it. In particular, I like the portability of the databases among different platforms. I learned about it from a company which uses a mix of Linux and Windows computers and recommends it to their staff for precisely that reason.

The help file in the application is quite well done and there's a FAQ at the website: http://www.keepassx.org/faq/

I have no experience with either of the others.
 
Old 09-06-2012, 05:06 PM   #3
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
I use KeePassX cross-platform. Works quite well. I've used PasswordSafe on Windows for years and it also works well.

Not familiar with FPM2, though looking at teh web page I'd have to question their logic in moving from Blowfish to AES.
 
Old 09-12-2012, 10:09 PM   #4
tquang
Member
 
Registered: Jul 2010
Posts: 44

Rep: Reputation: 0
KeePass is best choice, it's support multiple platform: MacOS, Linux, Windows
Also KeePass can management entry very smart
 
Old 09-14-2012, 02:18 PM   #5
NyteOwl
Member
 
Registered: Aug 2008
Location: Nova Scotia, Canada
Distribution: Slackware, OpenBSD, others periodically
Posts: 512

Rep: Reputation: 139Reputation: 139
I prefer KeePassX to KeePass as it doesn't require Mono(.NET) to function.

Last edited by NyteOwl; 09-14-2012 at 02:21 PM. Reason: fixed typo
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: KeePassX: Keeping Your Passwords Safe LXer Syndicated Linux News 0 07-16-2012 09:50 PM
Running Password Safe under Wine wootletootle Slackware 3 05-21-2012 01:03 AM
keepassx-git or keepassx-svn? Mr. Alex Arch 2 01-26-2012 09:06 AM
Suse Safe Mode Password? Mike Brown Linux - Newbie 1 07-29-2006 05:59 PM
password safe cambie Linux - Software 2 10-06-2004 08:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration