LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 03-27-2022, 10:24 PM   #1
random_guy
Member
 
Registered: Sep 2006
Location: TX,USA
Distribution: Slackware-15.0
Posts: 30

Rep: Reputation: 15
Recommendations for a Password Manager on Slackware


I'm looking for recommendations for a stand-alone password manager for Slackware.

The most common I've seen around the web are:
- KeepassXC
- Buttercup
- Bitwarden
- LastPass

Keepass and Lastpass are the only two I've heard about over the years but never used to date.

Any recommendations/comments would be greatly appreciated.

TIA
 
Old 03-27-2022, 11:48 PM   #2
truepatriot76
Member
 
Registered: Apr 2014
Location: California, USA
Distribution: slackware64-current
Posts: 231

Rep: Reputation: 195Reputation: 195
I've used KeePass and KeePassXC - currently using the latter (on current). Both do the job. The one thing that I like about KeePassXC, and why I settled on it - it doesn't require mono.
 
2 members found this post helpful.
Old 03-28-2022, 12:29 AM   #3
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,098

Rep: Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175
password-store (homepage).
 
8 members found this post helpful.
Old 03-28-2022, 12:36 AM   #4
ozanbaba
Member
 
Registered: May 2003
Location: İzmir
Distribution: Slackware64 15.0 Multilib
Posts: 778

Rep: Reputation: 135Reputation: 135
I personally use Bitwarden [1]. It is good and has apps for major systems you can get. However, it is a client - server system and that's definitely not standalone.


[1] Actually I use unofficial rust implementation called vaultgarden. I run it on my server and access it from my machines. It is small and can use sqlite as DB hence it is quite well fitting for small users like me.
https://github.com/dani-garcia/vaultwarden
 
1 members found this post helpful.
Old 03-28-2022, 01:54 AM   #5
pan64
LQ Addict
 
Registered: Mar 2012
Location: Hungary
Distribution: debian/ubuntu/suse ...
Posts: 21,852

Rep: Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310Reputation: 7310
You can easily try them. Or do you want to use what I like? (keepassxc)
 
Old 03-28-2022, 02:57 AM   #6
uiopqwerty
Member
 
Registered: May 2020
Distribution: Slackware64 15.0
Posts: 31

Rep: Reputation: Disabled
I can't recommend password-store highly enough. Along with having a sane structure, having excellent autocompletion, and being effectively future-proof (password-store is basically a porcelain for gpg and git), it's also got a dmenu interface, a Firefox plugin, an Emacs package, third-party Android and iOS apps, and a host of community-maintained plugins - OTP, tomb, various tools to migrate passwords from other databases, the Firefox plugin as mentioned ... It leverages git for version control, so you can go back in time to see e.g. old removed passwords you didn't realise you still needed, and you can distribute your repository easily using the same tools you would with git. If you want to maintain a password manager on both your computer and phone without passing KeePass files around, this is a great way of doing it. I've had my password-store on my laptop, home server, and iPhone for about 3 years now.

I think the only thing that can really be said against it is that the database might leak metadata about your online profile, since the database is really just a directory structure under $HOME/.password-store with encrypted files named whatever you like - it effectively lists all your online accounts if you use it in that way, and anyone with a copy of these files can see this in plain text. There are plenty of ways to work around this though, including encrypting your HDD at rest and locking your computer when you're away from it, or by using pass-tomb to encrypt the entire database and only unlock it for time-limited intervals while you're using it. Also, although in principle it would work great for team-based arrangements since it's so easy to distribute, since it's really just a git repository you can't realistically revoke access for anyone, so I would never honestly suggest it for that. It's awesome for personal use though.

Edit: also I use KeePassXC at work just because I’ve been using it for 5+ years and it works very well, but as I mentioned it doesn’t lend itself to my own workflow with computer and mobile device

Last edited by uiopqwerty; 03-28-2022 at 05:33 AM.
 
5 members found this post helpful.
Old 03-28-2022, 03:06 AM   #7
Richard Cranium
Senior Member
 
Registered: Apr 2009
Location: McKinney, Texas
Distribution: Slackware64 15.0
Posts: 3,858

Rep: Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225Reputation: 2225
Quote:
Originally Posted by uiopqwerty View Post
I can't recommend password-store highly enough.
I'm not quoting everything that you had written, but what you had written was enough for me to take a look. Thanks!
 
Old 03-28-2022, 03:11 AM   #8
ponce
LQ Guru
 
Registered: Aug 2004
Location: Pisa, Italy
Distribution: Slackware
Posts: 7,098

Rep: Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175Reputation: 4175
Quote:
Originally Posted by uiopqwerty View Post
I think the only thing that can really be said against it is that the database might leak metadata about your online profile, since the database is really just a directory structure under $HOME/.password-store with encrypted files named whatever you like - it effectively lists all your online accounts if you use it in that way, and anyone with a copy of these files can see this in plain text. There are plenty of ways to work around this though
here I insert my online accounts (or others too) as multi-line (-m), with the name of the online service as the store ("Facebook", for example), the account name as the first line and the password as the second line: this way very little will leak if you publish the git repository somewhere public...

Last edited by ponce; 03-28-2022 at 03:12 AM.
 
Old 03-28-2022, 03:23 AM   #9
knet
Member
 
Registered: Jun 2021
Distribution: Slackware Linux, LMDE5, Porteus
Posts: 166

Rep: Reputation: 13
KeepassXC. Thanks for the password-store suggestions.
 
1 members found this post helpful.
Old 03-28-2022, 03:54 AM   #10
kjhambrick
Senior Member
 
Registered: Jul 2005
Location: Round Rock, TX
Distribution: Slackware64 15.0 + Multilib
Posts: 2,159

Rep: Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512Reputation: 1512
Thanks all.

I've installed Alien Bob's keepassxc-2.6.6-x86_64-1alien.txz mostly for the keepass-cli

Looks like there is more to look at

-- kjh
 
Old 03-28-2022, 04:31 AM   #11
Thom1b
Member
 
Registered: Mar 2010
Location: France
Distribution: Slackware
Posts: 484

Rep: Reputation: 337Reputation: 337Reputation: 337Reputation: 337
I use KeePassXC, keepassxc-browser plugin for firefox, KeePass DX on Android.
 
1 members found this post helpful.
Old 03-28-2022, 05:29 AM   #12
uiopqwerty
Member
 
Registered: May 2020
Distribution: Slackware64 15.0
Posts: 31

Rep: Reputation: Disabled
Quote:
Originally Posted by ponce View Post
here I insert my online accounts (or others too) as multi-line (-m), with the name of the online service as the store ("Facebook", for example), the account name as the first line and the password as the second line: this way very little will leak if you publish the git repository somewhere public...
I do something similar, and for me this arrangement is fine - honestly I treat my personal laptop as pure convenience, so if someone has my laptop and I’m logged in then my gpg-agent already has my password saved … otherwise they’re not going to be getting their hands on my keys or password, and I’m not too concerned about leaked metadata because it’s kept offline (some people use Gitlab or GitHub to store their password store, which with a strong key is safe enough I suppose but still feels insane to me even if you have a private repository - I just have it on any home server).
 
Old 03-28-2022, 07:40 AM   #13
montagdude
Senior Member
 
Registered: Apr 2016
Distribution: Slackware
Posts: 2,011

Rep: Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619Reputation: 1619
Quote:
Originally Posted by ponce View Post
This is what I use too. Only problem is that it relies on xclip to copy password to the clipboard, which doesn't work on Wayland. Anyone know if there is a solution to that?

Last edited by montagdude; 03-28-2022 at 07:42 AM.
 
1 members found this post helpful.
Old 03-28-2022, 11:05 AM   #14
0XBF
Member
 
Registered: Nov 2018
Distribution: Slackware
Posts: 766

Rep: Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867
Quote:
Originally Posted by ponce View Post
here I insert my online accounts (or others too) as multi-line (-m), with the name of the online service as the store ("Facebook", for example), the account name as the first line and the password as the second line: this way very little will leak if you publish the git repository somewhere public...
Yep, I also use password-store with multiline entries. I like to keep my security questions/answers in multiline entries for logins that require it also. When pulling passwords in something like firefox, only the password line gets auto-filled after unlocking the password-store entry. Still need to open a terminal to unlock it that way for viewing the other lines stored in the entry.

The 'generate' command is nice to produce secure passwords also.
 
Old 03-28-2022, 11:13 AM   #15
0XBF
Member
 
Registered: Nov 2018
Distribution: Slackware
Posts: 766

Rep: Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867Reputation: 867
Quote:
Originally Posted by montagdude View Post
This is what I use too. Only problem is that it relies on xclip to copy password to the clipboard, which doesn't work on Wayland. Anyone know if there is a solution to that?
It's supposed to use 'wl-clipboard' on wayland. I'm not sure if that's included in Slackware though.

You can see that the password-store.sh script checks if wayland is running and defaults to commands from wl-clipboard, if its found on the system. This commit shows the relevant code: https://git.zx2c4.com/password-store...edf5938219a9b7

Edit: Doesn't appear to be in Slackware. I guess it could be added as an optional dependency to the slackbuilds.org build of password-store.

Last edited by 0XBF; 03-28-2022 at 11:14 AM.
 
2 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
should I prefer a password manager or a manually kept password list? newbiesforever Linux - General 60 01-09-2023 04:28 PM
LXer: KeePassXC Password Manager Gets Better Xfce Support, Improved Password Generator LXer Syndicated Linux News 0 08-21-2020 03:21 AM
[SOLVED] Password Manager recommendations hawkeyesc72 Linux - Software 6 07-17-2016 04:50 PM
Lubuntu: How can I change the password for the password manager? DJOtaku Ubuntu 11 03-22-2011 03:38 AM
[SOLVED] password manager "password dragon" garyg007 Debian 2 10-15-2009 04:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 07:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration