I 'mirror' my Bitwarden login entries in a KeepassXC database, so I have an offline carbon copy incase Bitwarden's servers are wiped or not accessible, or for whatever reason, I can't access my Bitwarden vault. I would suggest everyone do the same. The only pain point is remembering to make a carbon copy of each entry you add to Bitwarden, in the KeepassXC database.
I also make copies of my KeepassXC database in several cloud storage services incase of a house eating event which destroys my hard-drives (unlikely but still a possibility). I really don't like the idea of being locked out of my digital life.
Terence Eden has a good article about this potential scenario;
For those wondering why I use Bitwarden as-well as KeepassXC:
1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).
2.) Browser extension. I like to be able to login easily to sites using their extension.
3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.
4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
What exactly is Bitwarden getting you if you're doing this copy process? I have only used Keepass and haven't read why Bitwarden would be superior for some scenarios over what I am already doing.
1. Out-of-the-box integrated sync with a dedicated default host: keepass has 8 different sync plugins, all with different levels of maintenance & UX, each for separate sync backends, all requiring separate 3rd party backend account setup
2. Consistent cross-device features & UX: Keepass has 3 browser plugins with varying levels of browser support (not sure if any have mobile support?)
On top of the above, Bitwarden is open source and allows self-hosted sync
I didn't know KeePass(XC) had sync plugins, let alone eight, since I just sync the file myself as part of the same infrastructure that syncs everything else under my homedir.
1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).
2.) Browser extension. I like to be able to login easily to sites using their extension.
3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.
4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
Thanks! I will probably just stick with Keepass but this was a nice write-up to consider.
1) I have my database replicated several places already. Cloud storage, mobile, FTP server, etc.
2) I don't use a browser extension on desktop, but I know there is one. On mobile the accessibility permissions allow it to suggest login information both in third party apps and in the browser. I've found it works fairly well. If you aren't able to open your database quickly it might not be as convenient.
3) This sounds the same as what I was considering for (1). Historical backups would be important for recovering from possible corruption, but I have not run into this yet for Keepass.
4) Understood. Bitwarden doesn't support keyfiles?
I have been close to splitting my Keepass DB up into several, but haven't pulled the trigger on that effort.
4. is ... interesting :-) You made access to KeePass more obscure for "security reasons." But fear not: "With Bitwarden I just open the app." Okay cool.
I manually export my Bitwarden vault to KeePass from time to time as well. The benefit of still using Bitwarden for me is that I can access and update my main vault from any linked device (desktop PC, laptop, phone) without needing to synchronize data between devices. It's far from an ideal way, but you can have a little more confidence that you will have access to your data (although it might be a slightly outdated snapshot of the data) even if you can't access the Bitwarden server. That is exactly what happened today, and I was still able to retrieve my password from the local copy.
My understanding that BW have superior auto-fill features and wide support for different OS. Keepass don't have auto-fill for browsers, Keepass have to rely on third-party to provide the auto fill features and various apps for all variety of OS.
I'm a Keepass user since 2006 and never had a problem with them. My database is saved in OneDrive and always keep local copy in my system. If OneDrive is down, my local copy is always there for me.
KeePassXC does have auto-fill for browsers. And also Auto-Type which allows you to enter your credentials to _any_ application possible. All this works without any third party plugins.
I'm working on a product to solve this problem (i.e. where do you backup your seed, high value keys / secrets, 2FA codes). The approach is social recovery (threshold cryptography) for the root seed, and a digital agent component (i.e. DWN - distributed web noted) SaaS or self hosted. The digital agent is used for encrypted backups and to communicate with other parties (contacts). Does this sound interesting to you?
A - the service doesn't encrypt your data (or has access to your private keys), and
B - that you have access to the second factor which is used to reset your password (e.g. a backup email address).
Secure password managers do not have access to your private key (i.e. the encryption key), as such if you lose the seed there is no recovery.
In the case with other services (i.e. they can reset your password) there is a chance you could lose access to your backup email or phone number used for resetting.
Edit: some services do allow reset by proving your "identity" (e.g. bank), in which case you have to go through customer service and provide requested information. (I put "identity" in quotes, because nefarious actors can sometimes prove this too).
> incase of a house eating event which destroys my hard-drives
I worry about this as well. Yes, a friend's house is an option, but not everybody has friends or family in the same city, and if they're further away, updating copies is a pain.
On the contrary, it's very similar - you share a keyfile to your friends in a different city and then you encrypt your password safe with that extra keyfile that hasn't touched Dropbox. This solves the threat model issue while also relieving you of the pain of syncing the password safe (in this case syncing is even more convenient than your same-city-physical-visit model)
I've been considering this, but to be honest, I don't trust myself to keep up with updates and other aspects of opsec for something that I only use for myself and would have to do consistently and reliably at nights and weekends.
That would probably be balanced out with my self-hosted instance hopefully being less of a target, but the downside there is that I might not even know that my database was compromised and it's down to my passphrase strength now.
With Bitwarden's SaaS, I'd hope that I would hear about such a compromise before too long, giving me time to rotate passwords while GPUs gnaw at my (and everybody else's) passphrase.
Additionally, there are certain opportunities for account access recovery that are much harder or impossible when self-hosting, e.g. things like a cool-down period and a warning e-mail before allowing a less-secure 2FA method.
1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely!).
2.) Browser extension. I like to be able to login easily to sites using their extension.
3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.
4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.
1. You can store your encrypted KeepassXC kdbx file anywhere you wish.
2. KeepassXC has a browser extension.
3. Refer to point 1.
4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase.
The only reason Bitwarden "just opens" from the last session is because of the very features you have disabled in KeepassXC (remember last used kdbx).
Launching KeepassXC for me has exactly the same steps as Bitwarden has. Open program, put correct passphrase (or insecure PIN on Bitwarden for the lazy folks) and the password database unlocks.
> 4. Using a keyfile is optional and IMO don't see how it adds any security benefits to the master passphrase.
I believe it fulfills the same 2FA role as does the Secret Key in 1Password <https://support.1password.com/secret-key-security/>: combining something you know (passphrase) with something you have (keyfile/Secret Key), thus making a potential Dropbox breach (or wherever you store your .kdbx) not subject to offline dictionary attacks -- err, unless you also stored your keyfile in Dropbox in which case, yes, it wouldn't add any security benefits
A strong passphrase should be good enough to deter dictionary attacks, even if your kdbx file is leaked.
And even then the ciphers used to encrypt the kdbx file are highly configurable, you can future-proof the key derivation function as much as your hardware can reasonably afford to unlock the file.
Besides using a keyfile for daily use is impractical. For correct usage, you'd have to keep it in a separate drive from your kdbx (in a USB flash perhaps), as you very well mentioned. But then in the menu you'd have to go to the directory the keyfile is stored in every single time you want to unlock your database if am not mistaken about how the feature works on KeepassXC.
I also make copies of my KeepassXC database in several cloud storage services incase of a house eating event which destroys my hard-drives (unlikely but still a possibility). I really don't like the idea of being locked out of my digital life.
Terence Eden has a good article about this potential scenario;
https://shkspr.mobi/blog/2022/06/ive-locked-myself-out-of-my...
For those wondering why I use Bitwarden as-well as KeepassXC:
1.) Redundancy. Can't get at my KeepassXC?, then I try Bitwarden. Can't get at my Bitwarden? Then I try KeepassXC. Can't get access to both? Then I'm screwed (but this is unlikely).
2.) Browser extension. I like to be able to login easily to sites using their extension.
3.) LOCKSS (Lots of copies keeps stuff safe). Having a cloud-based mirror of my login entries stored in Bitwarden is marginally better than solely relying on KeepassXC.
4.) Logging into KeepassXC is sometimes more complicated than logging into Bitwarden. I have a long seven word passphrase for KeepassXC, and use a keyfile which I have to 'hunt down' in the filesystem each time I go to access KeepassXC (I have disabled the ability to store the last used database & keyfile for security reasons). With Bitwarden I just open the app and if it's unlocked, I get quick access to everything.