Dev/Password Manager
From Whonix
< Dev
Password Manager Comparison Table[edit]
The following table compares the features and status of three password managers that were suggested to be included in Whonix ™. Data was acquired in March, 2014.
TODO: add keepassxc
KeePass | KeePassX | Figaro's Password Manager 2 | |
---|---|---|---|
Homepage | http://keepass.info [archive] | https://www.keepassx.org/ [archive] | http://als.regnet.cz/fpm2/ [archive] |
Debian package | http://packages.qa.debian.org/keepass2 [archive] | http://packages.qa.debian.org/keepassx [archive] | http://packages.qa.debian.org/fpm2 [archive] |
Latest version | 2.25 [1] | 2.0 Alpha 5 [2] | 0.79 [3] |
Debian version (stable / testing) | 2.19 / 2.25 [4] | 0.4.3 [5] | 0.79 [6] |
Used in other security-focused distributions | No [7] | Tails [8] | Liberte Linux [9] |
Libraries | Mono 2.6 [10] | Qt 4.3 [11] | GTK2 [12] |
Popularity contest statistics (rounded) | 1750 [13] | 4300 [14] | 250 [15] |
Download archive size (rounded) | 7400 kB [16] | 1150 kB [17] | 150 kB [18] |
Additional disk space needed (rounded) | 22100 kB [19] | 3150 kB [20] | 550 kB [21] |
Size installed (rounded) | 2150 k [22] | 3100 k [23] | 500 k [24] |
Block ciphers | AES [25] | AES or Twofish [26] | AES [27] |
Key size | 256 bits [28] | 256 bits [29] | 256 bits [30] |
Hashing | SHA-256 [31] | SHA-256 [32] | SHA-256 [33] |
Key file support | Yes [34] | Yes [35] | Yes [36] |
Password generator | Yes [37] | Yes [38] | Yes [39] |
Various | 0.4.3 is no longer maintained [40] | No longer in Debian stretch. |
Discussion[edit]
These are update notes on the password manager choices covered as of 2016:
Candidates:
- Bruce Schneier's passwordsafe is a good replacement. Its only available in Stretch and Sid.
Excluded options:
- KeePass 2 use not recommended because of their hostile stance against user security. [41]
- fpm2 was removed from Debian because its upstream development is dead.[42]
Forum Topic[edit]
https://forums.whonix.org/t/done-add-password-manager-by-default/189 [archive]
Status[edit]
fpm2 is installed by default.
Footnotes[edit]
Many thanks to Tails team for their discussion on the topic of password managers. [43]
- ↑ http://keepass.info/news/news_all.html [archive]
- ↑ https://www.keepassx.org/news/ [archive]
- ↑ http://als.regnet.cz/fpm2/changelog [archive]
- ↑ http://packages.qa.debian.org/keepass2 [archive]
- ↑ http://packages.qa.debian.org/keepassx [archive]
- ↑ http://packages.qa.debian.org/fpm2 [archive]
- ↑ To the best knowledge of the author
- ↑ https://tails.boum.org/doc/encryption_and_privacy/manage_passwords/index.en.html [archive]
- ↑ http://dee.su/liberte [archive]
- ↑ http://keepass.info/help/v2/setup.html#mono [archive]
- ↑ https://www.keepassx.org/requirements/ [archive]
- ↑ http://als.regnet.cz/fpm2/ [archive]
- ↑ http://qa.debian.org/popcon.php?package=keepass2 [archive]
- ↑ http://qa.debian.org/popcon.php?package=keepassx [archive]
- ↑ http://qa.debian.org/popcon.php?package=fpm2 [archive]
- ↑ apt install keepass2
- ↑ apt install keepassx
- ↑ apt install fpm2
- ↑ apt install keepass2
- ↑ apt install keepassx
- ↑ apt install fpm2
- ↑ apt-cache show keepass2
- ↑ apt-cache show keepassx
- ↑ apt-cache show fpm2
- ↑ http://keepass.info/features.html [archive]
- ↑ https://www.keepassx.org/features/ [archive]
- ↑ http://als.regnet.cz/fpm2/about [archive]
- ↑ http://keepass.info/features.html [archive]
- ↑ https://www.keepassx.org/features/ [archive]
- ↑ http://als.regnet.cz/fpm2/about [archive]
- ↑ http://keepass.info/features.html [archive]
- ↑ https://www.keepassx.org/features/ [archive]
- ↑ http://als.regnet.cz/fpm2/about [archive]
- ↑ http://keepass.info/features.html [archive]
- ↑ https://www.keepassx.org/features/ [archive]
- ↑ http://als.regnet.cz/fpm2/about [archive]
- ↑ http://keepass.info/features.html [archive]
- ↑ https://www.keepassx.org/features/ [archive]
- ↑ http://als.regnet.cz/fpm2/about [archive]
- ↑ https://www.keepassx.org/bug-reports/ [archive]
- ↑ KeePass 2's reaction to a MITM bug report against its Update Check: 8.2.2016 @ 15:45: Received response from Dominik Reichl: The vulnerability will not be fixed. The indirect costs of switching to HTTPS (like lost advertisement revenue) make it a inviable solution. [archive]
- ↑ https://forums.whonix.org/t/add-password-manager-by-default/189/21 [archive]
- ↑ https://labs.riseup.net/code/issues/5745 [archive]
Whonix ™ is Supported by Evolution Host DDoS Protected VPS. Stay private and get your VPS with Bitcoin or Monero.
100px | |
Fosshost | About Advertisements |
Search engines: YaCy | Qwant | ecosia | MetaGer | peekier | Whonix ™ Wiki
We are looking for contributors and developers.
Priority Support | Investors | Professional Support
Whonix ™ | © ENCRYPTED SUPPORT LP | Freedom Software / Open Source (Why?)
The personal opinions of moderators or contributors to the Whonix ™ project do not represent the project as a whole.