We'd like to remind Forumites to please avoid political debate on the Forum... Read More »
📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
Taking passwords abroad safely?
Comments
-
Thanks for all replies.
my son's partner only yesterday told me that she use's Keepass, I'll be having a look at it.0 -
Thanks for all replies.
Speaking to a friend yesterday who is tech savvy and he recommended Keepass too.
Thanks for the link to Keepass for Android phones, hopefully look at it today.0 -
A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.
It also worth considering that if you have them stored on a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.
For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option.1 -
Have the new 2.54/2.55 releases addressed the memory exploit you may have been referring to ?Or are there other security problems?Please tell us more PHK.1
-
PHK said:A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.
It also worth considering that if you have them stored on a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.
For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option.
Any evidence for claiming that "Cloud based... is usually a better option"? If you use a trusted and audited app to store passwords locally, use a safe master password* (and preferably also a keyfile as a second factor) this is safer than storing passwords on somebody else's cloud server. Bitwarden is, as I wrote, probably the best option here, because they open-source their code but even there the user has no control over their security arrangements, bug handling etc. If you store stuff yourself, you have more of a responsibility but you also can make sure it's as safe as possible. 100% security doesn't exist.
* That's a topic in its own right.
2 -
Micron said:I've been using KeePass2 for many years on my PC and more recently Keepass2Android Password Safe on an Android phone.
It's free, open source, no need to open an account, works locally without internet access and works well for me.
You can also run a portable version of KeePass2 from a USB stick, it's said to be secure as it doesn't store any sensitive information on to the running system.
0 -
PHK said:A couple of points to consider. There are some known flaws in Keepass that mean a determined hacker could recover passwords from local storage.
It also worth considering that if you have them stored on a physical medium like a hard drive or USB then you need to secure that both physically and electronically. You should also have a copy off-site as it were in case of hardware failure.
For personal home use, Cloud based that's encrypted ( so that neither the security company or cloud provider can access it ) is usually a better option.
1
Confirm your email address to Create Threads and Reply

Categories
- All Categories
- 351.2K Banking & Borrowing
- 253.2K Reduce Debt & Boost Income
- 453.7K Spending & Discounts
- 244.2K Work, Benefits & Business
- 599.3K Mortgages, Homes & Bills
- 177.1K Life & Family
- 257.7K Travel & Transport
- 1.5M Hobbies & Leisure
- 16.2K Discuss & Feedback
- 37.6K Read-Only Boards