|
-
Password Management Software
Just thought I'd share my morning with you. I spent a few hours researching and trying out different open-source password management software. All of them use the same strategy of having a password-protected database file, encrypted with a key derived from a master password. I only looked at open-source tools because something just feels odd about putting all my passwords into a closed-source tool. Here's what I found:
KeePass Password Safe
http://keepass.info/
This is the one I'll use. It's really nice software. Nothing annoying about it in the first 5 minutes. (All the other three just gave the impression of being crap. ) No install required. In addition to password-protecting the file, this will also let you export a key to a file for a sort of "2-factor authentication." So if someone gets ahold of the master password they still need the key to decrypt the database.
KeePassX - Based off of KeePass, but supports more OS's than windows. I didn't try it.
Bruce Schneier's Password Safe
http://www.schneier.com/passsafe.html
A lot of people like this one because it was made by Bruce Schneier. He's a cryptography expert, so there might be more attention to detail in it. I didn't like it because the installer wasn't tested in a multi-user environment. (i.e. it doesn't put an icon in the All Users profile) Not as many features as KeePass either.
Password Gorilla
http://www.fpx.de/fp/Software/Gorilla/
I really wanted to use this one, because it has the coolest name and logo. But unfortunately, it has the least features of them all. Nothing annoying about it though. No install required. Based off of Bruce Schneier's Password Safe, and supports more OS's than windows. (Kind of a pattern here)
Oubliette
http://sourceforge.net/projects/oubliette/
Not sure if this is being developed anymore. In any event, the install was fine -- it put the icons in All Users like it's supposed to. But it doesn't run well without Admin privileges, because it likes to write to the registry and config files while it's running normally. Didn't like it.
In conclusion, I'd recommend KeePass (or KeePassX if you need portability) over anything else. Nothing else even comes close in terms of features. The only other one I'd consider is Bruce Schneier's, only because the password database might be safer if someone else gets ahold of it. But I'll trust KeePass just because I think it seems more popular, so there will be more eyes looking at the source code. It's overall more professionally done than any of the other ones, too.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|