DEV Community

Discussion on: What would it take to feel safe using a password manager with a DB file in the open?

Collapse
 
tomowens profile image
Thomas J Owens

Some of this is also good advice.

Personally, I don't see a need to use a key file over a passphrase or delete the local copy from my phone or computer. All of my devices are encrypted when off and would be off when they are not in my possession, so any bad actors would need to not only make a copy of the device storage, but also either know that password/pin or be able to break the encryption. There are a number of places where I simply wouldn't bring my normal phone or computer anyway, and the issue becomes a non-issue.

Regardless of if you are using a passphrase or not, your KeePass database should always be securely encrypted. I find it much easier to protect a secure password or passphrase than a key file. You start running into problems with a small number of keys that, if compromised, affect many things or a large number of key files that need to be managed.