Brain-based management is getting too exhausting, and isn’t even fully possible with a larger quantity of online accounts.
I ask AI to make me a random password for “x” service. Whenever I need to remember it, I just ask again \s
Vaultwarden
I use Password123$ everywhere.
I use KeePass database for all my passwords and other database for recovery passwords (like from 2FA codes etc). I have it synced in my Nextcloud and ProtonDrive (In case my Nextcloud would fuck up).
KeePass database in cloud storage, synced to my phone.
I write down a password hint on a physical piece of paper.
Since the primary threat vector is remote access and not physical access, I’d argue that is fine.
Additionally the password hint has to pass through several thought chains in order to provide the actual password.
I do wish sites would up front tell you what the password requirements were when you logged in though.
Nice try
keepassxc
A bit of a tangent but these are the right people to ask… What do you think when a site or app says that your password is too long?
I’m glad they told me and didn’t just truncate it forcing me to reset everytime.
With gnupg, git, and a hardware security token. Also known as “pass”.
Bitwarden
Mostly i get by by not telling others how or where I keep my passwords
Do you add 1 and then ! or ! And then 1 to secure your passwords?
pass: the standard unix password manager for tech-savvy people. It’s dead simple: just a directory of GPG-encrypted files that you can sync across devices using git or other means. It has a CLI interface, an Android app, and a Firefox extension.
Same one on every site. But don’t worry it’s 10 characters instead of 8. And I tossed a bang at the end to throw off attackers.
My dumbass reading through these comments: “keep ass… ehehehehe”
Piece of paper.









