My Switch to KeePass

— by

I have been a satisfied user of online password managers for many years. It is a brilliant invention that enables people to set a unique and hard-to-guess password for every account they have. Recently, I have started using KeePass-based password managers, where I manage my own password database.

1Password

1Password was my first introduction to password managers. It’s a great service that allowed me to remember complex passwords and synchronise them across my phone and computers. I used 1Password happily for many years.

Unfortunately, the world changed. Geopolitical relations became more strained, and the relationship between the European Union and the United States also became less certain. As a result, I began to think more about my dependence on online services and infrastructure outside Europe. I started to feel increasingly uncomfortable about my reliance on 1Password

Although 1Password is provided by the Canadian company AgileBits Inc., it uses Amazon Web Services (AWS) for its infrastructure.

Users can choose to store their encrypted password data within the EU. However, even with a European account, the 1Password app still connects to infrastructure outside the EU, including 1Password.com and AWS servers in the United States. For me, this meant I remained dependent on US infrastructure – something I specifically wanted to avoid as much as possible.

I therefore started looking for a European alternative. As I also wanted to host my email in Europe, I ended up choosing Proton Pass.

Proton Pass

A year and a half ago, I switched to Proton as my email provider and immediately switched to Proton Pass as my password manager as well. Proton AG is a Swiss-based company with a good reputation for security and privacy. Although the company is not based in the European Union, Switzerland has strict data protection and privacy regulations.

I must say that I’ve enjoyed using Proton Pass, but even now I’ve started to have my doubts. My access to all my passwords depended on a single service provider. What would happen if, for whatever reason, I could no longer log in to Proton, or if the service went down completely? I wanted to be in control myself and manage the password database on my own hardware. I also wanted to switch to open-source software as much as possible. This led me to use KeePass-based password managers.

KeePass

The main difference between my previous password managers and KeePass-based ones is that my passwords are now stored in an encrypted database file that I own. I can decide for myself where that file is stored and how I synchronise it across my devices. This makes it easy for me to switch storage providers or KeePass programmes.

The KeePass programme itself was not an option for me. It is only compatible with Windows and feels a bit outdated. It didn’t meet all my requirements. In the end, I settled on using KeePassXC and KeePassium. Both programmes are based on KeePass and can use the same KeePass database.

KeePassXC

I use KeePassXC on macOS and Linux. The browser extension allows me to fill in passwords with a single click. Unfortunately, KeePassXC does not have an app for iOS or Android.

KeePassium

At the moment, I’m still using an iPhone. If it gives up the ghost, I plan to switch to a phone running the /e/OS operating system. Until then, I’m using KeePassium on my iPhone, which also allows me to fill in my login details with a single click.

KeePass database

KeePassium and KeePassXC use the same database. The database is stored on my own home server and is synchronised across my devices. Within my own network, this synchronisation works even if the internet connection goes down. I’ve also set up automatic backups of the database.

In conclusion

My switch to KeePass does not mean that I think 1Password and Proton Pass are poor password managers. On the contrary, I have enjoyed using both services and, for many people, they are excellent choices.

For me, however, it has become important that my access to my passwords isn’t dependent on a single company or on a working internet connection. With KeePass, I manage my passwords myself; I can decide for myself which software to use and where to store my database.

On the other hand, this has brought with it an added responsibility. I have to ensure that my database is properly synchronised and that I have a sound backup strategy. I am personally responsible if I slip up somewhere. This is less hassle-free than using a service like 1Password or Proton Pass, but for me, the extra control more than makes up for that responsibility.

Ultimately, my switch to KeePass was therefore not so much a search for a better password manager, but for greater control over my own data.

Sander
Join the conversation on W Social

You can also reply from other ATProto services, such as Bluesky.

Comments

11 responses to “My Switch to KeePass”

  1. Denys Vuika avatar

    Interesting read, thanks. I'm at my Proton stage and am already thinking over full control as well.

    1. Sander Muller avatar

      Thanks! Since you’re a developer, it would be a piece of cake for you.

      1. Denys Vuika avatar

        Yep, the only thing that scares me off yet is protecting the file itself. Each time a rent a virtual server for something, it gets scanned/probed automatically on power on. Meaning the file may get leaked pretty fast unless I do a lot of work for access, ports, IP ranges, etc. still lazy to do that

        1. Sander Muller avatar

          I use a home server for this. But yes, security is most of the hassle.

  2. Tomi Tervo avatar

    Thanks for the tip! What do you see as its advantages in comparison to other password managers?

    1. Sander Muller avatar

      The main advantages are full control over the database, not being dependent on companies or working internet, being able to choose your own KeePass-capable software.

  3. Prata Catalin avatar

    Nice read and also I adhere to your concerns. I think all have some drawbacks we need to take into account, even the local ones since we still depend on some tools that unlock the DB to look it up for us and that can be exploited as well even though it is way more transparent. 🙂

    1. Sander Muller avatar

      True. There’s no perfect solution.

  4. Germo Veltmaat 🇳🇱🇪🇺🌍 avatar

    Ik gebruik ook voor ieder account een apart wachtwoord, maar ik maak ze zelf met een formule.
    De formule blijft principieel hetzelfde, alleen het wachtwoord veranderd bij ieder account.

    Nergens opgeslagen, kan nergens lekken

    1. Sander Muller avatar

      Dat is een interessante methode. Lekker puur.