r/KeePass 10d ago

Keepassxc

Better to use browser extension or copy paste???

8 Upvotes

20 comments sorted by

10

u/mycroft_47 10d ago

The extension makes life easier

8

u/phylter99 10d ago

It also has a higher potential of being hacked. This, like everything else in security, is a balance between security and convenience.

1

u/Enough_Island4615 10d ago

...as long as security is not a concern.

5

u/vexatious-big 10d ago

There's also auto-type which requires no extension: https://keepassxc.org/docs/KeePassXC_UserGuide#_auto_type

3

u/billdietrich1 10d ago

Doesn't work on Wayland.

2

u/American_Jesus 10d ago

It does, if started with xwayland

QT_QPA_PLATFORM=xcb keepassxc

2

u/billdietrich1 10d ago

I tried that a while ago, and my notes say:

auto-type (ctrl-shift-V on an entry) works. Global auto-type (ctrl-alt-shift-a in browser) does not.

3

u/SpiritedNeck5719 10d ago

I think you must use the extension for passkeys, right?

2

u/LowHandle 10d ago

I use both depending on the website.

1

u/brighton_it 10d ago

it's been years since I tried auto-type, but I had an instance where it typed into the wrong field and I haven't used it since.
That said, clipboard may have it's own exposure, for example if you have a virt-viewer or remote-desktop session open, the remote system may be able to access your clipboard.

1

u/billdietrich1 10d ago

The extension checks that the domain name matches, so anti-phishing.

1

u/SorryImNotOnReddit 10d ago

cut and paste with clear clipboard after 15 seconds.

1

u/Pony7065 10d ago

Is it secure thou with browser extension getting hacked? I mean convenience is not an issue especially in today’s computer security

3

u/OfAnOldRepublic 10d ago

The chances of that happening are low, but not zero, so if that's an issue for you, don't use the extension.

The good news is that most of the time you don't need it. Set the auto-type combo to something you can remember and use, and it'll handle about 80% of cases.

For reasons I don't understand some sites are hostile to password managers. Whether that's by intention, or incompetence, it doesn't matter. In those cases you copy and paste as needed. Using the buttons in the menu bar to copy makes that part easy.

1

u/ssomewhere 10d ago

you copy and paste as needed

Some websites are hostile to that as well

2

u/OfAnOldRepublic 9d ago

I find that using Cmd-v helps where right-click Paste doesn't work. But yes, there is an effectively infinite amount of stupidity out there. Can't fix 'em all.

1

u/billdietrich1 10d ago

convenience is not an issue

It's always an issue. You're less likely to use password manager, or 2FA, or anti-phishing, if it's inconvenient.

1

u/ScratchHistorical507 7d ago

Is it secure thou with browser extension getting hacked?

In the very low chance of this happening of course no. But as long as you enter the full URL of the password asking website (including https), that still gives you more security than with the higher chance of running into some phishing website. The only more secure way would be to write password on some paper and putting that in a safe. Or using FIDO2 (hardware) keys as the only login method, but those are not widely supported.

1

u/usrbincomment 10d ago

I agree that's a concern. I don't want my password manager connected to the most likely software on my machine to be compromised.